← Back to Daily Briefing

Check Point Quantum VPN: Critical Certificate Validation Flaws Enable Unauthenticated RCE

Published September 21, 2026

In June 2026, Check Point disclosed two critical authentication bypass flaws (CVE‑2026-50751 CVSS 9.3, CVE‑2026-50752 CVSS 7.4) in Quantum VPN gateways that allow unauthenticated attackers to establish IKEv1 VPN sessions when legacy Remote Access clients are enabled and machine‑certificate validation is not enforced; post‑authentication steps can lead to privileged remote code execution. Active exploitation of CVE‑2026-50751 was observed from May 7 2026, linked to a Qilin ransomware affiliate, prompting urgent warnings from the Dutch NCSC and inclusion considerations for CISA’s KEV catalog.

  • Vulnerability Overview
  • Affected products: Remote Access VPN, Mobile Access/SSL VPN, Spark Firewall across R80.20‑R82.10 releases (including EoS versions).
  • Root cause: Logic flow weakness in IKEv1 certificate validation that fails to enforce mandatory machine‑certificate authentication, permitting session establishment without valid credentials.
  • Impact: Unauthenticated remote code execution with privileged impact on the Security Gateway, enabling lateral movement and potential ransomware deployment.

  • Exploitation Mechanics & Threat Actor Links

  • Attacker sends crafted IKEv1 exchange to trigger validation bypass, establishes VPN tunnel, then leverages post‑authentication logic to execute arbitrary code.
  • Rapid7 confirmed active exploitation of CVE‑2026-50751 beginning 2026‑05‑07, with increased activity in early June 2026.
  • Binary analysis of post‑exploitation ELF payloads ties the campaign to a Qilin ransomware affiliate (medium confidence per Check Point).
  • Dutch NCSC issued an urgent warning that exploitation is imminent, urging immediate patching.

  • Indicators of Compromise

  • Malicious IPs observed in attacks: 45.77.149.152, 209.182.225.136, 38.60.157.139, 162.33.177.101, 45.76.26.42, 144.208.127.155, 38.54.88.201, 38.54.107.167, 66.42.99.200.
  • Associated file hashes (MD5): 52fda5c1b9704544f32ee98d9060e689, 51d39aa39478beeac94f2d12f682ecce.
  • Recommended detection: monitor for unusual IKEv1 traffic, VPN session logs from non‑certificate‑authenticated clients, and execution of unknown binaries on gateways.

  • Detection & Mitigation

  • Apply Check Point emergency hotfixes for CVE‑2026-50751 and CVE‑2026-50752 immediately.
  • Disable legacy Remote Access client support; enforce IKEv2‑only for Remote Access VPN.
  • Configure Global Properties to require machine‑certificate authentication as mandatory.
  • Deploy latest IPS signatures and enable IPS blocking for known exploit patterns.
  • Conduct forensic log review from 2026‑05‑07 onward, segment VPN access, and monitor IOC IPs/hashes in SIEM/EDR.

  • Conclusion & Recommendations

  • Though only several dozen organizations have been observed compromised, the high CVSS scores and widespread deployment of Check Point gateways create significant potential impact.
  • Prioritize hotfix application, enforce strong certificate‑based authentication, and retire IKEv1 where possible.
  • Maintain vigilant monitoring for the listed IOCs and consider network‑level VPN restrictions until patching is complete.

Related posts

  1. thehackernews.com — Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
  2. News4Hackers — Check Point Fixes Critical VPN Vulnerabilities
  3. rapid7.com — Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
  4. Forkast
  5. Sqmagazine
  6. Cyberinsider
  7. The420
  8. Cybersecurity News — NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected
  9. Security Affairs — Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk
  10. thehackernews.com — Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
  11. Ampcuscyber
  12. Ebuildersecurity
  13. Ground
  14. Youtube
  15. Beazley

LINK COPIED TO CLIPBOARD