Hackers Run Amok While Check Point VPN Snoozes
Cyber Mischief Makers Get a Head Start
Check Point has finally stirred and issued an urgent patch for a severe authentication bypass vulnerability in its Remote Access VPN and Mobile Access configurations. But here’s the twist: hackers, including the ransomware gang, enjoyed a month-long spree. The flaw, CVE-2026-50751, began attracting attention on May 7. Lotem Finkelstein, Check Point’s VP of research, mentioned that the antics really escalated by early June. Check Point caught a hint of something suspicious on June 4 and began investigating the zero-day, as outlined in Finkelstein’s blog post on Monday.
Qilin Ransomware Discoveries
“We’ve come across evidence that this mischievous activity has been restricted to a select few organizations (a few dozen globally), primarily in the past few days,” Finkelstein noted. In at least one situation, investigators observed some post-intrusion antics tied to a Qilin ransomware affiliate. These same ransomware criminals are probably taking advantage of VPN-related vulnerabilities in Palo Alto Networks, Fortinet, and F5 products, according to Finkelstein.
Technical Details
CVE-2026-50751 arises from a logic-flow blunder in the Remote Access and Mobile Access certificate validation process. This enables remote miscreants to bypass authentication and form a remote access VPN connection without a user password. It affects Mobile Access/SSL VPNs, Remote Access VPNs, and Spark Firewalls configured using the outdated and neglected IKEv1 key exchange protocol. While investigating CVE-2026-50751 and the impacted VPN components, Check Point discovered another issue, CVE-2026-50752, within its Security Gateways and Spark Firewall devices. This is attributed to a flaw in the certificate validation logic of the antiquated IKEv1 key exchange method, which could facilitate man-in-the-middle attacks on the VPN site-to-site configuration.
Check Point’s Urgent Call to Action
Check Point urges its clients to promptly patch vulnerable gateways and firewalls. They’ve also provided alternative methods to avoid the threats, with guidance in the security advisories. Furthermore, the software engineers have released a list of compromise indicators, including suspicious attacker IPs, and advise customers to sift through Check Point SmartConsole logs for any unusual activities related to VPN certificate authentication attempts connected to identified attacker infrastructure and certificate subject names from at least May 7 through June 5.
Summary: Who Let the Dogs Out? Oh, It Was Check Point!
Check Point has finally located its keys, but not before the hacker hounds reveled, exploiting the vulnerabilities as if it were a holiday. They’ve got some cleanup to attend to, but there’s at least a valuable lesson learned: Never leave the security house without securing the virtual door.
