logo

Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)

ID: 649c2448-c3d7-561b-8ac7-adf1e133f26f

STIX ID: report--649c2448-c3d7-561b-8ac7-adf1e133f26f

Feed Name: Help Net Security

Threat Score
78/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Zeljka Zorz

...
...

WatchTowr disclosed a technical analysis and a Detection Artefact Generator for CVE-2026-50751, an authentication-bypass flaw in Check Point Remote Access VPN and Mobile Access that Check Point confirmed has been actively exploited since early May. A publicly released PoC demonstrates unauthenticated remote login as a provisioned user via manipulated IKEv1 Vendor ID payloads; a few dozen organizations were targeted and at least one incident is linked to a Qilin ransomware affiliate. Check Point published IOCs and hotfixes (including for CVE-2026-50752), and advises immediate patching or disabling legacy IKEv1 and enforcing machine-certificate authentication where patching is not possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.