Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Check Point VPN Flaw Exploited by Ransomware

Critical Check Point VPN Flaw Exploited by Ransomware

Posted on June 9, 2026 By CWS

On Monday, cybersecurity firm Check Point disclosed a severe authentication bypass vulnerability in its VPN and firewall products. This flaw, identified as CVE-2026-50751 with a CVSS score of 9.3, has been actively exploited in the wild as a zero-day threat.

Vulnerability Details and Exploitation

The vulnerability stems from a flawed logic flow in the validation process of Remote Access and Mobile Access certificates. Particularly affecting the deprecated IKEv1 key exchange, it permits unauthorized remote attackers to initiate VPN sessions without needing valid credentials.

Check Point has observed the exploitation of this vulnerability since May 7, with a noticeable rise in activity by early June. The breach has primarily targeted a limited number of organizations worldwide.

Ransomware Connection and Threat Actor Analysis

One confirmed incident involved the Qilin ransomware group, a notorious affiliate known for financially motivated cyberattacks. Check Point’s analysis suggests that this group is also leveraging other VPN-related vulnerabilities from vendors like Palo Alto, Fortinet, and F5.

In addition to CVE-2026-50751, Check Point discovered another issue in the IKEv1 key exchange logic, labeled CVE-2026-50752. Although this second flaw enables man-in-the-middle attacks on VPN site-to-site connections, it has not yet been exploited in the wild.

Response and Mitigation Efforts

Check Point has swiftly released hotfixes to patch these vulnerabilities, providing indicators of compromise (IoCs) and guidance on mitigating the risk. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog, urging prompt action by federal agencies to patch affected systems by June 11.

In light of these developments, organizations using Check Point products are advised to update their systems immediately and follow best practices for cybersecurity to prevent further exploitation.

As cyber threats continue to evolve, it is crucial for organizations to stay informed and proactive in securing their networks against potential vulnerabilities and attacks.

Security Week News Tags:Check Point, CISA, CVE-2026-50751, Cybersecurity, IKEv1, network security, Qilin ransomware, Ransomware, VPN vulnerability, zero-day

Post navigation

Previous Post: Critical SAP NetWeaver Vulnerabilities Fixed in June Patch
Next Post: Microsoft Defender Enhances RPC Protocol Security

Related Posts

US Announces 0 Million for State, Local and Tribal Cybersecurity US Announces $100 Million for State, Local and Tribal Cybersecurity Security Week News
Cybersecurity M&A Roundup: 41 Deals Announced in June 2025 Cybersecurity M&A Roundup: 41 Deals Announced in June 2025 Security Week News
New AI Jailbreak Bypasses Guardrails With Ease New AI Jailbreak Bypasses Guardrails With Ease Security Week News
Bitcoin Depot Faces .6 Million Cyber Heist Bitcoin Depot Faces $3.6 Million Cyber Heist Security Week News
MCP Flaw in AI Systems Risks Major Supply Chain Attacks MCP Flaw in AI Systems Risks Major Supply Chain Attacks Security Week News
Anthropic Addresses Claude Code Sandbox Flaw Quietly Anthropic Addresses Claude Code Sandbox Flaw Quietly Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark