Check Point VPN Zero-Day CVE-2026-50751: Qilin Ransomware Exploit
Check Point has disclosed a critical zero-day vulnerability in its Remote Access VPN and Mobile Access deployments that allows unauthenticated attackers to bypass authentication and establish VPN connections. The flaw, tracked as CVE-2026-50751, is actively exploited in the wild and has been linked to the Qilin ransomware operation.
What Happened: Check Point VPN Zero-Day Enables Unauthenticated Remote Access
On June 8, 2026, Check Point Research published a security advisory confirming active exploitation of CVE-2026-50751. The vulnerability exists in the deprecated IKEv1 key exchange protocol used by Check Point Security Gateways. Furthermore, an attacker can exploit a logic flaw in certificate validation to establish a remote access VPN connection without a valid user password.
The attacks began on May 7, 2026, and surged in early June. Check Point stated that exploitation has been limited to a few dozen targeted organizations globally. However, at least one confirmed incident involved post-compromise activity associated with a Qilin ransomware affiliate. Consequently, CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog on June 8, 2026, with a federal patching deadline of June 11, 2026.
While investigating CVE-2026-50751, Check Point researchers identified a second vulnerability, CVE-2026-50752, affecting certificate validation in the same deprecated IKEv1 key exchange. This flaw could allow man-in-the-middle attacks on site-to-site VPN connections. Therefore, Check Point advised customers to patch both vulnerabilities even though CVE-2026-50752 has not yet been observed in active exploitation.
Technical Details of the Check Point VPN Authentication Bypass
CVE-2026-50751 is an improper authentication vulnerability in the IKEv1 key exchange implementation of Check Point Remote Access VPN and Mobile Access. The flaw enables an unauthenticated, remote attacker to bypass user authentication by exploiting a weakness in certificate validation logic.
The attack works as follows:
- The target deployment must use the deprecated IKEv1 key exchange protocol
- The security gateway must accept legacy Remote Access clients
- Machine certificate authentication must not be mandatory for connections
- The attacker exploits the certificate validation logic flaw to establish a VPN session without a valid password
Additional post-authentication activity is required to access internal resources or escalate privileges. However, the initial VPN connection grants the attacker a foothold inside the network perimeter. Moreover, Check Point Research noted that the threat actor infrastructure behind these attacks is also exploiting other VPN-related vulnerabilities published by Palo Alto Networks, Fortinet, and F5.
Business and Operational Impact
The CVE-2026-50751 vulnerability poses severe risks for organizations relying on Check Point VPN infrastructure. Because the flaw allows unauthenticated remote access, attackers can bypass perimeter defenses without stolen credentials or phishing.
- Unauthorized network access: Attackers can establish VPN tunnels without valid passwords
- Ransomware deployment: Confirmed linkage to Qilin ransomware affiliate activity
- Lateral movement: VPN foothold enables reconnaissance and spread across internal networks
- Data exfiltration: Access to sensitive systems and repositories behind the VPN perimeter
- Regulatory exposure: Federal agencies must patch by June 11, 2026, per CISA KEV requirements
Moreover, the threat actor uses a dedicated virtual private server infrastructure hosted by Kaupo Cloud HK, Shock Hosting, and Vultr Holdings. In some cases, the attacker VPS geolocation correlated with the victim organization’s geography, suggesting a deliberate targeting approach.
Mitigation and Recommendations
Check Point released security updates and hotfixes for all affected products. Therefore, organizations should apply patches immediately. For customers who cannot patch immediately, Check Point provided alternative mitigation steps.
Immediate Actions for Defenders
- Apply the latest Check Point hotfix for CVE-2026-50751 and CVE-2026-50752 immediately
- Remove support for the deprecated IKEv1 remote access client
- Configure Remote Access VPN Authentication to use IKEv2 only
- Set Machine Certificate Authentication as mandatory for all VPN connections
- Enable IPS and download the latest signatures to detect exploitation attempts
- Audit VPN logs from May 7, 2026, onward for suspicious connections
Alternative Mitigations for Unpatched Systems
- Disable IKEv1 key exchange protocol in Remote Access VPN global properties
- Restrict VPN access to known IP ranges or geographies
- Monitor for connections from known attacker infrastructure IPs: 45.77.149.152, 209.182.225.136, 38.60.157.139, 162.33.177.101, 45.76.26.42, 144.208.127.155, 38.54.88.201, 38.54.107.167, 66.42.99.200
Bottom line: CVE-2026-50751 is a critical authentication bypass in Check Point VPN that is actively exploited by ransomware actors. Organizations using IKEv1 must patch or disable the deprecated protocol immediately.
Incident Summary
| CVE ID / Incident: | CVE-2026-50751 / Check Point VPN Authentication Bypass |
| Affected Systems: | Check Point Security Gateways using IKEv1: R80.20.X, R80.40, R81, R81.10, R81.10.X, R81.20, R82, R82.00.X, R82.10; Mobile Access / SSL VPN, Remote Access VPN, Spark Firewall |
| Disclosure Date: | June 8, 2026 |
| Exploitation Start: | May 7, 2026 |
| Patch Status: | Hotfixes available; CISA KEV due date June 11, 2026 |
| CVSS Score: | 9.3 (Critical) |
References
- Sergiu Gatlan, “Check Point links VPN zero-day attacks to Qilin ransomware gang,” BleepingComputer, June 8, 2026, https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/ (accessed June 8, 2026).
- Check Point Research, “Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751),” Check Point Blog, June 8, 2026, https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ (accessed June 8, 2026).
- CISA, “Known Exploited Vulnerabilities Catalog: CVE-2026-50751,” CISA.gov, June 8, 2026, https://www.cisa.gov/known-exploited-vulnerabilities-catalog (accessed June 8, 2026).