Check Point Warns Critical Auth Bypass Bug Exploited in the Wild
ID: 30dd8238-c16d-5e45-b026-767933c69d61
STIX ID: report--30dd8238-c16d-5e45-b026-767933c69d61
Feed Name: Infosecurity Magazine (News)
Check Point disclosed a critical authentication-bypass zero-day (CVE-2026-50751, CVSS 9.3) impacting Remote Access VPN and Mobile Access when configured with deprecated IKEv1; the flaw has been actively exploited since early May and is attributed to a Qilin ransomware affiliate conducting post-compromise activity against a few dozen targeted organizations. During the investigation Check Point also identified a second vulnerability (CVE-2026-50752, CVSS 7.4) affecting IKEv1 certificate validation that is not yet observed in the wild; customers are urged to apply published hotfixes and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
