Rapid7 Blog ·EN Vendor research
Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
Overview
On June 8, 2026, Check Point published a security advisory for CVE-2026-50751">CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the deprecated IKEv1 key exchange protocol where gateways accept legacy Remote Access clients and do not require a machine certificate for connections.…