Check Point VPN Flaw Exploited Since Early May
A critical zero-day vulnerability (CVE-2026-50751) in Check Point's Security Gateways and Spark Firewalls has been exploited since early May by a Qilin ransomware affiliate. The flaw, involving a logic flaw in certificate validation, allows attackers to bypass authentication and access internal resources. Check Point has urged customers to immediately patch affected systems to prevent further exploitation.
The vulnerability, tracked as CVE-2026-50751, impacts versions of Check Point's Remote Access VPN and Mobile Access deployments that utilize the IKEv1 key exchange protocol. This protocol, originally created in 1998, is now deprecated and considered insecure. The flaw allows attackers to establish a VPN session without a valid password, effectively bypassing authentication. Further post-authentication activity can be used to access internal resources or escalate privileges. Check Point Research confirmed one instance where the exploitation was linked to Qilin ransomware activity. The threat actor is believed to be financially motivated and is actively exploiting other VPN vulnerabilities from vendors like Palo Alto, Fortinet, and F5. The initial malicious activity was detected on June 4th, with exploitation increasing in early June, prompting Check Point to advise immediate patching and forensic audits.
