CTIPilot

Check Point IKEv1 site-to-site VPN MitM via certificate validation weakness (CVSS 7.4), no observed exploitation

cve · CVE-2026-50752

Coverage timeline
1
first 2026-06-09 → last 2026-06-09
Peak priority
critical
1 critical
Sources cited
5
5 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-06-09CVE-2026-50751, Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliate
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • advisories.ncsc.nl1 (20%)
  • blog.checkpoint.com1 (20%)
  • helpnetsecurity.com1 (20%)
  • rapid7.com1 (20%)
  • security-hub.ncsc.admin.ch1 (20%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Check Point IKEv1 site-to-site VPN MitM via certificate validation weakness (CVSS 7.4), no observed exploitation (1)

2026-06-09 · view entry permalink →

CRITICALCVE-2026-50751 +1exploitedupdated

CVE-2026-50751, Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliate

Check Point disclosed and patched CVE-2026-50751 (CVSS 9.3) on 8 June 2026, a logic-flow weakness in certificate validation in the deprecated IKEv1 key exchange affecting Remote Access VPN and Mobile Access deployments. An unauthenticated remote attacker can establish a VPN session without a valid user password; post-authentication activity is still required to reach internal resources (Check Point, 2026-06-08). NCSC-CH issued an Action-Required advisory the same day and links observed exploitation to a Qilin ransomware affiliate (NCSC-CH, 2026-06-08); CISA added the CVE to its KEV catalog on 8 June. Full technical treatment, exploitation prerequisites and hardening are in § 5 below. The companion CVE-2026-50752 (CVSS 7.4, site-to-site IKEv1 MitM, no observed exploitation) should be patched in the same window.

An attacker can bypass user authentication by exploiting a logic flow weakness in the Remote Access and Mobile Access certificate validation and establish a remote access VPN connection without a valid user password

Check Point

Current exploitation status: Actively Exploited. Observed exploitation linked to Qilin ransomware affiliate

NCSC-CH Security Hub
Updaterun 2026-06-17-e102009cactionscvesregionssectorssourcestagsbody

NCSC-NL updated its advisory (NCSC-2026-0179, version 1.0.1) on 2026-06-16 to note that public proof-of-concept code is now available for the Check Point Security Gateway IKEv1 authentication bypass (CVE-2026-50751, CVSS 9.3), increasing the probability of exploitation (NCSC-NL, 2026-06-16).

The flaw lets an unauthenticated client abuse the IKEv1 negotiation to bypass peer-signature verification and impersonate any VPN identity configured for certificate or mixed authentication (username/password-only configurations are not affected); the public PoC follows watchTowr's earlier technical analysis (Help Net Security, 2026-06-12). Apply the early-June Check Point hotfix; where feasible disable IKEv1 legacy mode or enforce mandatory machine-certificate authentication, which is not bypassable by this flaw.

vulnerability09 Jun 05:00Zmulti-sourceOpen finding ↗