A critical vulnerability in Check Point's Remote Access VPN product is being actively exploited by ransomware attackers. Businesses running Check Point VPN need to act immediately.
- What it is: CVE-2026-50751 is a critical authentication bypass flaw (CVSS 9.3) in Check Point VPN products using the deprecated IKEv1 key exchange protocol. An attacker can establish a VPN session without supplying a valid password.
- Who is affected: Organisations running Check Point Remote Access VPN or Mobile Access with IKEv1 enabled — both cloud and on-premises deployments.
- What the risk is: The vulnerability is being actively exploited in the wild. At least one confirmed attack has been linked to the Qilin ransomware group. CISA added this to its Known Exploited Vulnerabilities catalog on 8 June 2026. A public proof-of-concept exploit was released on 12 June, significantly raising the risk of widespread opportunistic attacks.
- What you need to do: Apply Check Point's emergency hotfix immediately. If your VPN uses IKEv1, disable it. Contact your IT provider if you are unsure whether your Check Point deployment is affected.
If OzComm manages your Check Point environment, we are reviewing client configurations. Contact us if you have any concerns.
Sources: Check Point Security Blog | Help Net Security | CISA Advisory