Critical Check Point VPN flaw exploited to bypass user passwords
- Evelyn Carter

- Jun 10
- 2 min read
An urgent cybersecurity warning has been issued for organizations utilizing Check Point's virtual private network (VPN) solutions. A severe security vulnerability is being actively exploited by cybercriminals to infiltrate corporate networks without requiring valid user passwords.
How does the new Check Point VPN security flaw operate?
Tracked internationally as CVE-2026-50751 with a high severity score of 9.3, this flaw stems from a logic flow weakness in certificate validation. The issue occurs within remote access setups configured to use the deprecated IKEv1 key exchange protocol. An unauthenticated remote attacker can abuse this loophole to bypass standard user authentication requirements entirely, successfully establishing a VPN session without providing a password.

However, once inside the network perimeter, the attacker must still perform additional post-authentication activities to escalate privileges or gain access to deeper internal corporate resources.
Which products and configurations are most vulnerable to this attack?
The security issue impacts multiple gateway and firewall product lines from the vendor. A successful exploitation can only take place if the organization's deployment meets four specific criteria simultaneously:
Remote Access VPN or Mobile Access is enabled
The IKEv1 protocol is activated for remote connections
The gateways accept legacy Remote Access clients
The gateways do not mandate a machine certificate for incoming connections
What activities and damages have cybercriminals carried out so far?
Currently, the attack campaign remains highly targeted, impacting a few dozen organizations globally. Notably, at least one post-exploitation case has been associated with an affiliate of the Qilin ransomware group. The attackers utilized a virtual private server (VPS) infrastructure located within the target country to blend in with legitimate traffic, later attempting to download malicious ELF files from infrastructure under their control.
During further evaluation, experts uncovered a second flaw, CVE-2026-50752 (CVSS score 7.4), which could facilitate adversary-in-the-middle (AitM) attacks on site-to-site VPNs, though no real-world exploitation has been detected. In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-50751 to its Known Exploited Vulnerabilities (KEV) catalog on June 8, 2026, ordering federal agencies to apply necessary patches by June 11, 2026.
How to find a solution to upgrade the “security shield” for your business?
To proactively deal with the risks of data leaks and sophisticated brand impersonation attacks during major event seasons, businesses need a solid security shield.

The management and monitoring system of IPSIP Vietnam has successfully passed the strictest audits to achieve international information security standard certifications ISO 27001:2022 and SOC 2 Type II. By providing 24/7 non-stop core services such as the Cyber Security Monitoring Center (SOC), Network Operations Center (NOC), and an active IT Support/Helpdesk team, IPSIP commits to directly responding to and intercepting all intrusion attempts day and night. The companionship of leading technical minds will help businesses completely eliminate legal risks and free up resources for growth goals.
References:









Comments