logo

Check Point VPN Authentication Bypass Under Active Exploitation

ID: db146aa7-9215-577c-a42f-aca7076e0ee1

STIX ID: report--db146aa7-9215-577c-a42f-aca7076e0ee1

Feed Name: Kudelski Security

Threat Score
85/100

Date Published: 2026-06-08

Date Updated: 2026-07-22

...
...

A critical authentication-bypass vulnerability (CVE-2026-50751, CVSS 9.3) affecting Check Point Remote Access VPN and Mobile Access when using the deprecated IKEv1 protocol is being actively exploited to establish unauthenticated VPN sessions; observed intrusions have included follow-on activity linked to financially motivated (ransomware) actors, with IOCs and recommended mitigations—patching, disabling IKEv1, and hunting for anomalous VPN sessions—provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.