Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave Security Patch Release

Check Point IKEv1 VPN Authentication Bypass Exploitation and Response

Updated 09.06.2026 12:30
Case score 59
Members 3 First seen 08.06.2026 16:05 Latest activity 09.06.2026 12:30

Overview

**Check Point** gateways using **deprecated IKEv1** are facing active exploitation of **CVE-2026-50751** in **Remote Access VPN** and **Mobile Access** deployments. The bug lets unauthenticated attackers bypass authentication and open VPN sessions on exposed systems under specific legacy configuration conditions, and confirmed impact has reached **a few dozen organizations globally** since at least **May 7, 2026**. Defensive pressure rose as patches and mitigation guidance were released for affected **Security Gateways** and **Spark Firewalls**, one post-exploitation case was associated with a **Qilin** ransomware affiliate, and **CVE-2026-50751** entered the **Known Exploited Vulnerabilities** catalog. **CVE-2026-50752** was disclosed alongside the response for **site-to-site VPN** connections, but available evidence does not show it being exploited in the wild.
Latest development Open development history 3 earlier developments Check Point warns of active exploitation of CVE-2026-50751 in VPN deployments Check Point warned that CVE-2026-50751 was under active exploitation against Remote Access VPN and Mobile Access deployments using deprecated IKEv1, said the activity had affected a few dozen targeted organizations globally, and noted one post-exploitation case associated with a Qilin ransomware affiliate. The company also disclosed CVE-2026-50752, a second issue that may enable an adversary-in-the-middle attack on VPN site-to-site connections.
  1. Earlier development

    Check Point releases updates for CVE-2026-50751 and flags a related IKEv1 flaw

    On June 8, 2026, Check Point released security updates for CVE-2026-50751 and urged customers to patch immediately after confirming active exploitation against a few dozen organizations worldwide, including at least one case associated with a Qilin ransomware affiliate; the company also disclosed CVE-2026-50752, a related certificate-validation flaw in deprecated IKEv1 that could enable man-in-the-middle attacks on site-to-site VPN connections, and recommended moving Remote Access VPN authentication to IKEv2 only, making Machine Certificate Authentication mandatory, and enabling IPS signatures for systems that cannot be patched right away.

  2. Earlier development

    Check Point first sees suspicious activity tied to VPN exploitation

    Check Point first observed indications of suspicious activity tied to the CVE-2026-50751 exploitation wave, showing that the targeting of affected VPN deployments was ongoing by early June 2026.

  3. Earlier development

    Check Point VPN zero-day exploitation begins

    Check Point identifies active zero-day exploitation of CVE-2026-50751 against Remote Access VPN and Mobile Access deployments that use deprecated IKEv1, with unauthenticated remote attackers able to bypass authentication on targeted gateways.

Signals

Impact signals
Exploitation
CVEs/products
Remediation
Threat context

Malware context

2 families

Technical intelligence

Existing Case data

Member happenings

Vulnerability Check Point Remote Access VPN and Mobile Access authentication bypass (CVE-2026-50751)
Updated 08.06.2026 16:05 Lead Contribution 56
Exploitation Active Exploitation CVSS 9.3 Critical Patch Patch Available

**Check Point** warned that **CVE-2026-50751** is a **critical authentication bypass** in **Remote Access VPN** and **Mobile Access** deployments using **deprecated IKEv1**, letting an attacker **bypass user authentication** and establish a VPN connection without a valid password. Check Point said the flaw has been **actively exploited** since **May 7, 2026**, with activity affecting **a few dozen targeted organizations worldwide** and one post-compromise case linked to a **Qilin ransomware affiliate**. The company also disclosed **CVE-2026-50752**, a related certificate-validation flaw in the same IKEv1 path, and said it has **not been observed exploited**.

Exploitation Wave Check Point VPN CVE-2026-50751 targeted exploitation wave
Updated 08.06.2026 17:17 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 9.3 Critical Patch Patch Available

**CVE-2026-50751** is an **active exploitation wave** against **Check Point Remote Access VPN** and **Mobile Access** deployments that use **deprecated IKEv1**. The flaw is an **authentication bypass** that can let a remote attacker establish a VPN connection without a valid password, and Check Point said abuse has reached **a few dozen targeted organizations globally**. Exploitation has been observed since **May 7, 2026**, increased in **early June**, and in one case was tied to a **Qilin ransomware** affiliate in **post-compromise activity**. Check Point also identified **CVE-2026-50752** in the same IKEv1 certificate-validation path and said it has **not been observed exploited**.

Security Patch Release Check Point security patch release for CVE-2026-50751
Updated 08.06.2026 16:05 Context
Exploitation Active Exploitation Urgency Immediate Patch Patch Available

**Check Point** released **security updates** to patch **CVE-2026-50751** in **Remote Access VPN** and **Mobile Access** deployments. The update addressed a **critical authentication bypass** on systems using **deprecated IKEv1**, after the flaw was **exploited in zero-day attacks**. Check Point also disclosed **CVE-2026-50752** and urged customers to apply the fixes immediately or use mitigation steps such as **IKEv2 only** and mandatory **Machine Certificate Authentication**.