<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol-ljwrt6vob" -->

---
title: Check Point warns of ransomware-linked attacks...
description: Check Point has released emergency hotfixes for two vulnerabilities in deployments still using the deprecated IKEv1 VPN protocol. The critical flaw,...
canonical: https://daily.dev/posts/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol-ljwrt6vob
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol | daily.dev
og:description: Check Point has released emergency hotfixes for two vulnerabilities in deployments still using the deprecated IKEv1 VPN protocol. The critical flaw,...
og:url: https://daily.dev/posts/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol-ljwrt6vob
og:image: https://api.daily.dev/og/posts/LJWrT6vOB.png
og:image:alt: Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol

**[CSO Online](https://daily.dev/sources/csoonline)** · 4 min read · 0 upvotes · 0 comments

## Summary

Check Point has released emergency hotfixes for two vulnerabilities in deployments still using the deprecated IKEv1 VPN protocol. The critical flaw, CVE-2026-50571 (CVSS 9.3), allows unauthenticated attackers to establish VPN sessions without a valid password by exploiting a logic flaw in certificate validation. Exploitation has been observed since early May, with one confirmed case linked to a Qilin ransomware affiliate. A second vulnerability, CVE-2026-50752 (CVSS 7.4), enables potential man-in-the-middle attacks on site-to-site VPN communications but has not yet been exploited. Affected products include Remote Access VPN, Mobile Access VPN, and certain Spark Firewall products across multiple Gaia OS versions. Mitigations include applying hotfixes, disabling legacy IKEv1 connections, and migrating to IKEv2.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4182898/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol.html>

## Similar posts on daily.dev

- [Check Point links VPN zero-day attacks to Qilin ransomware gang](https://daily.dev/posts/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang-lxnnqkhtj) · BleepingComputer · 0 upvotes · 0 comments
- [Critical Check Point VPN Zero-Day Exploited in the Wild \(CVE-2026-50751\)](https://daily.dev/posts/critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751--8lk5ari1g) · Rapid7 Cybersecurity Blog · 0 upvotes · 0 comments
- [Check Point VPN Authentication Bypass \(CVE-2026-50751\): Client-Controlled IKEv1 Auth Flipped by Ransomware Affiliate](https://daily.dev/posts/check-point-vpn-authentication-bypass-cve-2026-50751-client-controlled-ikev1-auth-flipped-by-rans-ehcuolknf) · Latest Hacking News · 0 upvotes · 0 comments
- [A Qilin ransomware affiliate exploited a Check Point VPN zero-day for a month before a patch existed](https://daily.dev/posts/a-qilin-ransomware-affiliate-exploited-a-check-point-vpn-zero-day-for-a-month-before-a-patch-existed-m3wbw9z8q) · The Next Web · 0 upvotes · 0 comments
- [CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day](https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day-v4jbko8vp) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ransomware](https://daily.dev/tags/ransomware), [#vpn](https://daily.dev/tags/vpn)

[View this post on daily.dev](https://daily.dev/posts/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol-ljwrt6vob)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol","url":"https://daily.dev/posts/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol-ljwrt6vob","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol-ljwrt6vob"},"datePublished":"2026-06-09T12:03:43.356Z","dateModified":"2026-08-24T07:01:18.186Z","description":"Check Point has released emergency hotfixes for two vulnerabilities in deployments still using the deprecated IKEv1 VPN protocol. The critical flaw,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e8e0e953d87ba1c80b82b5750fe40be5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e8e0e953d87ba1c80b82b5750fe40be5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol-ljwrt6vob","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ransomware,vpn","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol"}]}
```

