INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

Explotan vulnerabilidad Check Point VPN

| 2026-06-08 14:17 CRITICAL HIGH
Executive Summary AI-generated
The recent incident data reveals a critical vulnerability in Check Point's VPN solution, CVE-2026-50751. This zero-day exploit allows attackers to bypass authentication and gain remote access to the organization's network by exploiting a lógico flaw in certificate validation. The vulnerability is particularly concerning as it affects widely used protocols like IKEv1, which has been largely replaced by more modern alternatives like IKEv2. Organizations must take immediate action to patch this critical issue, especially if they rely on legacy systems or have not kept their security gateways and Spark Firewalls up-to-date with the latest patches.
Technical Mitigations AI-generated
* CVE-2026-50751: Un fallo crítico en el protocolo IKEv1 de autenticación y negociación de claves que permite establecer sesiones VPN sin necesidad de una contraseña válida. * CVE-2026-50752: Una vulnerabilidad relacionada con la lógica de validación de certificados para permitir ataques de tipo man-in-the-middle en conexiones VPN a través del protocolo IKEv1.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SparkSparkQilinQilinAgendaAgenda CVE-2024-24919CVE-2024-24919 CVE-2026-42271CVE-2026-42271 CVE-2026-50752CVE-2026-50752 CVE-2026-50751CVE-2026-50751
Target & Sectors
FIVE_EYES FIVE_EYES NORTH_AMERICA NORTH_AMERICA governmentgovernment automotiveautomotive
Incident Timeline
‎August 2022
Qilin exploited a Check Point vulnerability to target nearly 400 victims on its dark web leak site.
tactic Ransomware
malware Qilin
victims 400 victims
malware Agenda
‎May 7
The Qilin ransomware operation exploited a Check Point Auth Bypass vulnerability.
vulnerability CVE-2026-50751
source_region Israel
tactic Ransomware
malware Qilin
organisation Mobile Access
organisation Remote Access VPN
organisation Check Point VP
organisation Lotem Finkelstein
‎May 7, 2026
Threat actors exploited a vulnerability in Check Point Auth Bypass to target various products and versions.
malware Spark
organisation Remote Access
source_region Israel
organisation R81
general_metric 19 Hotfix
general_metric 103 Hotfix
general_metric 141 Hotfix
organisation EOS
‎2026/05/09
Threat actors used a previously undisclosed exploit for Check Point Auth Bypass to target ransomware groups.
tactic Ransomware
organisation Ctrl-Alt-Intel
‎May 2026
Threat actors used a previously unknown vulnerability in Check Point's Auth Bypass software to target their systems.
‎June 4
Threat actors exploited a zero-day vulnerability in Check Point's Auth Bypass software.
‎June 4, 2026
Threat actors exploited a vulnerability in Check Point Auth Bypass to target various products and versions, including Security Gateways R82.10 Jumbo Hotfix Take 19 or below and Spark Firewalls: R80.20.X (EOS), R81.10.X, and R82.00.X.
malware Spark
organisation Remote Access
source_region Israel
organisation R81
general_metric 19 Hotfix
general_metric 103 Hotfix
general_metric 141 Hotfix
organisation EOS
‎June 8
Ransomware affiliates exploited a Check Point vulnerability in remote access VPN and mobile access deployments.
tactic Ransomware
malware Qilin
vulnerability CVE-2026-50751
‎2026/06/08
Threat actors exploited CVE-2026-50751 in Check Point Auth Bypass Exploited vulnerabilities.
vulnerability CVE-2026-50751
attribution CISA
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎Jun 08, 2026
Threat actors exploited a known vulnerability in Check Point's Auth Bypass software to gain unauthorized access into targeted networks.
‎at least May 7 through June 5
Threat actors exploited a vulnerability in Check Point SmartConsole to bypass authentication.
‎2026/06/09
Check Point has urged customers to patch a critical zero-day vulnerability in its Remote Access VPN and Mobile Access solutions that is being actively exploited.
organisation Check Point Research
organisation preparación de un ataque de ransomware
organisation los grupos de ransomware
organisation los actores financieros
organisation vía directa
organisation Ransomware
organisation Check Point
organisation The Hacker News
organisation Check Point Remote Access VPN
organisation El fallo
organisation CVE-2026
organisation CVSS
organisation Unauthenticated
organisation Mobile Access/SSL VPNs
organisation Remote Access
organisation Command Injection Vulnerability
organisation Check Point VPN
organisation Mobile Access
organisation IKEv2
organisation the Remote Access and Mobile Access
organisation Security Gateways
organisation Mobile Access / SSL VPNs
organisation IPs
organisation Remote Access VPN Authentication
organisation the Machine Certificate Authentication
organisation Explotan una vulnerabilidad
organisation Remote Access VPN
organisation Vulnerability / Network Security
organisation fue
organisation Check Point's
organisation EOS
organisation un
organisation lógico
organisation la validación de certificados
organisation Las VPN
organisation de un protocolo de autenticación
organisation negociación de claves
organisation Sin
organisation gran medida
organisation Machine Certificate Authentication
organisation El uso de tecnologías heredadas sigue
organisation las empresas
organisation falta de revisión o
organisation el actor
organisation observada de explotación
organisation el 7 de mayo
organisation los equipos de respuesta
organisation Key Exchange
organisation VPS
organisation Kaupo Cloud HK
organisation Vultr Holdings
organisation Check Point Security Gateway
organisation Known Exploited
organisation KEV
organisation BOD
organisation EDR
infrastructure 1.74.2
infrastructure 1.83.6
organisation Check Point Security
infrastructure 1.83.7
organisation MCP
organisation API
organisation Vulnerable Check Point Customers Should Patch
organisation R81
organisation Microsoft
organisation Bypass Passwords
organisation Setups
organisation ELF
organisation Nissan
organisation Asahi
organisation Court
‎June 11
The Federal Civilian Executive Branch (FCEB) agencies were ordered to secure their devices by June 11 due to the exploitation of CVE-2026-50751.
vulnerability CVE-2026-50751
attribution CISA
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎June 11, 2026
Threat actors exploited the Check Point Security Gateway vulnerability.
attribution the Check Point Security Gateway
‎June 22, 2026
Threat actors exploited the Check Point Security Gateway vulnerability to gain unauthorized access.
attribution the Check Point Security Gateway
Tactical Metrics
Metrics
victims
400
Victims
Metrics
infrastructure
‎1.74.2
Software Version
Metrics
infrastructure
‎1.83.6
Software Version
Metrics
infrastructure
‎1.83.7
Software Version