What happened

Cyber Centre said Check Point published a security advisory on June 8, 2026 for a critical vulnerability affecting Mobile Access, SSL VPN, Remote Access VPN, Security Gateways, and Spark Firewall. The agency also noted active exploitation of the flaw.

Why it matters

This is a live threat, not a future risk. If attackers are already exploiting a VPN issue, exposed systems may be at risk of unauthorized access very quickly.

What readers should do

Organizations should review the advisory, confirm product versions, and apply the vendor’s mitigation guidance immediately. VPN appliances should be treated as perimeter-critical assets, so delay is costly.

Technical details & remediation checklist

The flaw is tracked as CVE-2026-50751 (CVSS 9.3, improper authentication / CWE-287). It affects Check Point Remote Access VPN, Mobile Access, and Spark Firewall deployments still using the deprecated IKEv1 key exchange without requiring a machine certificate — the logic flaw lets an unauthenticated attacker establish a VPN session without valid credentials. Exploitation attempts were observed as early as May 7, 2026, with at least one confirmed case tied to follow-on Qilin ransomware activity.

Bottom line

When a VPN platform is under active exploitation, patching becomes a business continuity issue, not just a security chore.