INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Check Point VPN Exploit Bypass Vulnerability Found

| 2026-06-08 14:17 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The security vendor has revealed that an affiliate of the Qilin ransomware group exploited a flaw in post-compromise activity, with the actor behind the exploitation being financially motivated. The vulnerability is CVE-2026-50751, which affects deployments using deprecated IKEv1 key exchange protocol and allows authentication bypass. Another discovered vulnerability, CVE-2026-50752, has a score of 7.4 and impacts certificate validation in IKEv1 key exchange, potentially allowing man-in-the-middle interference with site-to-site VPN communications under specific conditions. Check Point urges customers to patch the critical zero-day vulnerability in its Remote Access VPN and Mobile Access solutions that is being actively exploited by ransomware criminals.
Technical Mitigations AI-generated
• Implement secure certificate validation: Ensure that all VPN deployments use the latest and most secure IKEv1 key exchange protocol, such as IKEv2 or IKEv3. This will help prevent authentication bypass vulnerabilities like CVE-2026-50751. • Regularly update and patch affected products: Keep all Check Point VPN solutions up-to-date with the latest security patches and hotfixes to ensure that any known exploits are patched before they can be used by attackers. • Use secure communication protocols: When establishing remote access VPN connections, use secure communication protocols like TLS or IPsec instead of deprecated IKEv1. This will help prevent man-in-the-middle attacks and other authentication bypass vulnerabilities. • Monitor for suspicious activity: Regularly monitor your network traffic for any suspicious activity that may indicate an attack on your Check Point VPN solution. Use security information and event management (SIEM) systems or intrusion detection/prevention systems to detect potential threats in real-time. • Use a secure virtual private server (VPS): If you're using a VPS, ensure it's properly secured with strong passwords, encryption, and access controls to prevent unauthorized access. This will help protect your Check Point VPN solution from being compromised by attackers.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SparkSparkQilinQilinAgendaAgenda CVE-2024-24919CVE-2024-24919 CVE-2026-42271CVE-2026-42271 CVE-2026-50752CVE-2026-50752 CVE-2026-50751CVE-2026-50751
Target & Sectors
FIVE_EYES FIVE_EYES NORTH_AMERICA NORTH_AMERICA governmentgovernment technologytechnology
Incident Timeline
‎August 2022
Threat actors used Qilin to target nearly 400 victims on its dark web leak site.
tactic Ransomware
malware Qilin
victims 400 victims
malware Agenda
‎May 7, 2026
Threat actors exploited vulnerabilities in Check Point VPN products to gain unauthorized access.
organisation EOS
organisation R81
malware Spark
organisation Remote Access
source_region Israel
general_metric 19 Hotfix
general_metric 103 Hotfix
general_metric 141 Hotfix
‎May 7
Ransomware attackers exploited a previously unknown vulnerability in Check Point's Remote Access VPN and Mobile Access deployments.
tactic Ransomware
malware Qilin
organisation Remote Access VPN
organisation Mobile Access
vulnerability CVE-2026-50751
organisation Check Point VP
organisation Lotem Finkelstein
source_region Israel
‎2026/05/09
Threat actors used a ransomware attack to exploit vulnerabilities in corporate VPN appliances.
tactic Ransomware
organisation Ctrl-Alt-Intel
‎May 2026
Threat actors used a vulnerability in Check Point's VPN software to gain unauthorized access.
‎June 4, 2026
Threat actors exploited vulnerabilities in Check Point VPN products and versions, specifically targeting those with hotfixes from R82.10 to R80.40, which were vulnerable to exploitation due to outdated or missing security features.
organisation EOS
organisation R81
malware Spark
organisation Remote Access
source_region Israel
general_metric 19 Hotfix
general_metric 103 Hotfix
general_metric 141 Hotfix
‎June 4
Check Point launched an investigation into the incident on June 4.
‎June 8, 2026
Threat actors used a known exploit to target CVE-2026-50751 vulnerabilities in Check Point VPN.
vulnerability CVE-2026-50751
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎Jun 08, 2026
Threat actors exploited a known vulnerability in Check Point's VPN software to gain unauthorized access.
‎at least May 7 through June 5
Threat actors used Check Point SmartConsole to monitor VPN certificate authentication attempts.
‎June 8
Ransomware affiliates exploited a CVE-2026-50751 vulnerability in Check Point's Remote Access VPN and Mobile Access deployments.
tactic Ransomware
malware Qilin
vulnerability CVE-2026-50751
‎2026/06/08
Threat actors used a known exploit of CVE-2026-50751 to target Federal Civilian Executive Branch agencies.
vulnerability CVE-2026-50751
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution FCEB
attribution CISA
attribution Known Exploited
attribution Federal Civilian Executive Branch
‎2026/06/08
Check Point warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol.
organisation Ransomware
organisation Check Point
organisation Check Point Research
organisation preparación de un ataque de ransomware
organisation los grupos de ransomware
organisation los actores financieros
organisation vía directa
organisation the Remote Access and Mobile Access
organisation Security Gateways
organisation CVSS
organisation El fallo
organisation CVE-2026
organisation Remote Access
organisation Mobile Access/SSL VPNs
organisation Unauthenticated
organisation Command Injection Vulnerability
organisation Mobile Access
organisation Check Point VPN
organisation IKEv2
organisation Mobile Access / SSL VPNs
organisation Check Point Remote Access VPN
organisation Check Point Security Gateway
organisation Known Exploited
organisation KEV
organisation Bypass Passwords
organisation Setups
organisation Vulnerability / Network Security
organisation Remote Access VPN
organisation EOS
organisation R81
organisation Check Point's
organisation VPS
organisation IPs
organisation Kaupo Cloud HK
organisation Vultr Holdings
organisation ELF
organisation The Hacker News
organisation DN
organisation ICA
organisation Remote Access VPN Authentication
organisation the Machine Certificate Authentication
organisation Machine Certificate Authentication
organisation Explotan una vulnerabilidad
organisation fue
organisation un
organisation lógico
organisation la validación de certificados
organisation Las VPN
organisation de un protocolo de autenticación
organisation negociación de claves
organisation Sin
organisation gran medida
organisation El uso de tecnologías heredadas sigue
organisation las empresas
organisation falta de revisión o
organisation el actor
organisation observada de explotación
organisation el 7 de mayo
organisation los equipos de respuesta
organisation Key Exchange
organisation BOD
organisation EDR
infrastructure 1.74.2
infrastructure 1.83.6
organisation Check Point Security
infrastructure 1.83.7
organisation MCP
organisation API
organisation Vulnerable Check Point Customers Should Patch
organisation Microsoft
organisation Nissan
organisation Asahi
organisation Court
‎June 11, 2026
The Check Point Security Gateway was updated to address CVE-2026-50751, a known exploited vulnerability.
vulnerability CVE-2026-50751
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
attribution the Check Point Security Gateway
‎June 11
Threat actors used a known exploit of CVE-2026-50751 to target Federal Civilian Executive Branch agencies.
vulnerability CVE-2026-50751
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution FCEB
attribution CISA
attribution Known Exploited
attribution Federal Civilian Executive Branch
‎June 12, 2026
Threat actors exploited a vulnerability in Check Point's VPN product to manipulate authentication flags during IKEv1 negotiation.
‎June 22, 2026
The Check Point Security Gateway was found to have a vulnerability that would be patched by June 11, 2026.
attribution the Check Point Security Gateway
Tactical Metrics
Metrics
victims
400
Victims
Metrics
infrastructure
‎1.74.2
Software Version
Metrics
infrastructure
‎1.83.6
Software Version
Metrics
infrastructure
‎1.83.7
Software Version