Find notable cyber news and cases, enriched with sources, timelines, and signals.

Check Point VPN CVE-2026-50751 targeted exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 47
3 unique sources, 3 articles

Summary

Hide ▲

CVE-2026-50751 is an active exploitation wave against Check Point Remote Access VPN and Mobile Access deployments that use deprecated IKEv1. The flaw is an authentication bypass that can let a remote attacker establish a VPN connection without a valid password, and Check Point said abuse has reached a few dozen targeted organizations globally. Exploitation has been observed since May 7, 2026, increased in early June, and in one case was tied to a Qilin ransomware affiliate in post-compromise activity. Check Point also identified CVE-2026-50752 in the same IKEv1 certificate-validation path and said it has not been observed exploited.

Cases

Related Happenings

Gravity SMTP actively exploited information disclosure flaw (CVE-2026-4020)

Vulnerability
H score16 First: 19.06.2026 23:25 Last: 19.06.2026 23:25 Sources 1

About this happening: An actively exploited unauthenticated information disclosure flaw in Gravity SMTP exposes API keys, secrets, OAuth tokens, and email-service credentials on sites using...

CISA KEV order for FCEB remediation of CVE-2026-50751

Public Sector Action
H score43 First: 09.06.2026 11:18 Last: 09.06.2026 11:18 Sources 1

How related: Yesterday, CISA also added CVE-2026-50751 to its Known Exploited Vulnerabilities (KEV) Catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their devices by June 11, as mandated by Binding Operational Directive (BOD) 22-01.

About this happening: CISA ordered Federal Civilian Executive Branch agencies to secure CVE-2026-50751, forcing a rapid federal response to a flaw that can let attackers bypass authenticati...

Check Point Remote Access VPN and Mobile Access authentication bypass (CVE-2026-50751)

Vulnerability
H score47 First: 08.06.2026 16:05 Last: 08.06.2026 16:05 Sources 1

How related: The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a case of a logic flow weakness in certificate validation that allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

About this happening: Check Point warned that CVE-2026-50751 is a critical authentication bypass in Remote Access VPN and Mobile Access deployments using deprecated IKEv1, letti...

Check Point security patch release for CVE-2026-50751

Security Patch Release
H score48 First: 08.06.2026 16:05 Last: 08.06.2026 16:05 Sources 1

How related: Israeli cybersecurity company Check Point released security updates to address CVE-2026-50751 on Monday, flagging it as exploited in attacks that began on May 7 and surged over the weekend.

About this happening: Check Point released security updates to patch CVE-2026-50751 in Remote Access VPN and Mobile Access deployments. The update addressed a critical authenticat...

PAN-OS GlobalProtect CVE-2026-0257 exploitation wave

Exploitation Wave
H score18 First: 01.06.2026 11:30 Last: 01.06.2026 11:30 Sources 1

About this happening: A CVE-2026-0257 exploitation wave is hitting Palo Alto Networks PAN-OS GlobalProtect appliances, creating unauthorized VPN access risk for multiple customers. Ra...

Timeline

  1. 08.06.2026 17:17 2 articles · 1mo ago

    Attackers exploit Check Point VPN authentication bypass

    Exploitation Observed

    Attackers began exploiting CVE-2026-50751 against Check Point Remote Access VPN and Mobile Access deployments configured to use deprecated IKEv1, abusing a certificate-validation logic flaw to bypass user authentication and establish VPN sessions without a valid password.

    Show sources
  2. 08.06.2026 17:17 1 articles · 1mo ago

    Check Point first sees suspicious activity tied to VPN exploitation

    Detection Ioc Update

    Check Point first observed indications of suspicious activity tied to the CVE-2026-50751 exploitation wave, showing that the targeting of affected VPN deployments was ongoing by early June 2026.

    Show sources
  3. 08.06.2026 17:17 3 articles · 1mo ago

    Check Point warns of active exploitation of CVE-2026-50751 in VPN deployments

    Initial Disclosure

    Check Point warned that CVE-2026-50751 was under active exploitation against Remote Access VPN and Mobile Access deployments using deprecated IKEv1, said the activity had affected a few dozen targeted organizations globally, and noted one post-exploitation case associated with a Qilin ransomware affiliate. The company also disclosed CVE-2026-50752, a second issue that may enable an adversary-in-the-middle attack on VPN site-to-site connections.

    Show sources