|
What is the Vulnerability? |
A critical authentication bypass vulnerability, CVE-2026-50751 (CVSS 9.3), is being actively exploited against vulnerable Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. The flaw allows unauthenticated attackers to bypass user authentication through a certificate validation logic weakness and establish a VPN session without valid credentials. Check Point has confirmed in-the-wild exploitation and released emergency hot fixes for affected products. Check Point’s investigation identified exploitation activity affecting multiple organizations globally. Public reporting indicates that affiliates of the ransomware operation Qilin have leveraged the vulnerability to gain initial access to targeted environments. Exploitation has reportedly been observed since early May 2026, prior to public disclosure and patch availability. |
|
What is the recommended Mitigation? |
Affected products include Check Point Remote Access VPN, Mobile Access, and Spark Firewall deployments utilizing IKEv1. Organizations running legacy VPN configurations should immediately apply the vendor hotfixes and assess exposed VPN gateways for signs of unauthorized access. • Check Point Remote Access VPN Recommended Actions |
|
What FortiGuard Coverage is available? |
• FortiGuard Antivirus & Behavior Detection: Detects malware and suspicious behaviors associated with ransomware operators and threat actors leveraging compromised VPN access for lateral movement and payload deployment. |





