BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical Check Point VPN Flaw Actively Exploited

Critical VPN flaw bypasses authentication, exploited by Qilin ransomware affiliate targeting organizations.

  • Check Point warns of active exploitation of CVE-2026-50751, a critical VPN authentication bypass vulnerability.
  • The flaw affects Remote Access VPN deployments using the deprecated IKEv1 protocol, allowing connection without a valid password.
  • Exploitation has been linked to a Qilin ransomware affiliate and involves VPS infrastructure for targeted attacks.
  • A second vulnerability, CVE-2026-50752, enabling a site-to-site VPN AitM attack, has been identified but not yet exploited.

Check Point security researchers issued a critical alert in June 2026 after detecting active exploitation of a severe flaw in its VPN products. The vulnerability, which bypasses user authentication, is being leveraged by threat actors targeting a select number of global organizations.

- Advertisement -

The security weakness, tracked as CVE-2026-50751, is a logic flaw in certificate validation. Consequently, an unauthenticated attacker can establish a remote access VPN session without possessing a valid user password. “By exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements,” Check Point said.

The issue impacts several versions of Security Gateways and Spark Firewalls where specific conditions are met. These include having VPN Remote Access enabled and accepting the legacy IKEv1 key exchange protocol.

Check Point first observed suspicious activity on June 4, 2026, with the earliest exploitation dating to May 7. Meanwhile, post-exploitation activity in one case has been associated with a Qilin ransomware affiliate.

The attackers are reportedly using virtual private server infrastructure to conduct their campaigns. Furthermore, their methods overlap with recent reports on ransomware groups abusing corporate VPNs for initial access.

- Advertisement -

A second vulnerability, CVE-2026-50752, was discovered during the review. This flaw may allow an adversary-in-the-middle attack on VPN site-to-site connections, though it has not been seen exploited in the wild.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Holds $60K Support as Macro Headwinds Mount

Bitcoin is testing the crucial $60,000 support level as Wall Street trading resumes.Analysts are...

SBF Seeks Presidential Pardon from Trump

Sam Bankman-Fried has publicly expressed his desire for a presidential pardon from Donald Trump,...

BitMine Buys $214 Million Worth of ETH Despite Market Slump

BitMine Immersion Technologies acquired 126,971 ETH worth approximately $214 million last week, marking its...

Schiff Accuses MSTR of Share Dilution in Bitcoin Buy

Strategy Inc. purchased 1,550 Bitcoin for $101.3 million, increasing its total holdings to 845,256...

Strive’s $50M Treasury Bet Loses 3.7% in 3 Months

Strive Inc. purchased $50 million of Strategy's STRC stock in March to replace "idle...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading