← Back to Daily Briefing (#VPNVulnerability)

Check Point Quantum VPN: Critical Certificate Validation Flaws Enable Unauthenticated RCE

Published September 21, 2026

In June 2026, Check Point disclosed two critical authentication bypass flaws (CVE‑2026-50751 CVSS 9.3, CVE‑2026-50752 CVSS 7.4) in Quantum VPN gateways that allow unauthenticated attackers to establish IKEv1 VPN sessions when legacy Remote Access clients are enabled and machine‑certificate validation is not enforced; post‑authentication steps can lead to privileged remote code execution. Active exploitation of CVE‑2026-50751 was observed from May 7 2026, linked to a Qilin ransomware affiliate, prompting urgent warnings from the Dutch NCSC and inclusion considerations for CISA’s KEV catalog.

  • Vulnerability Overview
  • Affected products: Remote Access VPN, Mobile Access/SSL VPN, Spark Firewall across R80.20‑R82.10 releases (including EoS versions).
  • Root cause: Logic flow weakness in IKEv1 certificate validation that fails to enforce mandatory machine‑certificate authentication, permitting session establishment without valid credentials.
  • Impact: Unauthenticated remote code execution with privileged impact on the Security Gateway, enabling lateral movement and potential ransomware deployment.

  • Exploitation Mechanics & Threat Actor Links

  • Attacker sends crafted IKEv1 exchange to trigger validation bypass, establishes VPN tunnel, then leverages post‑authentication logic to execute arbitrary code.
  • Rapid7 confirmed active exploitation of CVE‑2026-50751 beginning 2026‑05‑07, with increased activity in early June 2026.
  • Binary analysis of post‑exploitation ELF payloads ties the campaign to a Qilin ransomware affiliate (medium confidence per Check Point).
  • Dutch NCSC issued an urgent warning that exploitation is imminent, urging immediate patching.

  • Indicators of Compromise

  • Malicious IPs observed in attacks: 45.77.149.152, 209.182.225.136, 38.60.157.139, 162.33.177.101, 45.76.26.42, 144.208.127.155, 38.54.88.201, 38.54.107.167, 66.42.99.200.
  • Associated file hashes (MD5): 52fda5c1b9704544f32ee98d9060e689, 51d39aa39478beeac94f2d12f682ecce.
  • Recommended detection: monitor for unusual IKEv1 traffic, VPN session logs from non‑certificate‑authenticated clients, and execution of unknown binaries on gateways.

  • Detection & Mitigation

  • Apply Check Point emergency hotfixes for CVE‑2026-50751 and CVE‑2026-50752 immediately.
  • Disable legacy Remote Access client support; enforce IKEv2‑only for Remote Access VPN.
  • Configure Global Properties to require machine‑certificate authentication as mandatory.
  • Deploy latest IPS signatures and enable IPS blocking for known exploit patterns.
  • Conduct forensic log review from 2026‑05‑07 onward, segment VPN access, and monitor IOC IPs/hashes in SIEM/EDR.

  • Conclusion & Recommendations

  • Though only several dozen organizations have been observed compromised, the high CVSS scores and widespread deployment of Check Point gateways create significant potential impact.
  • Prioritize hotfix application, enforce strong certificate‑based authentication, and retire IKEv1 where possible.
  • Maintain vigilant monitoring for the listed IOCs and consider network‑level VPN restrictions until patching is complete.

Related posts

  1. thehackernews.com — Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
  2. News4Hackers — Check Point Fixes Critical VPN Vulnerabilities
  3. Check Point Research — Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
  4. rapid7.com — Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
  5. Digital
  6. Community
  7. Forkast
  8. Sqmagazine
  9. bleepingcomputer.com — Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
  10. Cyberinsider
  11. The420
  12. Cybersecurity News — NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected
  13. Security Affairs — Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk
  14. thehackernews.com — Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
  15. Ampcuscyber
  16. Labs
  17. Ebuildersecurity
  18. Ground
  19. Computing
  20. Youtube
  21. Beazley
  22. Reddit
  23. Obsonis
  24. Itdaily

LINK COPIED TO CLIPBOARD