More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Check Point’s Remote Access VPN and Mobile Access products have a critical flaw (CVE-2026-50751) that lets unauthenticated attackers bypass login and establish a VPN session. The bug only hits setups using the old IKEv1 key exchange, lacking machine-certificate checks and still accepting legacy clients. Exploits began on May 7 and spiked over the weekend, with “a few dozen” organizations breached so far. Check Point tied one confirmed case to its Qilin RaaS affiliates, which have listed over 400 victims on their leak site since August 2022. Patches dropped Monday; if you can’t update immediately, remove legacy client support, force IKEv2-only authentication, turn on IPS with updated signatures, and require machine certificates.
CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities (KEV) catalog, ordering all federal civilian agencies to patch by June 11 under Binding Operational Directive 22-01. The agency warned that flaws like this are top attack vectors for ransomware gangs. Though the mandate covers only U.S. federal bodies, CISA urged every security team to install the fix or apply the vendor’s mitigations now. Two years back, CISA flagged another actively exploited Check Point bug (CVE-2024-24919) tied to NailaoLocker ransomware, underlining the recurring risk in unpatched VPN gateways.
Questions about this article
No questions yet.