Critical Check Point VPN Vulnerability Exploited by Ransomware Gang

Critical Check Point VPN Vulnerability Exploited by Ransomware Gang

First seen 8 Jun 2026, 13:54 UTC Feeds2.FeedburnerDigital.Nhs.Ukwww.checkpoint.comBleepingcomputerStocktitan+32 88% similarity 78.8

Article Content

Browse articles
ThreatCluster

Check Point Software Technologies disclosed a critical authentication bypass vulnerability (CVE-2026-50751) affecting its Remote Access VPN and Mobile Access products, with exploitation confirmed since May 7, 2026. The flaw allows unauthenticated attackers to establish VPN sessions without valid credentials by exploiting a logic error in certificate validation, particularly in setups using the deprecated IKEv1 key exchange protocol. The vulnerability has been linked to the Qilin ransomware group, which has targeted several dozen organizations globally. Check Point has released emergency hotfixes and urged affected customers to apply them immediately. A related vulnerability, CVE-2026-50752, was also identified but has not been confirmed as exploited in the wild. The situation poses significant operational risks for organizations still using IKEv1 configurations. CISA has added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by June 11, 2026.

Key Points: • CVE-2026-50751 allows attackers to bypass VPN authentication entirely. • Exploitation linked to the Qilin ransomware group has targeted dozens of organizations. • Emergency hotfixes have been released; affected users must patch immediately.

ThreatCluster AI

Timeline

2024-05-28
CVE-2024-24919 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-07
Exploitation of CVE-2026-50751 begins
Attacks exploiting the authentication bypass vulnerability started on May 7, affecting organizations globally.
Darkreading
2026-06-04
Check Point activates incident response
Check Point began investigating suspicious activities related to the VPN vulnerability after detecting issues on June 4.
Stocktitan
2026-06-08
CVE-2026-50751 disclosed
Check Point publicly disclosed the critical vulnerability and released hotfixes for affected systems.
Bleepingcomputer
2026-06-08
CISA adds CVE-2026-50751 to KEV catalog
CISA mandated federal agencies to secure their Check Point VPN deployments against the exploited vulnerability by June 11.
Bleepingcomputer
2026-06-08
CVE-2026-50752 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-09
Check Point stock slides
Following the vulnerability disclosure, Check Point's stock fell 2.5%, reflecting investor concerns over the active exploitation.
Investing.com

Community

Browse all →