Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Check Point VPN Vulnerability Exploited

Critical Check Point VPN Vulnerability Exploited

Posted on June 8, 2026 By CWS

Check Point, a prominent name in cybersecurity, has raised alarms about the active exploitation of a severe vulnerability impacting Remote Access VPN and Mobile Access setups utilizing the obsolete IKEv1 key exchange protocol. This vulnerability is cataloged as CVE-2026-50751 and has been assigned a CVSS score of 9.3, indicating its critical nature.

Details of the Exploited Vulnerability

The flaw identified by Check Point involves a logic weakness in certificate validation. This loophole enables an unauthenticated remote adversary to bypass user authentication, establishing a VPN connection without the need for a valid user password. Although authentication can be bypassed, further activity post-authentication is required for attackers to access internal systems or escalate their privileges.

Products and versions affected by this vulnerability include Security Gateways R82.10 Jumbo Hotfix Take 19 or below, R82 Jumbo Hotfix Take 103 or below, R81.20 Jumbo Hotfix Take 141 or below, and older versions such as R81.10, R81, and R80.40. Also affected are the Spark Firewalls: R80.20.X, R81.10.X, and R82.00.X.

Exploitation Conditions and Observations

Exploitation of this vulnerability necessitates specific conditions: VPN Remote Access or Mobile Access must be enabled, IKEv1 must be active for remote access, legacy Remote Access clients must be accepted, and no machine certificate should be required for connections. Check Point first detected suspicious activities on June 4, 2026, though the exploitation commenced much earlier, around May 7, 2026, with a significant increase in activity noted this month.

The attacks have primarily targeted a limited number of organizations worldwide. In at least one incident, the exploitation was linked to a Qilin ransomware affiliate, suggesting a broader pattern of financially driven cyber threats. Check Point also suspects the use of the Tox protocol for communication by these threat actors, which is a common tactic among ransomware operators.

Infrastructure and Additional Vulnerabilities

The attackers employ virtual private server (VPS) infrastructure, often geolocating servers to specific countries to target organizations within those regions. Upon gaining initial access, they attempt to download malicious ELF files from infrastructure under their control.

In further examinations, a secondary vulnerability, CVE-2026-50752, was discovered. This flaw, with a CVSS score of 7.40, could enable adversary-in-the-middle attacks on VPN site-to-site connections. However, there is currently no evidence indicating this vulnerability has been exploited in real-world scenarios.

The situation underscores the ongoing threat landscape faced by organizations relying on outdated protocols and highlights the importance of staying updated with security patches and employing robust network security measures.

The Hacker News Tags:authentication bypass, Check Point, CVE-2026-50751, cyber attack, Cybersecurity, IKEv1, network security, Ransomware, VPN, Vulnerability

Post navigation

Previous Post: WhatsApp Uncovers NSO’s Alleged Court Order Breach
Next Post: Lansing College Data Breach Affects 174,000 Individuals

Related Posts

The Wild West of Shadow IT The Wild West of Shadow IT The Hacker News
Open Source Web Application Firewall with Zero-Day Detection and Bot Protection Open Source Web Application Firewall with Zero-Day Detection and Bot Protection The Hacker News
Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks The Hacker News
Breeze Comet Exploits Brazilian Payment Systems in Cyber Heists Breeze Comet Exploits Brazilian Payment Systems in Cyber Heists The Hacker News
Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities Experts Detect Pakistan-Linked Cyber Campaigns Aimed at Indian Government Entities The Hacker News
Forg365 PhaaS Exploits Microsoft 365 with Advanced Tactics Forg365 PhaaS Exploits Microsoft 365 with Advanced Tactics The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark