# Check Point UTM auth bypass under active exploit

Published: 2026-06-09 · Severity: critical
Canonical: https://vorant.io/reports/7357b5fb-cbc3-4e59-a839-8b72faa11e2d/check-point-utm-auth-bypass-under-active-exploit

> Check Point UTM products contain an improper authentication flaw (CVE-2026-50751) being actively exploited to bypass authentication; vendor urges immediate hotfix deployment.

Japan's IPA has issued an advisory regarding a critical authentication bypass vulnerability (CVE-2026-50751) affecting Check Point Software Technologies UTM products. The flaw allows remote attackers to circumvent authentication mechanisms without proper credentials. Check Point has confirmed active exploitation of this vulnerability in the wild, making immediate remediation essential.

The vendor has released hotfixes to address the vulnerability and published IOCs including attacker IP addresses and investigation queries for log analysis. Organizations are urged to apply the hotfixes immediately following Check Point's published procedures and review their logs for signs of compromise using the provided detection queries.

Affected systems include end-of-support (EOS) products. For EOS devices, Check Point recommends reviewing lifecycle policies and planning migration to supported platforms. IPA warns that the threat is likely to expand and emphasizes the urgency of patching all vulnerable UTM appliances.

## Mentioned in this report

- Vulnerabilities: CVE-2026-50751 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260610.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7357b5fb-cbc3-4e59-a839-8b72faa11e2d/check-point-utm-auth-bypass-under-active-exploit.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
