www.infosecurity-magazine.com 6/9/2026, 9:50:40 AM · external

Check Point Warns Critical Auth Bypass Bug Exploited in the Wild

Check Point Warns Critical Auth Bypass Bug Exploited in the Wild
CyberSIXT Evidence Panel
Primary Source blog.checkpoint.com
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
Qilin

CHECK Point has issued a warning about a critical zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access solutions, which is actively being exploited. The flaw allows attackers to bypass user authentication using a logic weakness in certificate validation related to the deprecated IKEv1 key exchange protocol. Since May 7, the vulnerability has been exploited by a group associated with the Qilin ransomware, targeting various organizations globally.

Check Point also discovered another vulnerability (CVE-2026-50752), which is not currently exploited but could allow man-in-the-middle attacks. Customers are urged to apply updates to mitigate these threats.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline