High severity7.4NVD Advisory· Published Jun 8, 2026· Updated Jun 8, 2026
CVE-2026-50752
CVE-2026-50752
Description
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
9- Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)Help Net Security · Jun 12, 2026
- Check Point VPN Zero-Day Exploited in Qilin Ransomware AttacksSecurityWeek · Jun 9, 2026
- Check Point Warns Critical Auth Bypass Bug Exploited in the WildInfosecurity Magazine · Jun 9, 2026
- Check Point VPN Flaw Exploited Since Early MayDark Reading · Jun 8, 2026
- Check Point VPN 0-day Vulnerability Exploited in the Wild to Deploy RansomwareCyber Security News · Jun 8, 2026
- Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fixThe Register Security · Jun 8, 2026
- Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)Rapid7 Blog · Jun 8, 2026
- Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 SetupsThe Hacker News · Jun 8, 2026
- Check Point links VPN zero-day attacks to Qilin ransomware gangBleepingComputer · Jun 8, 2026