1 link tagged with all of: cybersecurity + check-point + vpn
Click any tag below to further narrow down your results
Links
CISA has directed U.S. federal agencies to fix a critical authentication bypass in Check Point Remote Access and Mobile Access VPNs (CVE-2026-50751) by June 11. The flaw, exploited by Qilin ransomware affiliates since early May, affects IKEv1 deployments without machine certificates. Check Point released updates and mitigation steps for unpatched environments.
- CVE-2026-50751 lets attackers bypass authentication entirely on Check Point Remote Access/Mobile Access VPNs using legacy IKEv1 setups without machine certificates.
- Qilin ransomware affiliates have been exploiting it since May 7, breaching a few dozen organizations, with exploitation spiking over the weekend.
- CISA added it to the KEV catalog and gave federal agencies until June 11 to patch, citing VPN flaws as a top ransomware entry point.
- If patching isn't immediate, mitigations include disabling legacy clients, enforcing IKEv2-only, enabling updated IPS signatures, and requiring machine certificates.