Click any tag below to further narrow down your results
Links
Check Point released updates for CVE-2026-50751, an authentication bypass in IKEv1-based Remote Access and Mobile Access VPNs that has been exploited since May and impacted a few dozen organizations, including a confirmed Qilin ransomware incident. They also patched CVE-2026-50752, a certificate validation flaw in IKEv1 site-to-site VPNs, and urge customers to move to IKEv2, enforce machine certificates, or apply the provided mitigations.
- CVE-2026-50751, an unauthenticated login bypass in Check Point's IKEv1-based VPNs, has been exploited since May 7, hitting a few dozen organizations, with at least one leading to a confirmed Qilin ransomware attack.
- A second flaw, CVE-2026-50752, allows MITM attacks on site-to-site VPNs via IKEv1 certificate validation issues, though it hasn't been seen exploited yet.
- Check Point's fix/mitigation advice: drop legacy clients, switch to IKEv2-only, enforce machine certificates, and enable updated IPS signatures.
CISA has directed U.S. federal agencies to fix a critical authentication bypass in Check Point Remote Access and Mobile Access VPNs (CVE-2026-50751) by June 11. The flaw, exploited by Qilin ransomware affiliates since early May, affects IKEv1 deployments without machine certificates. Check Point released updates and mitigation steps for unpatched environments.
- CVE-2026-50751 lets attackers bypass authentication entirely on Check Point Remote Access/Mobile Access VPNs using legacy IKEv1 setups without machine certificates.
- Qilin ransomware affiliates have been exploiting it since May 7, breaching a few dozen organizations, with exploitation spiking over the weekend.
- CISA added it to the KEV catalog and gave federal agencies until June 11 to patch, citing VPN flaws as a top ransomware entry point.
- If patching isn't immediate, mitigations include disabling legacy clients, enforcing IKEv2-only, enabling updated IPS signatures, and requiring machine certificates.