Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVERansomwareZero Day

Check Point VPN Zero-Day CVE-2026-50751: Qilin Ransomware Exploit

By ogwatermelon
June 9, 2026 4 Min Read
0
June 8, 2026

Check Point has disclosed a critical zero-day vulnerability in its Remote Access VPN and Mobile Access deployments that allows unauthenticated attackers to bypass authentication and establish VPN connections. The flaw, tracked as CVE-2026-50751, is actively exploited in the wild and has been linked to the Qilin ransomware operation.

What Happened: Check Point VPN Zero-Day Enables Unauthenticated Remote Access

On June 8, 2026, Check Point Research published a security advisory confirming active exploitation of CVE-2026-50751. The vulnerability exists in the deprecated IKEv1 key exchange protocol used by Check Point Security Gateways. Furthermore, an attacker can exploit a logic flaw in certificate validation to establish a remote access VPN connection without a valid user password.

The attacks began on May 7, 2026, and surged in early June. Check Point stated that exploitation has been limited to a few dozen targeted organizations globally. However, at least one confirmed incident involved post-compromise activity associated with a Qilin ransomware affiliate. Consequently, CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog on June 8, 2026, with a federal patching deadline of June 11, 2026.

While investigating CVE-2026-50751, Check Point researchers identified a second vulnerability, CVE-2026-50752, affecting certificate validation in the same deprecated IKEv1 key exchange. This flaw could allow man-in-the-middle attacks on site-to-site VPN connections. Therefore, Check Point advised customers to patch both vulnerabilities even though CVE-2026-50752 has not yet been observed in active exploitation.

Technical Details of the Check Point VPN Authentication Bypass

CVE-2026-50751 is an improper authentication vulnerability in the IKEv1 key exchange implementation of Check Point Remote Access VPN and Mobile Access. The flaw enables an unauthenticated, remote attacker to bypass user authentication by exploiting a weakness in certificate validation logic.

The attack works as follows:

  • The target deployment must use the deprecated IKEv1 key exchange protocol
  • The security gateway must accept legacy Remote Access clients
  • Machine certificate authentication must not be mandatory for connections
  • The attacker exploits the certificate validation logic flaw to establish a VPN session without a valid password

Additional post-authentication activity is required to access internal resources or escalate privileges. However, the initial VPN connection grants the attacker a foothold inside the network perimeter. Moreover, Check Point Research noted that the threat actor infrastructure behind these attacks is also exploiting other VPN-related vulnerabilities published by Palo Alto Networks, Fortinet, and F5.

Business and Operational Impact

The CVE-2026-50751 vulnerability poses severe risks for organizations relying on Check Point VPN infrastructure. Because the flaw allows unauthenticated remote access, attackers can bypass perimeter defenses without stolen credentials or phishing.

  • Unauthorized network access: Attackers can establish VPN tunnels without valid passwords
  • Ransomware deployment: Confirmed linkage to Qilin ransomware affiliate activity
  • Lateral movement: VPN foothold enables reconnaissance and spread across internal networks
  • Data exfiltration: Access to sensitive systems and repositories behind the VPN perimeter
  • Regulatory exposure: Federal agencies must patch by June 11, 2026, per CISA KEV requirements

Moreover, the threat actor uses a dedicated virtual private server infrastructure hosted by Kaupo Cloud HK, Shock Hosting, and Vultr Holdings. In some cases, the attacker VPS geolocation correlated with the victim organization’s geography, suggesting a deliberate targeting approach.

Mitigation and Recommendations

Check Point released security updates and hotfixes for all affected products. Therefore, organizations should apply patches immediately. For customers who cannot patch immediately, Check Point provided alternative mitigation steps.

Immediate Actions for Defenders

  1. Apply the latest Check Point hotfix for CVE-2026-50751 and CVE-2026-50752 immediately
  2. Remove support for the deprecated IKEv1 remote access client
  3. Configure Remote Access VPN Authentication to use IKEv2 only
  4. Set Machine Certificate Authentication as mandatory for all VPN connections
  5. Enable IPS and download the latest signatures to detect exploitation attempts
  6. Audit VPN logs from May 7, 2026, onward for suspicious connections

Alternative Mitigations for Unpatched Systems

  • Disable IKEv1 key exchange protocol in Remote Access VPN global properties
  • Restrict VPN access to known IP ranges or geographies
  • Monitor for connections from known attacker infrastructure IPs: 45.77.149.152, 209.182.225.136, 38.60.157.139, 162.33.177.101, 45.76.26.42, 144.208.127.155, 38.54.88.201, 38.54.107.167, 66.42.99.200

Bottom line: CVE-2026-50751 is a critical authentication bypass in Check Point VPN that is actively exploited by ransomware actors. Organizations using IKEv1 must patch or disable the deprecated protocol immediately.

Incident Summary

CVE ID / Incident: CVE-2026-50751 / Check Point VPN Authentication Bypass
Affected Systems: Check Point Security Gateways using IKEv1: R80.20.X, R80.40, R81, R81.10, R81.10.X, R81.20, R82, R82.00.X, R82.10; Mobile Access / SSL VPN, Remote Access VPN, Spark Firewall
Disclosure Date: June 8, 2026
Exploitation Start: May 7, 2026
Patch Status: Hotfixes available; CISA KEV due date June 11, 2026
CVSS Score: 9.3 (Critical)

References

  1. Sergiu Gatlan, “Check Point links VPN zero-day attacks to Qilin ransomware gang,” BleepingComputer, June 8, 2026, https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/ (accessed June 8, 2026).
  2. Check Point Research, “Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751),” Check Point Blog, June 8, 2026, https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ (accessed June 8, 2026).
  3. CISA, “Known Exploited Vulnerabilities Catalog: CVE-2026-50751,” CISA.gov, June 8, 2026, https://www.cisa.gov/known-exploited-vulnerabilities-catalog (accessed June 8, 2026).

Tags:

RansomwareVulnerabilityZero Day
Author

ogwatermelon

Follow Me
Other Articles
Previous

Meta AI Support Breach Hijacks 20,000 Instagram Accounts

Next

Google Chrome Zero-Day CVE-2026-11645: Fifth 2026 Exploit

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.