VORANT. Threat Intelligence Sign in Get the full feed

Check Point UTM auth bypass under active exploit

critical vulnerability

Check Point UTM products contain an improper authentication flaw (CVE-2026-50751) being actively exploited to bypass authentication; vendor urges immediate hotfix deployment.

Japan's IPA has issued an advisory regarding a critical authentication bypass vulnerability (CVE-2026-50751) affecting Check Point Software Technologies UTM products. The flaw allows remote attackers to circumvent authentication mechanisms without proper credentials. Check Point has confirmed active exploitation of this vulnerability in the wild, making immediate remediation essential.

The vendor has released hotfixes to address the vulnerability and published IOCs including attacker IP addresses and investigation queries for log analysis. Organizations are urged to apply the hotfixes immediately following Check Point's published procedures and review their logs for signs of compromise using the provided detection queries.

Affected systems include end-of-support (EOS) products. For EOS devices, Check Point recommends reviewing lifecycle policies and planning migration to supported platforms. IPA warns that the threat is likely to expand and emphasizes the urgency of patching all vulnerable UTM appliances.

Mentioned in this report

Vulnerabilities CVE-2026-50751KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260610.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free