Check Point VPN authentication bypass CVE-2026-50751
Back to Blog
Vulnerability Research

Check Point VPN Authentication Bypass (CVE-2026-50751): Active Exploitation & CISA Deadline

PublishedJune 10, 2026
Read time7 min read
Share
Originally reported viaCheck Point Security Advisory sk182336 · CISA Known Exploited Vulnerabilities Catalogue

CVE-2026-50751 is a critical (CVSS 9.8) authentication bypass vulnerability affecting Check Point Network Security gateways with the Remote Access VPN blade enabled. A remote, unauthenticated attacker can read sensitive information from the gateway file system — including credential material — without any prior access. Check Point's advisory sk182336 confirms exploitation in the wild as of 9 June 2026.

CISA binding directive and federal deadline

CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities catalogue on 10 June 2026 and issued a binding operational directive requiring all federal civilian executive branch agencies to apply the Check Point hotfix or disable the Remote Access VPN blade by 13 June 2026 — a 72-hour remediation window. CISA's KEV catalogue represents the most actionable exploitation signal available; commercial organisations should mirror its timelines for internet-exposed assets.

Source: Check Point Security Advisory sk182336 — 9 June 2026
Check Point confirmed active exploitation targeting Quantum Gateway appliances running R81.20, R81.10, R81, and R80.40. The hotfix is available immediately. Gateways without the hotfix applied remain vulnerable regardless of other controls.

Affected versions and immediate actions

Affected versions include Quantum Security Gateway and CloudGuard Network with R81.20, R81.10, R81, and R80.40 firmware. The vulnerability requires the IPSec VPN or Mobile Access software blade to be enabled. Organisations running Check Point gateways in managed or cloud-hosted environments should verify with their MSP that the hotfix has been applied and confirm via gateway version string.

Source: CISA KEV Catalogue — 10 June 2026
CISA KEV entry for CVE-2026-50751 notes evidence of active exploitation targeting both government and critical infrastructure sectors. Exploitation has been observed within 24 hours of public advisory disclosure.
  • Apply Check Point hotfix immediately on all affected gateways — available in the Check Point Support Centre under sk182336.
  • If patching cannot be completed within 24 hours, disable the Remote Access VPN blade as a temporary mitigation.
  • Review gateway access logs for anomalous authentication events and unexpected file access in the 14 days prior to patch.
  • Rotate all VPN credentials and certificates associated with affected gateways post-patch.
  • Validate that internet-exposed Check Point appliances do not appear in Shodan or Censys with vulnerable version strings.
Furix's vulnerability prioritisation engine auto-ingests CISA KEV entries and surfaces affected assets within your environment within minutes of a new catalogue addition.

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.