AI Stories on SHORT INFO are generated & curated with AI
unverified 17 Jun, 15:14

Check Point VPN flaw CVE-2026-50751 abused by Qilin ransomware affiliate, CISA orders emergency federal hotfix within three days

Organizations running Check Point $CHKP Remote Access VPN on the legacy IKEv1 protocol are exposed to an authentication bypass that has been exploited since early May. CVE-2026-50751 lets remote attackers connect without a valid password. CISA gave US federal agencies three days

Organizations that rely on Check Point Software $CHKP Remote Access VPN have an urgent patching job. The company disclosed CVE-2026-50751 on June 8, a critical authentication bypass that allows a remote, unauthenticated attacker to establish a VPN connection without a valid user password. The flaw, rated 9.3 on the severity scale, stems from how the Remote Access and Mobile Access components validate certificates during the deprecated IKEv1 key exchange. Deployments that still accept legacy clients and do not require a machine certificate are the ones at risk, and the Spark Firewall line is affected as well. What makes this more than a routine advisory is the timeline. Check Point says exploitation began on May 7 and surged over the weekend before the fix shipped, which gave attackers a long head start. The company has linked at least one intrusion to the Qilin ransomware operation, and researchers believe a Qilin affiliate is behind a cluster of the attacks. So far the activity has touched a few dozen organizations worldwide rather than becoming mass exploitation, but the US Cybersecurity and Infrastructure Security Agency considered it serious enough to order federal agencies to patch within three days, a tighter deadline than its usual guidance. Check Point has released hotfixes, and the practical step for affected administrators is to apply them on an emergency basis and move away from IKEv1 where possible.

Published on
FacebookBlueskyThreadsX