Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
ID: 3cb40b39-eace-5b57-889d-16f946b398b1
STIX ID: report--3cb40b39-eace-5b57-889d-16f946b398b1
Feed Name: The Hacker News
Threat Score
Check Point disclosed active exploitation of a critical IKEv1 certificate-validation logic flaw (CVE-2026-50751, CVSS 9.3) that allows unauthenticated attackers to bypass VPN authentication and establish remote access sessions; exploitation has been observed since May 2026 against a few dozen targeted organizations, linked in at least one case to a Qilin ransomware affiliate, prompting CISA to add the flaw to its Known Exploited Vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
