Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical VPN Vulnerability Exploited to Deploy Ransomware

Critical VPN Vulnerability Exploited to Deploy Ransomware

Posted on June 8, 2026 By CWS

Check Point Research has identified the active exploitation of a significant security flaw, CVE-2026-50751, affecting Check Point’s Remote Access VPN and Mobile Access products. This vulnerability, rated 9.3 on the CVSS scale, is being used by cybercriminals associated with the Qilin ransomware group to compromise systems.

Vulnerability Details and Impact

The vulnerability targets configurations using the outdated IKEv1 key exchange protocol. Exploiting a weakness in certificate validation, attackers can initiate a VPN session without a valid password, bypassing authentication entirely. The affected products include Mobile Access/SSL VPN, Remote Access VPN, and Spark Firewall, spanning versions from R80.20.X to R82.10.

While the initial breach occurs through this authentication bypass, further actions are necessary for attackers to access internal systems or elevate privileges. Check Point began investigating on June 4, 2026, following unusual activity, with exploitation efforts traced back to May 7, 2026.

Exploitation and Response

Exploitation incidents surged in early June 2026, impacting several dozen organizations worldwide. Security teams are advised to prioritize forensic audits of logs and review configurations from the earliest observed exploitation date. The attackers are believed to be financially motivated, deploying Qilin Linux ransomware binaries and attempting to download malicious ELF files from their controlled infrastructure.

The threat actors likely utilize the Tox protocol for command-and-control, a method frequently linked to ransomware operations. The same attackers are suspected of exploiting VPN vulnerabilities in products by Palo Alto, Fortinet, and F5. Their infrastructure was found across hosting services like Kaupo Cloud HK, Shock Hosting, and Vultr Holdings, with server locations often matching victim locations.

Related Vulnerability and Mitigation Measures

During the investigation of CVE-2026-50751, a related flaw, CVE-2026-50752, was discovered by Check Point’s AI code security platform, BLAST. This vulnerability affects IKEv1 certificate validation, potentially enabling man-in-the-middle attacks on site-to-site VPN communications. While not yet exploited, customers are strongly advised to apply updates promptly.

Check Point recommends immediate application of their hotfix for affected Security Gateways. Those unable to patch immediately should consider disabling support for legacy remote access clients, configuring authentication to IKEv2, enforcing machine certificate authentication, and enabling IPS with the latest signatures.

For further updates, follow Check Point on Google News, LinkedIn, and X.

Cyber Security News Tags:Check Point, CVE-2026-50751, Cybersecurity, Exploitation, IKEv1 protocol, network security, Qilin ransomware, Ransomware, security update, VPN vulnerability

Post navigation

Previous Post: Anthropic Calls for Unified AI Development Pause Amid Risks
Next Post: China-Linked Group OP-512 Exploits IIS Servers

Related Posts

PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access Cyber Security News
Seraphic Becomes the First and Only Secure Enterprise Browser Solution to Protect Electron-Based Applications Seraphic Becomes the First and Only Secure Enterprise Browser Solution to Protect Electron-Based Applications Cyber Security News
Global Outage Disrupts Microsoft Exchange Online Access Global Outage Disrupts Microsoft Exchange Online Access Cyber Security News
NPM Supply Chain Breach via Binding.gyp Exploitation NPM Supply Chain Breach via Binding.gyp Exploitation Cyber Security News
New Phantom Stealer Campaign Hits Windows Machines Through ISO Mounting New Phantom Stealer Campaign Hits Windows Machines Through ISO Mounting Cyber Security News
Researchers Unmasked Russia’s Most Secretive FSB’s Spy Network Researchers Unmasked Russia’s Most Secretive FSB’s Spy Network Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark