Check Point Patches Critical VPN Zero-Day CVE-2026-50751 After a Month of Exploitation Tied to a Qilin Ransomware Affiliate
A logic flaw in Check Point's deprecated IKEv1 certificate validation let attackers bypass VPN authentication. CISA added it to KEV with a June 11 deadline.
Editor's Note ·
- Clarification:
- Two of the article's six cited sources fall outside The Machine Herald's editorial source allowlist: the Check Point advisory (blog.checkpoint.com) and Field Effect (fieldeffect.com). Both are credible primary sources — Check Point is the affected vendor and Field Effect is an established security firm — and every claim drawn from them (the 'few dozen organizations' figure, the medium-confidence Qilin attribution, the May 7 / June 4 / June 8 timeline, and the CVE-2026-50752 details) is independently corroborated by allowlisted or government primary sources (Rapid7, NVD, and the CISA KEV catalog).
Overview
Check Point has released emergency hotfixes for a critical authentication-bypass flaw in its remote-access VPN products after detecting that attackers had been quietly exploiting the vulnerability for roughly a month. The flaw, tracked as CVE-2026-50751, lets an unauthenticated remote attacker establish a VPN session without a valid password by abusing a logic error in certificate validation, according to the company’s official advisory. The U.S. Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalog on June 8, 2026, setting a federal remediation deadline of June 11, per the CISA KEV catalog.
What We Know
The vulnerability carries a CVSS 3.1 base score of 9.3, with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N, according to the National Vulnerability Database. NVD describes it as “A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange [that] allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.” The flaw is classified under CWE-287 (improper authentication), as noted by Rapid7.
The defect lies specifically in the deprecated IKEv1 key-exchange protocol. Check Point describes the issue as a “logic flow weakness in the Remote Access and Mobile Access certificate validation” that lets an attacker “establish a remote access VPN connection without a valid user password,” according to its advisory. Rapid7 reports the affected products as Check Point Remote Access VPN, Mobile Access, and Spark Firewall, spanning versions R80.20.X, R80.40, R81, R81.10, R81.10.X, R81.20, R82, R82.00.X, and R82.10.
The exploitation predates the public disclosure by weeks. Field Effect lays out the timeline: the earliest observed exploitation dates to May 7, 2026; Check Point detected suspicious activity on June 4; and the company publicly reported the issue and released hotfixes on June 8. The Next Web frames the same sequence as attackers having a roughly one-month head start before a patch existed.
Check Point characterizes the campaign as narrow. “To date, the observed exploitation has been limited to a few dozen targeted organizations globally,” the company states in its advisory.
The Ransomware Connection
At least one intrusion has been tied to ransomware. “One case involved confirmed post-compromise activity associated with Qilin ransomware affiliate,” Check Point states in its advisory, which assesses with medium confidence that the actor uses Qilin ransomware. Rapid7 similarly notes that “At least one incident has been linked to a Qilin ransomware affiliate, which Check Point assesses with medium confidence.” Qilin is a financially motivated ransomware-as-a-service operation that has been active since 2022, according to Field Effect, which adds that observed post-compromise activity included data exfiltration using Rclone and communication over the Tox protocol.
CISA’s catalog entry marks the flaw with a “Known” ransomware-campaign-use status, reinforcing that the bug is not a theoretical risk, per the CISA KEV catalog.
Remediation
Check Point has released hotfixes and urges affected organizations to “apply the available updates on an emergency basis,” according to Rapid7. For organizations that cannot patch immediately, Rapid7 lists alternative mitigations: removing legacy client support, configuring authentication to IKEv2 only, mandating machine certificates, and enabling IPS with the latest signatures. CISA’s required action is to “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable,” per the CISA KEV catalog.
Check Point disclosed a second, related flaw alongside the actively exploited one. CVE-2026-50752, rated CVSS 7.4, is described in the advisory as a condition in IKEv1 certificate-validation logic that “can allow a man-in-the-middle attack on VPN site-to-site connections.” Check Point states it has not observed exploitation of that vulnerability in the wild.
What We Don’t Know
Check Point’s attribution of the intrusions to a Qilin affiliate is held at medium confidence, and the company has not publicly identified the targeted organizations or quantified how many of the “few dozen” affected entities suffered a full compromise versus a blocked attempt. The advisory does not detail how many of the impacted deployments were running end-of-support versions, several of which appear in the affected-version list. It also remains unclear whether the May 7 date marks the true start of the campaign or simply the earliest activity Check Point has so far reconstructed.