<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751--8lk5ari1g" -->

---
title: Critical Check Point VPN Zero-Day Exploited in the Wild...
description: Check Point has disclosed CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) affecting its Remote Access VPN, Mobile Access, and Spark...
canonical: https://daily.dev/posts/critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751--8lk5ari1g
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751) | daily.dev
og:description: Check Point has disclosed CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) affecting its Remote Access VPN, Mobile Access, and Spark...
og:url: https://daily.dev/posts/critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751--8lk5ari1g
og:image: https://api.daily.dev/og/posts/8Lk5ARI1G.png
og:image:alt: Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)

**[Rapid7 Cybersecurity Blog](https://daily.dev/sources/rapid7-blog)** · 4 min read · 0 upvotes · 0 comments

## Summary

Check Point has disclosed CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) affecting its Remote Access VPN, Mobile Access, and Spark Firewall products. The flaw exists in the deprecated IKEv1 key exchange protocol and allows unauthenticated attackers to establish VPN sessions without valid credentials. Active exploitation has been observed since May 7, 2026, with at least one incident linked to a Qilin ransomware affiliate. A related vulnerability, CVE-2026-50752 (CVSS 7.4), enabling man-in-the-middle attacks on site-to-site VPN tunnels, was also identified but has not been exploited. Hotfixes are available for supported versions; four affected version branches are end-of-support. Interim mitigations include disabling legacy remote access clients, enforcing IKEv2, requiring machine certificates, and enabling IPS. Indicators of compromise including attacker IP addresses and file hashes are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751>

## Similar posts on daily.dev

- [Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol](https://daily.dev/posts/check-point-warns-of-ransomware-linked-attacks-exploiting-outdated-vpn-protocol-ljwrt6vob) · CSO Online · 0 upvotes · 0 comments
- [Check Point links VPN zero-day attacks to Qilin ransomware gang](https://daily.dev/posts/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang-lxnnqkhtj) · BleepingComputer · 0 upvotes · 0 comments
- [Check Point VPN Authentication Bypass \(CVE-2026-50751\): Client-Controlled IKEv1 Auth Flipped by Ransomware Affiliate](https://daily.dev/posts/check-point-vpn-authentication-bypass-cve-2026-50751-client-controlled-ikev1-auth-flipped-by-rans-ehcuolknf) · Latest Hacking News · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ransomware](https://daily.dev/tags/ransomware), [#vpn](https://daily.dev/tags/vpn)

[View this post on daily.dev](https://daily.dev/posts/critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751--8lk5ari1g)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)","url":"https://daily.dev/posts/critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751--8lk5ari1g","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751--8lk5ari1g"},"datePublished":"2026-06-08T17:50:26.824Z","dateModified":"2026-06-08T18:37:42.495Z","description":"Check Point has disclosed CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) affecting its Remote Access VPN, Mobile Access, and Spark...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/135ef1d43315d714b8d03af137e0e542?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/135ef1d43315d714b8d03af137e0e542?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Rapid7 Cybersecurity Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Rapid7 Cybersecurity Blog","logo":"https://media.daily.dev/image/upload/logos/placeholder.jpg","url":"https://daily.dev/sources/rapid7-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751--8lk5ari1g","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ransomware,vpn","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Rapid7 Cybersecurity Blog","item":"https://daily.dev/sources/rapid7-blog"},{"@type":"ListItem","position":3,"name":"Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)"}]}
```

