AI Stories on SHORT INFO are generated & curated with AI
unverified 23 Jun, 06:10

Check Point VPN zero-day CVE-2026-50751 CVSS 9.3 auth bypass exploited by Qilin ransomware emergency hotfix

Any org running Check Point Remote Access VPN on the legacy IKEv1 protocol is exposed now. CVE-2026-50751 (CVSS 9.3) lets an unauthenticated attacker open a VPN session with no valid credentials. Check Point $CHKP shipped an emergency hotfix June 8; Qilin ransomware is already ex

Network defenders have an emergency on their hands. Check Point disclosed CVE-2026-50751 on June 8, a critical authentication bypass affecting its Remote Access VPN, Mobile Access, and Spark Firewall products. The flaw carries a CVSS score of 9.3, near the top of the severity scale. The vulnerability lives in deployments still configured to use the deprecated IKEv1 key exchange protocol, where gateways accept legacy remote access clients without requiring a machine certificate. Because of a logic flaw in how those components validate certificates, an unauthenticated attacker can establish a VPN session without supplying any valid credentials, effectively walking through the front door of the corporate network. This is not theoretical. Check Point $CHKP has observed active exploitation in the wild, with attempts climbing in early June. The activity is attributed with medium confidence to a financially motivated actor deploying Qilin ransomware. Several of the affected version branches have already reached end of support, leaving some organizations without a straightforward patch path. Check Point has released hotfixes for all supported releases and is urging administrators to apply them on an emergency basis rather than waiting for a regular patch cycle. Sources: Check Point, Rapid7.

Published on
ThreadsFacebookXBluesky