← Back to news

Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)

Rapid7 Blog08/06/2026, 17:05
Read full article →

Summary

AI-Generated

Key Points:

  • CVE-2026-50751 is a critical authentication bypass vulnerability in Check Point VPN products, allowing unauthenticated attackers to establish VPN sessions without valid credentials.
  • The vulnerability affects Remote Access VPN, Mobile Access, and Spark Firewall products using the deprecated IKEv1 protocol, with a CVSS score of 9.3. Active exploitation has been observed since May 7, 2026, impacting several dozen organizations, including links to Qilin ransomware affiliates.
  • Organizations must apply the released hotfixes immediately and consider additional mitigations such as disabling legacy clients and enforcing IKEv2 authentication.

Technical Details: CVE-2026-50751 exploits a logic flow weakness during IKEv1 key exchange, enabling attackers to bypass authentication. Check Point has also identified CVE-2026-50752, which could allow man-in-the-middle attacks but has not yet been exploited.

MITRE ATT&CK Techniques:

  • T1078 - Valid Accounts (Initial Access)
  • T1190 - Exploit Public-Facing Application (Initial Access)
  • T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)

IOCs Mentioned:

  • IP addresses: 45.77.149[.]152, 209.182.225[.]136, 38.60.157[.]139, 162.33.177[.]101, 45.76.26[.]42, 144.208.127[.]155, 38.54.88[.]201, 38.54.107[.]167, 66.42.99[.]200
  • File hash (MD5): 52fda5c1b9704544f32ee98d9060e68951d39aa39478beeac94f2d12f682ecce

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.