Close Menu
    What's Hot

    Patrick Bruel, French Singer, Is Taken Into Custody Over Sex Assault Claims

    U.S. Judge Reverses Decision on Colombian Woman Deported to Congo

    China Reasserts Itself, to Contain North Korea’s Tilt Toward Russia

    Facebook X (Twitter) Instagram
    Trending
    • Patrick Bruel, French Singer, Is Taken Into Custody Over Sex Assault Claims
    • U.S. Judge Reverses Decision on Colombian Woman Deported to Congo
    • China Reasserts Itself, to Contain North Korea’s Tilt Toward Russia
    • His ‘Absurd Question’ Led to a $9M-a-Year Business: Free Spirits
    • Meta Deletes Face-Recognition System From Its Smart Glasses App After WIRED Report
    • Wall Street Lunch: Intel Leads Chip And AI Stock Rally On Google, Nvidia Foundry Report
    • Lionel Messi could feature for Argentina before World Cup, Nico Paz back in training
    • Wetzel: Sorsby ruling a temporary injunction that will cause permanent damage
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups

    adminBy adminJune 8, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 08, 2026Vulnerability / Network Security

    Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups

    Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol.

    The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a case of a logic flow weakness in certificate validation that allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

    “By exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements,” Check Point said. “Additional post-authentication activity is required to access internal resources or escalate privileges.”

    Cybersecurity

    The shortcoming impacts the following products and versions –

    • Security Gateways R82.10 Jumbo Hotfix Take 19 or below, R82 Jumbo Hotfix Take 103 or below, R81.20 Jumbo Hotfix Take 141 or below, R81.10 (EOS), R81 (EOS), and R80.40 (EOS)
    • Spark Firewalls: R80.20.X (EOS), R81.10.X, and R82.00.X

    Successful exploitation requires the following conditions to be met –

    • VPN Remote Access or Mobile Access is enabled
    • IKEv1 is enabled for remote access
    • Gateways accept legacy Remote Access clients
    • Gateways do not demand a machine certificate for connections

    The Israeli cybersecurity company said it first observed indications of suspicious activity on June 4, 2026, with the earliest observed exploitation dating back to May 7, 2026. Exploitation efforts are said to have ramped up starting this month.

    The exploitation activity, Check Point added, has been limited to a “few dozen targeted organizations globally.” In one case, the post-exploitation phase has been associated with a Qilin ransomware affiliate.

    “We believe that this threat actor infrastructure is exploiting other VPN related vulnerabilities such as the ones published by Palo Alto [Networks], Fortinet, and F5,” it noted. “We identified indicators suggesting the actor may use the Tox protocol for communication, a pattern commonly associated with financially motivated ransomware actors.”

    Cybersecurity

    A key aspect is the use of a virtual private server (VPS) infrastructure to conduct the attacks. Specifically, this involves relying on VPS servers geolocated to a particular country to target organizations within its borders. Once access was established, the attackers were found attempting to download malicious ELF files from actor-controlled infrastructure.

    Some aspects of these efforts overlap with a report from Ctrl-Alt-Intel last month, which highlighted the ransomware crew’s abuse of corporate VPN appliances for initial access.

    Further review of the affected VPN components has uncovered a second vulnerability, CVE-2026-50752 (CVSS score: 7.40), which may allow an adversary-in-the-middle (AitM) attack on VPN site-to-site connections. There is no evidence the flaw has been exploited in real-world attacks.

    Bypass check critical Exploited flaw IKEv1 Passwords Point Setups VPN
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article‘Lives turned in a second’: Family of baby Sam, shot dead by Israel, grieve | Israel-Palestine conflict News
    Next Article NotebookLM’s Gemini 3.5 upgrade adds a cloud computer and help finding sources
    admin
    • Website

    Related Posts

    Meta Blocks NSO Group’s New WhatsApp Phishing Attack, Files Contempt Order

    June 8, 2026

    How to Reduce Tier 1 Overload

    June 8, 2026

    VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

    June 8, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Patrick Bruel, French Singer, Is Taken Into Custody Over Sex Assault Claims

    U.S. Judge Reverses Decision on Colombian Woman Deported to Congo

    China Reasserts Itself, to Contain North Korea’s Tilt Toward Russia

    His ‘Absurd Question’ Led to a $9M-a-Year Business: Free Spirits

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by