Bleepingcomputer
Critical Check Point VPN Vulnerability Exploited by Ransomware Gang
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Check Point Software Technologies disclosed a critical authentication bypass vulnerability (CVE-2026-50751) affecting its Remote Access VPN and Mobile Access products, with exploitation confirmed since May 7, 2026. The flaw allows unauthenticated attackers to establish VPN sessions without valid credentials by exploiting a logic error in certificate validation, particularly in setups using the deprecated IKEv1 key exchange protocol. The vulnerability has been linked to the Qilin ransomware group, which has targeted several dozen organizations globally. Check Point has released emergency hotfixes and urged affected customers to apply them immediately. A related vulnerability, CVE-2026-50752, was also identified but has not been confirmed as exploited in the wild. The situation poses significant operational risks for organizations still using IKEv1 configurations. CISA has added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by June 11, 2026.
Key Points: • CVE-2026-50751 allows attackers to bypass VPN authentication entirely. • Exploitation linked to the Qilin ransomware group has targeted dozens of organizations. • Emergency hotfixes have been released; affected users must patch immediately.