Check Point VPN Authentication Bypass (CVE-2026-50751): Active Exploitation & CISA Deadline
Originally reported viaCheck Point Security Advisory sk182336 · CISA Known Exploited Vulnerabilities CatalogueCVE-2026-50751 is a critical (CVSS 9.8) authentication bypass vulnerability affecting Check Point Network Security gateways with the Remote Access VPN blade enabled. A remote, unauthenticated attacker can read sensitive information from the gateway file system — including credential material — without any prior access. Check Point's advisory sk182336 confirms exploitation in the wild as of 9 June 2026.
CISA binding directive and federal deadline
CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities catalogue on 10 June 2026 and issued a binding operational directive requiring all federal civilian executive branch agencies to apply the Check Point hotfix or disable the Remote Access VPN blade by 13 June 2026 — a 72-hour remediation window. CISA's KEV catalogue represents the most actionable exploitation signal available; commercial organisations should mirror its timelines for internet-exposed assets.
Affected versions and immediate actions
Affected versions include Quantum Security Gateway and CloudGuard Network with R81.20, R81.10, R81, and R80.40 firmware. The vulnerability requires the IPSec VPN or Mobile Access software blade to be enabled. Organisations running Check Point gateways in managed or cloud-hosted environments should verify with their MSP that the hotfix has been applied and confirm via gateway version string.
- Apply Check Point hotfix immediately on all affected gateways — available in the Check Point Support Centre under sk182336.
- If patching cannot be completed within 24 hours, disable the Remote Access VPN blade as a temporary mitigation.
- Review gateway access logs for anomalous authentication events and unexpected file access in the 14 days prior to patch.
- Rotate all VPN credentials and certificates associated with affected gateways post-patch.
- Validate that internet-exposed Check Point appliances do not appear in Shodan or Censys with vulnerable version strings.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.