Vulnerability
Exploitation Wave
Security Patch Release
Check Point IKEv1 VPN Authentication Bypass Exploitation and Response
Updated 09.06.2026 12:30
Case score 59
Score breakdown
- Total
- 59
- Lead score
- 56
- Support bonus
- +3 / 20
- Scoring support
- 1
- Context members
- 1
Top contributors
- Vulnerability Primary anchor for **CVE-2026-50751**, active exploitation status, affected products, victim scope, and mitigation guidance. base
- Exploitation Wave Corroborates the exploitation wave timing, targeted victim scope, and the **Qilin**-linked post-exploitation detail. support
- Security Patch Release Adds direct remediation context, hardening guidance, and the linked disclosure of **CVE-2026-50752**. context
Case score 59
Members 3
Latest activity 09.06.2026 12:30
Active exploitation
KEV: CISA KEV
Patch available
CVSS: 9.3 Critical
Members 3
First seen 08.06.2026 16:05
Last seen 08.06.2026 17:17
Updated 09.06.2026 12:30
Overview
**Check Point** gateways using **deprecated IKEv1** are facing active exploitation of **CVE-2026-50751** in **Remote Access VPN** and **Mobile Access** deployments. The bug lets unauthenticated attackers bypass authentication and open VPN sessions on exposed systems under specific legacy configuration conditions, and confirmed impact has reached **a few dozen organizations globally** since at least **May 7, 2026**.
Defensive pressure rose as patches and mitigation guidance were released for affected **Security Gateways** and **Spark Firewalls**, one post-exploitation case was associated with a **Qilin** ransomware affiliate, and **CVE-2026-50751** entered the **Known Exploited Vulnerabilities** catalog. **CVE-2026-50752** was disclosed alongside the response for **site-to-site VPN** connections, but available evidence does not show it being exploited in the wild.
Attackers are actively exploiting **CVE-2026-50751** in **Check Point Remote Access VPN** and **Mobile Access** deployments that still rely on **deprecated IKEv1**. The flaw is an authentication bypass that lets an unauthenticated remote attacker establish a remote access VPN session without a valid user password when exposed gateways accept legacy remote access clients and do not require a machine certificate. Available evidence places the earliest exploitation on **May 7, 2026**, with suspicious activity observed by **June 4** and a broader increase in activity during early June.
The activity has been described as targeted rather than indiscriminate, with impact confirmed at **a few dozen organizations globally**. In at least one intrusion, the post-exploitation phase was associated with a **Qilin** ransomware affiliate, showing that initial VPN access can progress into follow-on compromise. During the response, **Check Point** also disclosed **CVE-2026-50752**, a related certificate-validation weakness affecting **site-to-site VPN** connections, but available evidence does not show real-world exploitation of that second issue.
Security updates are available for affected **Security Gateways** and **Spark Firewalls**, and urgent mitigation guidance focuses on removing legacy remote access client support, switching Remote Access VPN authentication to **IKEv2 only**, requiring **Machine Certificate Authentication**, and enabling **IPS** signatures where immediate patching is not possible. The urgency increased further after **CVE-2026-50751** was added to the **Known Exploited Vulnerabilities** catalog with a **2026-06-11** remediation deadline for affected federal agencies. The exposure story therefore combines live exploitation, a limited but confirmed set of targeted victims, and a narrow set of legacy configuration conditions that defenders can audit and harden immediately. What remains unclear in available material is the full victim list, how many compromised environments progressed beyond initial VPN access, and whether any actor beyond the noted **Qilin**-linked post-exploitation case has operationalized the flaw.
Signals
8 derivedExploitation
Exploitation
Active exploitation
CVSS
9.3 Critical
CVEs/products
CVE
CVE
Remediation
Urgency
Immediate
KEV
CISA KEV
Remediation
Patch available
Threat context
Ransomware
Qilin
Malware context
2 familiesMember happenings
3 related
Vulnerability
Check Point Remote Access VPN and Mobile Access authentication bypass (CVE-2026-50751)
Exploitation
Active Exploitation
CVSS
9.3 Critical
Patch
Patch Available
Vulnerability
Check Point Remote Access VPN and Mobile Access authentication bypass (CVE-2026-50751)
Exploitation
Active Exploitation
CVSS
9.3 Critical
Patch
Patch Available
Exploitation Wave
Check Point VPN CVE-2026-50751 targeted exploitation wave
Exploitation
Active Exploitation
CVSS
9.3 Critical
Patch
Patch Available
Exploitation Wave
Check Point VPN CVE-2026-50751 targeted exploitation wave
Exploitation
Active Exploitation
CVSS
9.3 Critical
Patch
Patch Available
Security Patch Release
Check Point security patch release for CVE-2026-50751
Exploitation
Active Exploitation
Urgency
Immediate
Patch
Patch Available
Security Patch Release
Check Point security patch release for CVE-2026-50751
Exploitation
Active Exploitation
Urgency
Immediate
Patch
Patch Available