# Check Point UTM auth bypass exploited

Published: 2026-06-09 · Severity: high
Canonical: https://vorant.io/reports/3b2db8c5-c4a7-5730-874b-21ede04f260e/check-point-utm-auth-bypass-exploited

> Check Point disclosed an actively exploited authentication bypass (CVE-2026-50751) in its UTM products and released hotfixes.

Check Point Software Technologies has disclosed an improper authentication vulnerability, tracked as CVE-2026-50751, affecting its UTM appliances. The vendor states that exploitation of this vulnerability has already been observed in the wild, allowing a remote attacker to bypass authentication controls on affected devices.

Check Point has released hotfixes addressing the flaw and published indicators of compromise, including associated IP addresses and investigative queries, to help administrators determine whether their systems have been targeted. Notably, some of the affected systems are end-of-support (EOS) products, which will not receive further updates and require migration planning per the vendor's lifecycle policy.

IPA (Japan) is urging organizations running Check Point UTM products to review logs for signs of exploitation, apply the vendor-provided hotfixes without delay, and plan migration away from any EOS hardware still in use, given the likelihood of continued and expanding exploitation attempts.

## Mentioned in this report

- Vulnerabilities: CVE-2026-50751 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260610.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3b2db8c5-c4a7-5730-874b-21ede04f260e/check-point-utm-auth-bypass-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
