Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenAI Expands GPT-3.5 Access With Unlimited Chats for All Users
August 7, 2026
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Home/CyberSecurity News/Critical Check Point VPN Zero-Day Exploited to Deploy Ransomware
CyberSecurity News

Critical Check Point VPN Zero-Day Exploited to Deploy Ransomware

Key Takeaways A critical authentication bypass vulnerability (CVE-2026-50751) in Check Point VPN products is actively being exploited. The Qilin ransomware gang is leveraging this zero-day to gain...

Sarah simpson
Sarah simpson
June 8, 2026 3 Min Read
47 0

Key Takeaways

  • A critical authentication bypass vulnerability (CVE-2026-50751) in Check Point VPN products is actively being exploited.
  • The Qilin ransomware gang is leveraging this zero-day to gain initial access and deploy ransomware.
  • The flaw specifically affects Check Point Remote Access VPN and Mobile Access deployments configured with the outdated IKEv1 protocol.
  • A hotfix is available, and Check Point urges all customers to apply it immediately.

Check Point VPN Zero-Day Actively Exploited by Qilin Ransomware Group

Check Point Research has confirmed active exploitation of a severe authentication bypass vulnerability, identified as CVE-2026-50751, within its Remote Access VPN and Mobile Access products. This critical flaw, boasting a CVSS score of 9.3, has been linked to post-compromise activities orchestrated by the Qilin ransomware gang.

Table Of Content

  • Key Takeaways
  • Check Point VPN Zero-Day Actively Exploited by Qilin Ransomware Group
  • The Critical Flaw: CVE-2026-50751
  • Qilin Ransomware’s Involvement and Tactics
  • Second Vulnerability – CVE-20752
  • Indicators of Compromise (IOCs)
  • What You Should Do

The Critical Flaw: CVE-2026-50751

The vulnerability, CVE-2026-50751, specifically targets deployments that still utilize the deprecated IKEv1 key exchange protocol. Attackers can exploit a logic error in the certificate validation process, allowing an unauthorized remote actor to establish a VPN session without providing valid user credentials. This effectively circumvents all configured authentication mechanisms.

Affected products include Mobile Access / SSL VPN, Remote Access VPN, and Spark Firewall across versions R80.20.X through R82.10. While the bypass grants initial network access, threat actors must perform additional post-authentication steps to reach internal resources or elevate their privileges.

Check Point Research initiated its investigation on June 4, 2026, after detecting suspicious activity. Their findings indicate that exploitation attempts began as early as May 7, 2026. A significant surge in these attempts was observed in early June 2026, impacting dozens of organizations globally. Incident response teams are advised to conduct thorough forensic log audits and configuration reviews, extending back to the initial exploitation date.

Qilin Ransomware’s Involvement and Tactics

The threat actor behind these attacks is believed to be financially motivated, operating with medium confidence. Evidence suggests the use of Qilin Linux ransomware binaries and attempts to download malicious ELF files from infrastructure controlled by the attackers. The group likely employs the Tox protocol for command-and-control communications, a common tactic among ransomware operators. There are also indications that this actor is simultaneously exploiting VPN vulnerabilities previously disclosed in products from Palo Alto, Fortinet, and F5.

Attacker infrastructure has been traced to hosting providers such as Kaupo Cloud HK, Shock Hosting, and Vultr Holdings. In several instances, the geolocation of the Virtual Private Servers (VPS) correlated with the geographical location of the victims.

Second Vulnerability – CVE-20752

During the investigation into CVE-2026-50751, Check Point’s advanced AI code security platform, BLAST, identified a related vulnerability: CVE-2026-50752. This flaw, rated with a CVSS score of 7.4, also impacts certificate validation within the deprecated IKEv1 key exchange. Under specific circumstances, it could enable man-in-the-middle (MitM) attacks on site-to-site VPN communications. Although no active exploitation of CVE-2026-50752 has been observed, customers are strongly encouraged to apply updates as a proactive measure.

CVE Description CVSS Affected Products In the Wild
CVE-2026-50751 Auth bypass via IKEv1 certificate validation flaw 9.3 Mobile Access/SSL VPN, Remote Access VPN, Spark Firewall YES
CVE-2026-50752 MitM condition in IKEv1 certificate validation 7.4 Security Gateways, Spark Firewall NO

Indicators of Compromise (IOCs)

Malicious IPs:

  • 45.77.149[.]152
  • 209.182.225[.]136
  • 38.60.157[.]139
  • 162.33.177[.]101
  • 45.76.26[.]42
  • 144.208.127[.]155
  • 38.54.88[.]201
  • 38.54.107[.]167
  • 66.42.99[.]200

File Hashes (MD5):

  • 52fda5c1b9704544f32ee98d9060e689
  • 51d39aa39478beeac94f2d12f682ecce

What You Should Do

Check Point strongly advises all customers using affected versions to immediately apply the hotfix released for their Security Gateways. For organizations unable to patch instantly, the following interim mitigation steps are recommended:

  • Discontinue support for legacy remote access clients.
  • Configure Remote Access VPN Authentication to exclusively use IKEv2.
  • Enforce Machine Certificate Authentication as a mandatory requirement.
  • Enable IPS and ensure the latest signatures are downloaded and applied.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchransomwareSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Linux Kernel Privilege Escalation Vulnerability (CVE-2024-XXXX) Found

Next Post

China-Linked OP-512 Targets IIS Servers With Unique Web Shell Framework

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best Intrusion Detection & Prevention (IDS/IPS) Tools for 2026
August 6, 2026
Critical WSUS Vulnerability Lets Attackers Compromise Enterprise Endpoints
August 6, 2026
Critical Paperclip Flaws Let Attackers Gain Admin Access
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us