Vulnerabilities

Check Point VPN CVE-2026-50751: exploited authentication bypass

Check Point reports active exploitation of CVE-2026-50751 in certain VPN deployments using the deprecated IKEv1 protocol.

Conceptual illustration: Check Point VPN CVE-2026-50751: exploited authentication bypass
Conceptual illustration · SecurCheck

What is confirmed

Check Point's 8 June advisory describes authentication bypass affecting Remote Access and Mobile Access under specified deprecated IKEv1 configurations.

The vendor reports exploitation and publishes fixes and indicators. Another flaw, CVE-2026-50752, is addressed in the same review without observed exploitation according to the vendor.

What it means

The risk concerns specifically configured gateways, not every VPN user or every Check Point product.

A malicious connection can leave traces in VPN logs; a consumer URL scanner cannot establish a gateway's integrity.

What to do

Network teams: identify affected gateways, apply official fixes and retire IKEv1 where possible.

Review Check Point's logs and indicators; if suspicious access is confirmed, initiate incident response.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Check Point — avis et correctifs CVE-2026-50751
  2. Check Point — fiche technique sk185033