Check Point UTM auth bypass exploited
Check Point disclosed an actively exploited authentication bypass (CVE-2026-50751) in its UTM products and released hotfixes.
Check Point Software Technologies has disclosed an improper authentication vulnerability, tracked as CVE-2026-50751, affecting its UTM appliances. The vendor states that exploitation of this vulnerability has already been observed in the wild, allowing a remote attacker to bypass authentication controls on affected devices.
Check Point has released hotfixes addressing the flaw and published indicators of compromise, including associated IP addresses and investigative queries, to help administrators determine whether their systems have been targeted. Notably, some of the affected systems are end-of-support (EOS) products, which will not receive further updates and require migration planning per the vendor's lifecycle policy.
IPA (Japan) is urging organizations running Check Point UTM products to review logs for signs of exploitation, apply the vendor-provided hotfixes without delay, and plan migration away from any EOS hardware still in use, given the likelihood of continued and expanding exploitation attempts.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260610.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free