Trusted Design

Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)

概要

A critical authentication bypass vulnerability affecting Remote Access VPN and Mobile Access deployments has been actively exploited in the wild. The vulnerability exploits a logic flaw in certificate validation within the deprecated IKEv1 key exchange protocol, allowing attackers to establish VPN sessions without valid passwords. Exploitation has been observed since May 7, 2026, targeting several dozen organizations globally. One confirmed incident involved post-compromise activity linked to Qilin ransomware operations. The threat actor appears financially motivated and operates dedicated VPS infrastructure across multiple hosting providers. An additional related vulnerability affecting site-to-site VPN communications was discovered through AI-assisted code analysis, though no active exploitation has been observed. Immediate patching is strongly recommended for affected systems using IKEv1 protocol.

Created: 2026-06-10

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る