Last Updated: 2026-06-08T18:30:00Z
What’s Happening
Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol.
By exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements.
Vendor blogpost Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) - Check Point Blog
Vendor security advisory: CVE-2026-50751 - User Authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange
Actions
- Determine if you are using a vulnerable configuration.
- If vulnerable, proceed to patching or mitigating while also following the hunting guide to look for an existing compromise.
Notes
The earliest observed exploitation so far is 2026-05-07T00:00:00Z.
Check Point assesses with medium confidence that the actor exploiting this vulnerability is financially motivated and uses Qilin ransomware. The actor uses infrastructure hosted in the networks of Kaupo Cloud HK (AS138915), Shock Hosting (AS395092), and Vultr Holdings (AS20473).
Check Point published a list of IP’s and MD5 file hashes as Indicators of Compromise. One of the file hashes refers to rclone v1.73.4.