Critical Check Point VPN Zero-Day Exploited to Deploy Ransomware
Key Takeaways A critical authentication bypass vulnerability (CVE-2026-50751) in Check Point VPN products is actively being exploited. The Qilin ransomware gang is leveraging this zero-day to gain...
Key Takeaways
- A critical authentication bypass vulnerability (CVE-2026-50751) in Check Point VPN products is actively being exploited.
- The Qilin ransomware gang is leveraging this zero-day to gain initial access and deploy ransomware.
- The flaw specifically affects Check Point Remote Access VPN and Mobile Access deployments configured with the outdated IKEv1 protocol.
- A hotfix is available, and Check Point urges all customers to apply it immediately.
Check Point VPN Zero-Day Actively Exploited by Qilin Ransomware Group
Check Point Research has confirmed active exploitation of a severe authentication bypass vulnerability, identified as CVE-2026-50751, within its Remote Access VPN and Mobile Access products. This critical flaw, boasting a CVSS score of 9.3, has been linked to post-compromise activities orchestrated by the Qilin ransomware gang.
Table Of Content
The Critical Flaw: CVE-2026-50751
The vulnerability, CVE-2026-50751, specifically targets deployments that still utilize the deprecated IKEv1 key exchange protocol. Attackers can exploit a logic error in the certificate validation process, allowing an unauthorized remote actor to establish a VPN session without providing valid user credentials. This effectively circumvents all configured authentication mechanisms.
Affected products include Mobile Access / SSL VPN, Remote Access VPN, and Spark Firewall across versions R80.20.X through R82.10. While the bypass grants initial network access, threat actors must perform additional post-authentication steps to reach internal resources or elevate their privileges.
Check Point Research initiated its investigation on June 4, 2026, after detecting suspicious activity. Their findings indicate that exploitation attempts began as early as May 7, 2026. A significant surge in these attempts was observed in early June 2026, impacting dozens of organizations globally. Incident response teams are advised to conduct thorough forensic log audits and configuration reviews, extending back to the initial exploitation date.
Qilin Ransomware’s Involvement and Tactics
The threat actor behind these attacks is believed to be financially motivated, operating with medium confidence. Evidence suggests the use of Qilin Linux ransomware binaries and attempts to download malicious ELF files from infrastructure controlled by the attackers. The group likely employs the Tox protocol for command-and-control communications, a common tactic among ransomware operators. There are also indications that this actor is simultaneously exploiting VPN vulnerabilities previously disclosed in products from Palo Alto, Fortinet, and F5.
Attacker infrastructure has been traced to hosting providers such as Kaupo Cloud HK, Shock Hosting, and Vultr Holdings. In several instances, the geolocation of the Virtual Private Servers (VPS) correlated with the geographical location of the victims.
Second Vulnerability – CVE-20752
During the investigation into CVE-2026-50751, Check Point’s advanced AI code security platform, BLAST, identified a related vulnerability: CVE-2026-50752. This flaw, rated with a CVSS score of 7.4, also impacts certificate validation within the deprecated IKEv1 key exchange. Under specific circumstances, it could enable man-in-the-middle (MitM) attacks on site-to-site VPN communications. Although no active exploitation of CVE-2026-50752 has been observed, customers are strongly encouraged to apply updates as a proactive measure.
| CVE | Description | CVSS | Affected Products | In the Wild |
|---|---|---|---|---|
| CVE-2026-50751 | Auth bypass via IKEv1 certificate validation flaw | 9.3 | Mobile Access/SSL VPN, Remote Access VPN, Spark Firewall | YES |
| CVE-2026-50752 | MitM condition in IKEv1 certificate validation | 7.4 | Security Gateways, Spark Firewall | NO |
Indicators of Compromise (IOCs)
Malicious IPs:
- 45.77.149[.]152
- 209.182.225[.]136
- 38.60.157[.]139
- 162.33.177[.]101
- 45.76.26[.]42
- 144.208.127[.]155
- 38.54.88[.]201
- 38.54.107[.]167
- 66.42.99[.]200
File Hashes (MD5):
52fda5c1b9704544f32ee98d9060e68951d39aa39478beeac94f2d12f682ecce
What You Should Do
Check Point strongly advises all customers using affected versions to immediately apply the hotfix released for their Security Gateways. For organizations unable to patch instantly, the following interim mitigation steps are recommended:
- Discontinue support for legacy remote access clients.
- Configure Remote Access VPN Authentication to exclusively use IKEv2.
- Enforce Machine Certificate Authentication as a mandatory requirement.
- Enable IPS and ensure the latest signatures are downloaded and applied.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.