Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
Check Point says attackers are abusing a critical IKEv1 VPN flaw to log in without passwords, with activity tied to targeted orgs and a Qilin affiliate.
Intelligence analysis by GPT-5.4 Mini

Check Point says CVE-2026-50751 lets unauthenticated attackers bypass password checks in certain Remote Access and Mobile Access VPN setups that still use IKEv1. The company has seen targeted exploitation globally, including activity linked to a Qilin ransomware affiliate.
A broken lock on a VPN door may let a stranger inside without the right password. Check Point says attackers found a way around one check in older setup types, then tried to use that opening to do more harm.
Analysis
What happened
Check Point warned that a critical flaw in its Remote Access VPN and Mobile Access deployments is being actively exploited when those systems are configured with the deprecated IKEv1 key exchange protocol. The issue is tracked as CVE-2026-50751 and carries a CVSS score of 9.3.
The bug is described as a logic flaw in certificate validation. In practice, that means an unauthenticated remote attacker may be able to establish a VPN session without a valid user password. Check Point says additional steps would still be needed to reach internal resources or move further inside a network, but the initial access hurdle can be bypassed.
Who is affected
The advisory covers several Security Gateway and Spark Firewall lines, including versions that are end-of-life. Check Point says exploitation requires a specific set of conditions: Remote Access or Mobile Access must be enabled, IKEv1 must be enabled, the gateway must accept legacy Remote Access clients, and the system must not require a machine certificate.
What defenders should know
Check Point first saw suspicious activity on June 4, 2026, with the earliest observed exploitation dating back to May 7, 2026. The company says attacks have been limited to a few dozen targeted organizations worldwide. In one case, the post-exploitation activity was associated with a Qilin ransomware affiliate.
The report also says attackers were using VPS infrastructure geolocated to target organizations in specific countries, and that they attempted to download malicious ELF files after access was established. Separately, Check Point found a second flaw, CVE-2026-50752, that could enable an adversary-in-the-middle attack on site-to-site VPN connections, but it says there is no evidence it has been used in the wild.
Key points
- Check Point says CVE-2026-50751 is being actively exploited against certain VPN deployments that use IKEv1.
- The flaw is a certificate-validation logic issue that can let an attacker bypass password authentication.
- Exploitation requires specific conditions, including legacy client support and no machine certificate requirement.
- Check Point observed targeted activity globally and linked one post-exploitation case to a Qilin ransomware affiliate.
- The company also identified CVE-2026-50752, but it says there is no evidence of real-world exploitation.
If organizations patch quickly and remove the risky IKEv1 setup, the attack path described in the advisory can be closed before it spreads further. The finding also gives defenders a clear checklist for hardening legacy VPN deployments and reducing exposure from older clients and missing machine certificates.
If exposed gateways stay unpatched, attackers can keep using the authentication bypass to gain a foothold without a valid password. Because the activity is already linked to targeted organizations and ransomware infrastructure, successful intrusions could lead to follow-on malware deployment and deeper network compromise.



