Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Check Point VPN Flaw Exploited by Ransomware

Critical Check Point VPN Flaw Exploited by Ransomware

Posted on June 9, 2026 By CWS

On Monday, cybersecurity firm Check Point disclosed a severe authentication bypass vulnerability in its VPN and firewall products. This flaw, identified as CVE-2026-50751 with a CVSS score of 9.3, has been actively exploited in the wild as a zero-day threat.

Vulnerability Details and Exploitation

The vulnerability stems from a flawed logic flow in the validation process of Remote Access and Mobile Access certificates. Particularly affecting the deprecated IKEv1 key exchange, it permits unauthorized remote attackers to initiate VPN sessions without needing valid credentials.

Check Point has observed the exploitation of this vulnerability since May 7, with a noticeable rise in activity by early June. The breach has primarily targeted a limited number of organizations worldwide.

Ransomware Connection and Threat Actor Analysis

One confirmed incident involved the Qilin ransomware group, a notorious affiliate known for financially motivated cyberattacks. Check Point’s analysis suggests that this group is also leveraging other VPN-related vulnerabilities from vendors like Palo Alto, Fortinet, and F5.

In addition to CVE-2026-50751, Check Point discovered another issue in the IKEv1 key exchange logic, labeled CVE-2026-50752. Although this second flaw enables man-in-the-middle attacks on VPN site-to-site connections, it has not yet been exploited in the wild.

Response and Mitigation Efforts

Check Point has swiftly released hotfixes to patch these vulnerabilities, providing indicators of compromise (IoCs) and guidance on mitigating the risk. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog, urging prompt action by federal agencies to patch affected systems by June 11.

In light of these developments, organizations using Check Point products are advised to update their systems immediately and follow best practices for cybersecurity to prevent further exploitation.

As cyber threats continue to evolve, it is crucial for organizations to stay informed and proactive in securing their networks against potential vulnerabilities and attacks.

Security Week News Tags:Check Point, CISA, CVE-2026-50751, Cybersecurity, IKEv1, network security, Qilin ransomware, Ransomware, VPN vulnerability, zero-day

Post navigation

Previous Post: Critical SAP NetWeaver Vulnerabilities Fixed in June Patch
Next Post: Microsoft Defender Enhances RPC Protocol Security

Related Posts

Zania Raises  Million for AI-Powered GRC Platform Zania Raises $18 Million for AI-Powered GRC Platform Security Week News
RansomHouse Claims Responsibility for Trellix Cyber Breach RansomHouse Claims Responsibility for Trellix Cyber Breach Security Week News
Rituals Cosmetics Reveals Member Data Breach Incident Rituals Cosmetics Reveals Member Data Breach Incident Security Week News
Decade-Old Pixie Dust Wi-Fi Hack Still Impacts Many Devices Decade-Old Pixie Dust Wi-Fi Hack Still Impacts Many Devices Security Week News
Coralogix Secures 0M to Enhance AI Observability Tools Coralogix Secures $200M to Enhance AI Observability Tools Security Week News
13-Year-Old RCE Flaw Found in Apache ActiveMQ 13-Year-Old RCE Flaw Found in Apache ActiveMQ Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages
  • Unveiling the Hidden Risks in Network Security Operations
  • Microsoft Defender Enhances RPC Protocol Security
  • Critical Check Point VPN Flaw Exploited by Ransomware
  • Critical SAP NetWeaver Vulnerabilities Fixed in June Patch

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Shai-Hulud Supply Chain Attacks Target NPM and PyPI Packages
  • Unveiling the Hidden Risks in Network Security Operations
  • Microsoft Defender Enhances RPC Protocol Security
  • Critical Check Point VPN Flaw Exploited by Ransomware
  • Critical SAP NetWeaver Vulnerabilities Fixed in June Patch

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark