Check Point released security updates to fix multiple vulnerabilities across Mobile Access, SSL VPN, Remote Access VPN, Spark Firewall, Security Gateways, and Multi-Domain Security Management. The most severe flaw, CVE-2026-50751 with a CVSS 9.3, is an authentication bypass issue in deprecated IKEv1 key exchange used for VPN Remote Access and Mobile Access, and Check Point said it is being exploited in the wild as a zero-day.
The update also addresses CVE-2026-50752, which affects certificate validation in deprecated IKEv1 site-to-site VPN connections and could allow man-in-the-middle attacks. Across the broader set of flaws, Check Point warned of risks including denial of service, data manipulation, authentication bypass, and unauthorized access, and urged organizations to apply patches as soon as testing is complete.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In the June 9, 2026 security update, Check Point stated that CVE-2026-50751, a critical authentication bypass flaw in deprecated IKEv1 key exchange for VPN Remote Access and Mobile Access, is being exploited in the wild as a zero-day. The vulnerability was assigned a CVSS score of 9.3.
On June 9, 2026, Check Point released security updates to remediate multiple vulnerabilities affecting products including Mobile Access, SSL VPN, Remote Access VPN, Spark Firewall, Security Gateways, and Multi-Domain Security Management. The issues could enable denial-of-service, man-in-the-middle attacks, data manipulation, authentication bypass, and unauthorized access.
According to the new reference, exploitation of Check Point VPN authentication bypass flaw CVE-2026-50751 began on May 7, 2026. The activity reportedly compromised dozens of organizations before public disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.