216.73.217.22

Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)

· Published 09/06/2026 15:50 · Modified 10/06/2026 11:00

Export JSON

Essential information

Published
09/06/2026 15:50
Modified
10/06/2026 11:00
Tags
2026-06-09 CVE-2026-50751 CVE-2026-50752 active exploitation qilin ransomware remote access vpn vpn authentication bypass
Related entities
2 vulnerabilities (cve), 7 observables, 1 intrusion sets (apt), 11 techniques (mitre), 1 malware, 1 others

Description

A critical authentication bypass vulnerability affecting and Mobile Access deployments has been actively exploited in the wild. The vulnerability exploits a logic flaw in certificate validation within the deprecated IKEv1 key exchange protocol, allowing attackers to establish VPN sessions without valid passwords. Exploitation has been observed since May 7, 2026, targeting several dozen organizations globally. One confirmed incident involved post-compromise activity linked to operations. The threat actor appears financially motivated and operates dedicated VPS infrastructure across multiple hosting providers. An additional related vulnerability affecting site-to-site VPN communications was discovered through AI-assisted code analysis, though no has been observed. Immediate patching is strongly recommended for affected systems using IKEv1 protocol.

External references