Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Check Point VPN Vulnerability Exploited

Critical Check Point VPN Vulnerability Exploited

Posted on June 8, 2026 By CWS

Check Point, a prominent name in cybersecurity, has raised alarms about the active exploitation of a severe vulnerability impacting Remote Access VPN and Mobile Access setups utilizing the obsolete IKEv1 key exchange protocol. This vulnerability is cataloged as CVE-2026-50751 and has been assigned a CVSS score of 9.3, indicating its critical nature.

Details of the Exploited Vulnerability

The flaw identified by Check Point involves a logic weakness in certificate validation. This loophole enables an unauthenticated remote adversary to bypass user authentication, establishing a VPN connection without the need for a valid user password. Although authentication can be bypassed, further activity post-authentication is required for attackers to access internal systems or escalate their privileges.

Products and versions affected by this vulnerability include Security Gateways R82.10 Jumbo Hotfix Take 19 or below, R82 Jumbo Hotfix Take 103 or below, R81.20 Jumbo Hotfix Take 141 or below, and older versions such as R81.10, R81, and R80.40. Also affected are the Spark Firewalls: R80.20.X, R81.10.X, and R82.00.X.

Exploitation Conditions and Observations

Exploitation of this vulnerability necessitates specific conditions: VPN Remote Access or Mobile Access must be enabled, IKEv1 must be active for remote access, legacy Remote Access clients must be accepted, and no machine certificate should be required for connections. Check Point first detected suspicious activities on June 4, 2026, though the exploitation commenced much earlier, around May 7, 2026, with a significant increase in activity noted this month.

The attacks have primarily targeted a limited number of organizations worldwide. In at least one incident, the exploitation was linked to a Qilin ransomware affiliate, suggesting a broader pattern of financially driven cyber threats. Check Point also suspects the use of the Tox protocol for communication by these threat actors, which is a common tactic among ransomware operators.

Infrastructure and Additional Vulnerabilities

The attackers employ virtual private server (VPS) infrastructure, often geolocating servers to specific countries to target organizations within those regions. Upon gaining initial access, they attempt to download malicious ELF files from infrastructure under their control.

In further examinations, a secondary vulnerability, CVE-2026-50752, was discovered. This flaw, with a CVSS score of 7.40, could enable adversary-in-the-middle attacks on VPN site-to-site connections. However, there is currently no evidence indicating this vulnerability has been exploited in real-world scenarios.

The situation underscores the ongoing threat landscape faced by organizations relying on outdated protocols and highlights the importance of staying updated with security patches and employing robust network security measures.

The Hacker News Tags:authentication bypass, Check Point, CVE-2026-50751, cyber attack, Cybersecurity, IKEv1, network security, Ransomware, VPN, Vulnerability

Post navigation

Previous Post: WhatsApp Uncovers NSO’s Alleged Court Order Breach
Next Post: Lansing College Data Breach Affects 174,000 Individuals

Related Posts

Cisco Highlights Exploitation of Catalyst SD-WAN Vulnerabilities Cisco Highlights Exploitation of Catalyst SD-WAN Vulnerabilities The Hacker News
Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign The Hacker News
CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks The Hacker News
Adapting Security Strategies for Near-Zero Exploit Windows Adapting Security Strategies for Near-Zero Exploit Windows The Hacker News
DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown The Hacker News
n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Security Concerns Rise with AI-Driven Vibe Coding
  • The Emerging Threat of Mythos in Open Source
  • UNC3753 Targets US Law Firms with Vishing Tactics
  • Lansing College Data Breach Affects 174,000 Individuals
  • Critical Check Point VPN Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Security Concerns Rise with AI-Driven Vibe Coding
  • The Emerging Threat of Mythos in Open Source
  • UNC3753 Targets US Law Firms with Vishing Tactics
  • Lansing College Data Breach Affects 174,000 Individuals
  • Critical Check Point VPN Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark