Summary
Key Points:
- CVE-2026-50751 is a critical authentication bypass vulnerability in Check Point VPN products, allowing unauthenticated attackers to establish VPN sessions without valid credentials.
- The vulnerability affects Remote Access VPN, Mobile Access, and Spark Firewall products using the deprecated IKEv1 protocol, with a CVSS score of 9.3. Active exploitation has been observed since May 7, 2026, impacting several dozen organizations, including links to Qilin ransomware affiliates.
- Organizations must apply the released hotfixes immediately and consider additional mitigations such as disabling legacy clients and enforcing IKEv2 authentication.
Technical Details: CVE-2026-50751 exploits a logic flow weakness during IKEv1 key exchange, enabling attackers to bypass authentication. Check Point has also identified CVE-2026-50752, which could allow man-in-the-middle attacks but has not yet been exploited.
MITRE ATT&CK Techniques:
- T1078 - Valid Accounts (Initial Access)
- T1190 - Exploit Public-Facing Application (Initial Access)
- T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
IOCs Mentioned:
- IP addresses: 45.77.149[.]152, 209.182.225[.]136, 38.60.157[.]139, 162.33.177[.]101, 45.76.26[.]42, 144.208.127[.]155, 38.54.88[.]201, 38.54.107[.]167, 66.42.99[.]200
- File hash (MD5): 52fda5c1b9704544f32ee98d9060e68951d39aa39478beeac94f2d12f682ecce
Join the discussion — sign up to comment, upvote, and save articles.