Critical Check Point VPN Vulnerability CVE-2026-50751

We inform you that a critical security vulnerability (CVE-2026-50751) has been discovered in Check Point software (Mobile Access / SSL VPN, Remote Access VPN, Spark Firewall), which allows an attacker to exploit a flaw in the certificate validation logic (when using the IKEv1 protocol) to establish a VPN connection without a valid user password, thereby bypassing authentication. Check Point has confirmed that the vulnerability is already being actively exploited in real attacks. We recommend verifying if the affected functionality is in use and installing the manufacturer's updates as soon as possible if not already done. It is also advised to enable the IKEv2 only option in Remote Access -> VPN Authentication for establishing connections. Additional information about affected versions and recommendations for mitigating the vulnerability is provided.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source