Check Point VPN zero-day CVE-2026-50751 (CVSS 9.3) auth bypass exploited via deprecated IKEv1, linked to Qilin ransomware, CISA KEV deadline June 11
Check Point $CHKP firewalls using the deprecated IKEv1 protocol can be reached without a valid password. CVE-2026-50751 (CVSS 9.3) has been exploited since May 7, one case tied to Qilin ransomware. CISA set a June 11 federal patch deadline. Source: Check Point sk185033, cisa.gov/
Organizations running Check Point Remote Access VPN, Mobile Access, or the company's Spark firewalls may be exposed if those products are configured to use the deprecated IKEv1 key exchange protocol. According to a security advisory from Check Point $CHKP, a logic flaw in certificate validation allows an attacker to establish a VPN session without possessing a valid password. The vulnerability is tracked as CVE-2026-50751 and carries a CVSS severity score of 9.3. Check Point Research reports the flaw has been under active exploitation, with the earliest observed activity dating to May 7, 2026, and the first indications of suspicious activity detected on June 4. The company states the exploitation has so far been limited to a few dozen targeted organizations worldwide. In one case, Check Point observed post-compromise activity associated with an affiliate of the Qilin ransomware operation, and assesses with medium confidence that the actor is financially motivated. The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog on June 8, 2026, requiring federal civilian agencies to apply the fixes by June 11. Check Point has released security updates and advises customers using the IKEv1 protocol to apply them immediately. Source: Check Point advisory sk185033 and cisa.gov/kev.