CVE-2026-50751 is an authentication-bypass vulnerability in Check Point Remote Access VPN and Mobile Access. A logic-flow weakness in certificate validation during deprecated IKEv1 key exchange permits an unauthenticated remote attacker to establish a remote-access VPN connection without a valid user password. The vulnerability has been actively exploited, including activity associated with a Qilin ransomware affiliate.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (7 hidden).
This 13-file Go repository is a standalone operational proof-of-concept for CVE-2026-50751, an alleged Check Point iked IKEv1 Remote Access VPN certificate-authentication bypass. The primary executable is cmd/main.go, which accepts a gateway host, target Remote Access username, transport port, DN organization/OU values, timeout, and retry settings. It can automatically obtain the organization from the gateway TLS certificate on TCP/443. The exploit logic in exploit/exploit.go implements IKEv1 Main Mode: it first sends an RSA-signature security-association proposal plus the Check Point-specific VPNExtFeatures Vendor ID (magic 3cf187b2474029ea46ac7fd0eaf289f5) with feature value 0x00000004; performs MODP group-2 Diffie-Hellman and nonce exchange; derives IKEv1 session keys; and sends an AES-256-CBC encrypted identity, self-signed certificate, and deliberately random invalid RSA signature. It identifies success from an encrypted IKE Main Mode response and tries to decrypt an IPv4 gateway identity from that response. Supporting packages provide ordered ASN.1/X.501 DN encoding (to preserve O/OU/CN order), self-signed certificate creation and invalid-signature generation, IKEv1 packet/payload/key-schedule handling, and UDP, UDP NAT-T, and Check Point TCPT Visitor Mode transports. The repository contains no post-auth VPN traffic, shell, persistence, or arbitrary-command payload; its direct capability is authentication bypass and confirmation of an IKE phase-1 security association as a selected user.
This is a small standalone Python repository containing one executable implementation file, scanner.py, plus a README, MIT license, and a generic Python .gitignore. scanner.py is a command-line offensive testing tool presented as a CVE-2026-50751 Check Point IKEv1 authentication-bypass framework. It uses Scapy/ISAKMP functionality and Python socket, cryptographic, subprocess, threading, and IP-addressing libraries. Its visible workflow supports a single target or CIDR range, invokes masscan or zmap for UDP/500 discovery, records candidates, and proceeds to IKEv1 fingerprinting and a claimed authentication-bypass attempt. Command-line modes allow scan-only, exploit-only, and full-chain behavior, with a default bypass username of admin. The post-exploitation path, triggered after reported exploit success and an operator-provided listener host, claims to establish a VPN tunnel, probe the accessible internal network, and deploy a reverse shell to a discovered host. No fixed public victim IPs, domains, or C2 URLs are embedded; primary network targets and callback settings are operator controlled. Although it contains exploitation and reverse-shell functionality rather than merely a detector, the README itself says it is not a confirmed reliable exploit and may generate false positives or simulate actions, so successful compromise/tunnel creation should not be assumed without validation.
Repository contains a single substantive Python exploit/detection artifact generator plus a README. The Python script is a standalone operational exploit for CVE-2026-50751 affecting Check Point Remote Access VPN / Mobile Access when legacy IKEv1 Remote Access is enabled. Its core capability is to authenticate as a known provisioned Remote Access username without possessing a valid client certificate, private key, or password. The exploit implements substantial protocol logic itself rather than relying on an external framework: socket transport, IKEv1/ISAKMP message construction, Diffie-Hellman group 2 exchange, RFC 2409 key derivation, HMAC-SHA1 PRF, AES-CBC encryption/decryption, and X.509 certificate generation using Python cryptography. Based on the comments and CLI, it forges a self-signed certificate whose subject DN matches the target user and abuses the vulnerable gateway behavior where attacker-controlled VPNExtFeatures flags cause peer-auth/signature verification to be skipped. Success is determined by whether phase 1 is granted and the gateway treats the session as authenticated for that user. Repository structure is minimal: README.md documents the vulnerability, prerequisites, usage, and expected output; watchTowr-vs-Check-Point-CVE-2026-50751.py is the main and only code file. The script accepts a remote host, remote port, username to impersonate, optional organization and OU values for the forged DN, timeout/retry settings, and a TCPT mode for Visitor Mode over raw TCP 443. It can target standard IKE over UDP 500 or 4500, or Check Point Visitor Mode over TCP 443. This is not merely a detector in the narrow sense: although branded as a detection artifact generator, it actively performs the authentication bypass against the target and confirms exploitation when the gateway authenticates the supplied username. No post-auth remote code execution payload is included; the exploit’s result is unauthorized VPN authentication / identity impersonation at the IKEv1 phase-1 level.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
295 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication-bypass zero-day exploited since June by a Qilin ransomware affiliate.
An authentication-bypass zero-day in Check Point products that has been actively exploited since June by a Qilin ransomware affiliate.
An authentication-bypass vulnerability in Check Point Remote Access VPN, mentioned as historical evidence of adversary interest in the Check Point VPN attack surface.
A Check Point zero-day vulnerability previously reported as exploited; no further technical details are provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.