Check Point VPN bypass CVE-2026-50751 gets a public exploit, tied to Qilin ransomware
Researchers released a working proof-of-concept four days after the patch. Attackers had already used the flaw since early May, including one Qilin ransomware case.
A working exploit is now public for a critical Check Point VPN flaw that attackers had already used for weeks. A security research firm published a technical breakdown and proof-of-concept tool for CVE-2026-50751 on June 12, four days after the vendor shipped a fix.
The vulnerability raises the urgency for any organization that has not yet patched. CVE-2026-50751 is an authentication-bypass zero-day rated CVSS 9.3, affecting Check Point Remote Access VPN and Mobile Access gateways configured for the legacy IKEv1 protocol. It lets an unauthenticated, remote attacker complete the IKEv1 phase-1 handshake without a valid signature, defeating certificate-based authentication.
Check Point released hotfixes on June 8 for Remote Access VPN, Mobile Access/SSL VPN, and its Spark Firewall, and patched a second related certificate-validation flaw, CVE-2026-50752, the same day. The company also published indicators of compromise on its support portal to help defenders check for intrusions.
Exploitation in the wild stretched back to May 7, 2026, with roughly a few dozen organizations targeted before the patch existed, and at least one incident has been linked to a Qilin ransomware affiliate. The newly released proof-of-concept also works over TCP port 443 when UDP is blocked, widening the conditions under which it can be used.
The risk is real but bounded. The bypass requires that a gateway not mandate a machine certificate; deployments using a plain legacy username-and-password method are not affected, because that method still demands a password. Organizations that have applied the June 8 hotfixes are protected, and the headline severity applies to unpatched, IKEv1-configured gateways rather than every Check Point install.
Public proof-of-concept code typically widens the pool of attackers within days, turning a niche zero-day into commodity tooling. With a fix available since June 8 and indicators of compromise published, the immediate task for affected administrators is to patch and to look for signs they were already hit.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
