Attackers are actively exploiting a critical vulnerability in Check Point VPN to bypass authentication and gain unauthorised remote access. Apply security updates immediately.
Check Point has released a security update to address a critical authentication bypass vulnerability (CVE-2026-50751) affecting Remote Access VPN and Mobile Access deployments. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.3 out of 10.
Due to a logic flow weakness in certificate validation, successful exploitation of this vulnerability could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without valid user credentials.
The vulnerability requires all of the following configurations to be in place in order for attackers to exploit:
VPN Remote Access or Mobile Access is enabled
IKEv1 is enabled for remote access
Gateways accept legacy Remote Access clients
Gateways do not demand a machine certificate for connections
This vulnerability is being actively exploited in the wild.
This vulnerability affects the following product versions.
R82.10 Jumbo Hotfix Take 19 or below
R82 Jumbo Hotfix Take 103 or below
R81.20 Jumbo Hotfix Take 141 or below
Users and administrators of affected products are advised to upgrade deployments to the minimum required Jumbo Hotfix Take or software version specified in the official Check Point advisory.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
