{"id":1218,"date":"2026-06-08T16:07:05","date_gmt":"2026-06-08T16:07:05","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1218"},"modified":"2026-06-08T16:07:05","modified_gmt":"2026-06-08T16:07:05","slug":"critical-check-point-vpn-flaw-exploited-to-bypass-passwords-in-ikev1-setups","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1218","title":{"rendered":"Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 08, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Network Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYhQjzMpxYhylqWwtRqt0p7upc-fSMohRLJs5lRSXUg51_lrzt63JYz0K9zo2V7Rl9yCOMpQk6YFBfTdE1CuSuFYGA3odGeHu3mIV-LY_JHWyIx7g32NPOx1tuSZ-ZIMasTT5S-43DoYHEpCTykl4E4TfyXw89HksiOppUEMp5ganCT27SF0xu7noBUQ5i\/s1700-e365\/checkpoint.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated <a href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/security-vpn\/ipsec-negotiation-ike-protocols\/217432-understand-ipsec-ikev1-protocol.html\">IKEv1<\/a> key exchange protocol.<\/p>\n<p>The vulnerability, tracked as <b>CVE-2026-50751<\/b> (CVSS score: 9.3), is a case of a logic flow weakness in certificate validation that allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.<\/p>\n<p>\u00abBy exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements,\u00bb Check Point <a href=\"https:\/\/blog.checkpoint.com\/security\/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol\/\">said<\/a>. \u00abAdditional post-authentication activity is required to access internal resources or escalate privileges.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The shortcoming <a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk185033\">impacts<\/a> the following products and versions &#8211;<\/p>\n<ul>\n<li>Security Gateways R82.10 Jumbo Hotfix Take 19 or below, R82 Jumbo Hotfix Take 103 or below, R81.20 Jumbo Hotfix Take 141 or below, R81.10 (EOS), R81 (EOS), and R80.40 (EOS)<\/li>\n<li>Spark Firewalls: R80.20.X (EOS), R81.10.X, and R82.00.X<\/li>\n<\/ul>\n<p>Successful exploitation requires the following conditions to be met &#8211;<\/p>\n<ul>\n<li>VPN Remote Access or Mobile Access is enabled<\/li>\n<li>IKEv1 is enabled for remote access<\/li>\n<li>Gateways accept legacy Remote Access clients<\/li>\n<li>Gateways do not demand a machine certificate for connections<\/li>\n<\/ul>\n<p>The Israeli cybersecurity company said it first observed indications of suspicious activity on June 4, 2026, with the earliest observed exploitation dating back to May 7, 2026. Exploitation efforts are said to have ramped up starting this month.<\/p>\n<p>The exploitation activity, Check Point added, has been limited to a \u00abfew dozen targeted organizations globally.\u00bb In one case, the post-exploitation phase has been associated with a <a href=\"https:\/\/thehackernews.com\/2026\/04\/qilin-and-warlock-ransomware-use.html\">Qilin ransomware affiliate.<\/p>\n<p>\u00abWe believe that this threat actor infrastructure is exploiting other VPN related vulnerabilities such as the ones published by Palo Alto [Networks], Fortinet, and F5,\u00bb it noted. \u00abWe identified indicators suggesting the actor may use the Tox protocol for communication, a pattern commonly associated with financially motivated ransomware actors.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>A key aspect is the use of a virtual private server (VPS) infrastructure to conduct the attacks. Specifically, this involves relying on VPS servers geolocated to a particular country to target organizations within its borders. Once access was established, the attackers were found attempting to download malicious ELF files from actor-controlled infrastructure.<\/p>\n<p>Some aspects of these efforts <a href=\"https:\/\/ctrlaltintel.com\/research\/Qilin\/\">overlap<\/a> with a report from Ctrl-Alt-Intel last month, which highlighted the ransomware crew&#8217;s abuse of corporate VPN appliances for initial access.<\/p>\n<p>Further review of the affected VPN components has uncovered a second vulnerability, CVE-2026-50752 (CVSS score: 7.40), which may allow an adversary-in-the-middle (AitM) attack on VPN site-to-site connections. There is no evidence the flaw has been exploited in real-world attacks.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 08, 2026Vulnerability \/ Network Security Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1219,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[394,1958,58,128,70,1960,296,1959,1961,668],"class_list":["post-1218","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-bypass","tag-check","tag-critical","tag-exploited","tag-flaw","tag-ikev1","tag-passwords","tag-point","tag-setups","tag-vpn"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1218"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1218\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1219"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}