Home/Threat Intelligence/CBN-2026-024
CriticalAdvisoryTLP: CLEARCBN-2026-024 · 09 Jun 2026
Check Point VPN authentication bypass used by a Qilin ransomware affiliate
A certificate-validation flaw in Check Point's IKEv1 handling let attackers establish remote-access VPN sessions without a password. Exploitation predated the fix by a month, and a Qilin affiliate is the assessed operator.
At a glance
Affected
Check Point Mobile Access and SSL VPN, Remote Access VPN, and Spark Firewall on R80.20.X, R80.40, R81, R81.10, R81.10.X, R81.20, R82, R82.00.X and R82.10 — but only where the deprecated IKEv1 key exchange is in use.
Impact
An unauthenticated attacker lands inside the corporate network as an apparently legitimate VPN user, with ransomware deployment as the observed follow-on.
Action
Apply the emergency hotfixes (Check Point SK185033 and SK185035). If you cannot patch immediately, disable legacy client support, enforce IKEv2 only, require machine-certificate authentication and enable IPS with current signatures.
Client status
No Check Point gateways in our managed estate. Four of the affected branches are already end-of-support, so clients on R80.20.X, R80.40, R81 or R81.10 need an upgrade path rather than a hotfix.
Detail
The defect is a logic error in how the Remote Access and Mobile Access components validate certificates during IKEv1 key exchange. An attacker negotiates a session that the gateway accepts as legitimate, and never presents a valid password. Deployments configured to accept legacy clients without demanding a machine certificate are the exposed configuration; IKEv2-only estates are not affected.
The timeline is the uncomfortable part
Check Point detected the suspicious activity on 4 June and shipped hotfixes on 8 June. The earliest observed exploitation was 7 May. That is a month of unauthenticated network access at an unknown number of organisations before anyone knew there was a bug — and Check Point's own characterisation is that targeting was limited to dozens of organisations rather than opportunistic mass exploitation, which usually means someone was choosing victims deliberately.
Check Point assesses at medium confidence that the operator was a Qilin ransomware affiliate. Rapid7 reported two high-confidence attributions from its own casework. CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 8 June with a three-day federal deadline, and flags it as used in known ransomware campaigns.
IKEv1 has been deprecated for years
The exposure condition here is a protocol that the industry has been retiring since 2017. If your gateway still accepts IKEv1, this vulnerability is a symptom rather than the problem — the problem is a remote-access configuration carried forward through several upgrades because nothing forced a review. Four of the nine affected branches are past end of support, which suggests the same inertia applies to the platform version underneath.
The compensating controls Check Point published are worth applying permanently, not just until the hotfix lands. Machine-certificate authentication in particular turns a stolen or bypassed user credential into something the attacker still cannot use.
If you find evidence of this activity, do not begin remediation before preserving evidence — console and appliance audit logs are frequently short-retention and will roll off. Acronis MDR provides around-the-clock detection and response for covered estates; otherwise reach us through the contact page and we will advise on preservation before containment.
Sources
Cybernalyst's analysis and recommendations are our own. The underlying research is credited below — please read the original reporting.
- Check Point Releases Important Hotfix for Vulnerabilities in Deprecated IKEv1 VPN ProtocolLotem Finkelstein·Check Point·8 June 2026
- Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)Rapid7·8 June 2026
- Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)Zeljka Zorz·Help Net Security·8 June 2026