RW
RiskWire Real-time vulnerability intelligence
This week Pricing Live dashboard
Critical 9.3 KEV + Ransomware

CVE-2026-50751

Q2 2026 Threat Statistics and Ransomware Exploitation

Vendor / product: Check Point Remote Access VPN and Mobile Access
Event date: 2026-05-07
Public PoC: Yes
First tracked by RiskWire: 2026-07-28

CISA KEV catalog

Added to KEV
Federal remediation due
2026-06-11 (101 days overdue)
Ransomware campaign use
Known
CISA description
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Named threat actors

Fox TempestRhysidaAkiraINCQilinBlackBytePayoutsKing groupDragonForce RaaS group

Sources & citations (1)

References

See CVE-2026-50751 in context

RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.

Book a 20-min demo →