# Check Point IKEv1 VPN flaw exploited in wild

Published: 2026-06-09 · Severity: critical
Canonical: https://vorant.io/reports/0d67fe1d-fd65-410d-ad61-e05d16d72762/check-point-ikev1-vpn-flaw-exploited-in-wild

> Multiple vulnerabilities in Check Point VPN products allow security policy bypass, with CVE-2026-50751 actively exploited targeting deprecated IKEv1 protocol.

Check Point has disclosed multiple vulnerabilities affecting their VPN products, including Spark firewalls and Security Gateways across numerous versions. The vulnerabilities enable attackers to bypass security policies, with the vendor confirming active exploitation of CVE-2026-50751. This critical flaw affects the deprecated IKEv1 protocol implementation.

Affected products include Spark firewalls running R80.20.X, R81.10.17 and earlier, and R82.00.10 and earlier without current security patches. Security Gateways versions R80.40, R81, R81.10, R81.20 and earlier, R82 and earlier, and R82.10 and earlier are also vulnerable. Check Point has announced that R80.40, R81, and R81.10 versions of Security Gateways, as well as R80.20.X versions of Spark firewalls, have reached end-of-life and will not receive patches.

The vendor has released security bulletins with patches for supported versions and provided workarounds and indicators of compromise. Organizations running affected Check Point VPN products should prioritize patching, particularly given the active exploitation of CVE-2026-50751.

## Mentioned in this report

- Vulnerabilities: CVE-2026-50751 (KEV), CVE-2026-50752

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0711

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0d67fe1d-fd65-410d-ad61-e05d16d72762/check-point-ikev1-vpn-flaw-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
