Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
June 10, 2026, 11 a.m.
Description
A critical authentication bypass vulnerability affecting Remote Access VPN and Mobile Access deployments has been actively exploited in the wild. The vulnerability exploits a logic flaw in certificate validation within the deprecated IKEv1 key exchange protocol, allowing attackers to establish VPN sessions without valid passwords. Exploitation has been observed since May 7, 2026, targeting several dozen organizations globally. One confirmed incident involved post-compromise activity linked to Qilin ransomware operations. The threat actor appears financially motivated and operates dedicated VPS infrastructure across multiple hosting providers. An additional related vulnerability affecting site-to-site VPN communications was discovered through AI-assisted code analysis, though no active exploitation has been observed. Immediate patching is strongly recommended for affected systems using IKEv1 protocol.
Tags
Date
- Created: June 9, 2026, 3:50 p.m.
- Published: June 9, 2026, 3:50 p.m.
- Modified: June 10, 2026, 11 a.m.
Indicators
- 45.61.136.173
- 209.182.225.136
- 144.208.127.155
- 162.33.177.101
- 38.54.88.201
- 38.54.107.167
- 38.60.157.139
Additional Informations
- Taiwan