Skip to content
Critical Vulnerability in Check Point VPN

Critical Vulnerability in Check Point VPN

Csa.Sg June 9, 2026

Attackers are actively exploiting a critical vulnerability in Check Point VPN to bypass authentication and gain unauthorised remote access. Apply security updates immediately.

Check Point has released a security update to address a critical authentication bypass vulnerability (CVE-2026-50751) affecting Remote Access VPN and Mobile Access deployments. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.3 out of 10.

Due to a logic flow weakness in certificate validation, successful exploitation of this vulnerability could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without valid user credentials.

The vulnerability requires all of the following configurations to be in place in order for attackers to exploit:

VPN Remote Access or Mobile Access is enabled

IKEv1 is enabled for remote access

Gateways accept legacy Remote Access clients

Gateways do not demand a machine certificate for connections

This vulnerability is being actively exploited in the wild.

This vulnerability affects the following product versions.

R82.10 Jumbo Hotfix Take 19 or below

R82 Jumbo Hotfix Take 103 or below

R81.20 Jumbo Hotfix Take 141 or below

Users and administrators of affected products are advised to upgrade deployments to the minimum required Jumbo Hotfix Take or software version specified in the official Check Point advisory.

Extracted Entities

Companies (1)

Platforms (1)