What happened
Cyber Centre said Check Point published a security advisory on June 8, 2026 for a critical vulnerability affecting Mobile Access, SSL VPN, Remote Access VPN, Security Gateways, and Spark Firewall. The agency also noted active exploitation of the flaw.
Why it matters
This is a live threat, not a future risk. If attackers are already exploiting a VPN issue, exposed systems may be at risk of unauthorized access very quickly.
What readers should do
Organizations should review the advisory, confirm product versions, and apply the vendor’s mitigation guidance immediately. VPN appliances should be treated as perimeter-critical assets, so delay is costly.
Technical details & remediation checklist
The flaw is tracked as CVE-2026-50751 (CVSS 9.3, improper authentication / CWE-287). It affects Check Point Remote Access VPN, Mobile Access, and Spark Firewall deployments still using the deprecated IKEv1 key exchange without requiring a machine certificate — the logic flaw lets an unauthenticated attacker establish a VPN session without valid credentials. Exploitation attempts were observed as early as May 7, 2026, with at least one confirmed case tied to follow-on Qilin ransomware activity.
- Apply Check Point's released hotfix to all affected Security Gateways immediately.
- Disable IKEv1 entirely and require IKEv2 only — in SmartConsole: VPN Community > Encryption > General > Encryption Method.
- Audit existing Remote Access/Mobile Access configurations for machine-certificate enforcement.
- Review VPN gateway logs for connection attempts predating your patch date, since exploitation was already occurring by early May 2026.
Bottom line
When a VPN platform is under active exploitation, patching becomes a business continuity issue, not just a security chore.
CYBERSHIELDZONE