news.mlab.sh
Back to the feed
vulnerability

Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups

Critical
Summary

Check Point has identified and warned of a critical vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access products, allowing unauthenticated attackers to bypass password authentication when using the IKEv1 protocol. This flaw has been actively exploited, with evidence linking it to a Qilin ransomware affiliate and broader reconnaissance activities. The vulnerability highlights the ongoing risk associated with legacy VPN configurations.

The vulnerability, rated 9.3 on the CVSS scale, stems from a logic flaw in certificate validation, enabling attackers to establish VPN sessions without valid user credentials. Check Point reported initial suspicious activity on June 4, 2026, with exploitation beginning as early as May 7, 2026, and escalating this month. The company estimates that only a "few dozen targeted organizations globally" have been affected. The exploitation is being conducted through the use of VPS infrastructure, primarily targeting organizations within specific geographic locations, and appears to be part of a coordinated effort to identify and exploit other VPN vulnerabilities, including those from Palo Alto Networks and Fortinet. Furthermore, the investigation uncovered a second vulnerability, CVE-2026-50752, which could facilitate an adversary-in-the-middle attack on site-to-site VPN connections, though this has not yet been observed in active attacks.

Read the full article at The Hacker News