Check Point patches critical VPN authentication bypass

Check Point issued a security advisory on 8 June concerning a critical VPN authentication bypass. The vulnerability, designated CVE-2026-50751, carries a CVSS score of 9.3 and affects Check Point Remote Access VPN and Mobile Access deployments configured for IKEv1. A logic flaw in certificate validation allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Exploitation has been observed in the wild, and Check Point has released a hotfix.

What this means for your organisation

The VPN is often the outermost door into internal systems. When authentication can be bypassed, one of the control points the rest of access management is built around gives way, and an attacker gains network access without stealing a single password. Because the flaw is already being exploited, the window between disclosure and intrusion attempts is short. For organisations under NIS2, both remediation pace and incident handling will be questioned afterwards.

Berigo recommends

  • Apply the Check Point hotfix to all affected gateways, ahead of the ordinary change cadence.
  • Determine whether IKEv1 is still in use and phase it out in favour of newer protocols where possible.
  • Review VPN logs for logins missing the expected password step or originating from unusual addresses.
  • Require multi-factor authentication on all remote access so that no single control point decides access alone.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch