Check Point Quantum VPN: Critical Certificate Validation Flaws Enable Unauthenticated RCE
In June 2026, Check Point disclosed two critical authentication bypass flaws (CVE‑2026-50751 CVSS 9.3, CVE‑2026-50752 CVSS 7.4) in Quantum VPN gateways that allow unauthenticated attackers to establish IKEv1 VPN sessions when legacy Remote Access clients are enabled and machine‑certificate validation is not enforced; post‑authentication steps can lead to privileged remote code execution. Active exploitation of CVE‑2026-50751 was observed from May 7 2026, linked to a Qilin ransomware affiliate, prompting urgent warnings from the Dutch NCSC and inclusion considerations for CISA’s KEV catalog.
- Vulnerability Overview
- Affected products: Remote Access VPN, Mobile Access/SSL VPN, Spark Firewall across R80.20‑R82.10 releases (including EoS versions).
- Root cause: Logic flow weakness in IKEv1 certificate validation that fails to enforce mandatory machine‑certificate authentication, permitting session establishment without valid credentials.
-
Impact: Unauthenticated remote code execution with privileged impact on the Security Gateway, enabling lateral movement and potential ransomware deployment.
-
Exploitation Mechanics & Threat Actor Links
- Attacker sends crafted IKEv1 exchange to trigger validation bypass, establishes VPN tunnel, then leverages post‑authentication logic to execute arbitrary code.
- Rapid7 confirmed active exploitation of CVE‑2026-50751 beginning 2026‑05‑07, with increased activity in early June 2026.
- Binary analysis of post‑exploitation ELF payloads ties the campaign to a Qilin ransomware affiliate (medium confidence per Check Point).
-
Dutch NCSC issued an urgent warning that exploitation is imminent, urging immediate patching.
-
Indicators of Compromise
- Malicious IPs observed in attacks: 45.77.149.152, 209.182.225.136, 38.60.157.139, 162.33.177.101, 45.76.26.42, 144.208.127.155, 38.54.88.201, 38.54.107.167, 66.42.99.200.
- Associated file hashes (MD5): 52fda5c1b9704544f32ee98d9060e689, 51d39aa39478beeac94f2d12f682ecce.
-
Recommended detection: monitor for unusual IKEv1 traffic, VPN session logs from non‑certificate‑authenticated clients, and execution of unknown binaries on gateways.
-
Detection & Mitigation
- Apply Check Point emergency hotfixes for CVE‑2026-50751 and CVE‑2026-50752 immediately.
- Disable legacy Remote Access client support; enforce IKEv2‑only for Remote Access VPN.
- Configure Global Properties to require machine‑certificate authentication as mandatory.
- Deploy latest IPS signatures and enable IPS blocking for known exploit patterns.
-
Conduct forensic log review from 2026‑05‑07 onward, segment VPN access, and monitor IOC IPs/hashes in SIEM/EDR.
-
Conclusion & Recommendations
- Though only several dozen organizations have been observed compromised, the high CVSS scores and widespread deployment of Check Point gateways create significant potential impact.
- Prioritize hotfix application, enforce strong certificate‑based authentication, and retire IKEv1 where possible.
- Maintain vigilant monitoring for the listed IOCs and consider network‑level VPN restrictions until patching is complete.
Related posts
- thehackernews.com — Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
- News4Hackers — Check Point Fixes Critical VPN Vulnerabilities
- rapid7.com — Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
- Forkast
- Sqmagazine
- Cyberinsider
- The420
- Cybersecurity News — NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected
- Security Affairs — Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk
- thehackernews.com — Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
- Ampcuscyber
- Ebuildersecurity
- Ground
- Youtube
- Beazley