Critical VPN vulnerability actively exploited
Security software vendor Check Point is warning of active attacks on a critical vulnerability in its own VPN software. The flaw, classified as CVE-2026-50751, carries a CVSS score of 9.3 and is rated as a critical security risk. Germany's Federal Office for Information Security (BSI) has also issued a corresponding warning.
The vulnerability enables unauthenticated attackers on the network to bypass authentication and establish VPN connections without a valid password. Check Point Remote Access VPN, Mobile Access and Spark Firewall are affected.
Technical details of the vulnerability
The flaw lies in the outdated IKEv1 protocol used for key exchange. In Check Point Remote Access and Mobile Access, a logic error occurs in the certificate check that malicious actors can abuse. This allows attackers to gain access to VPN connections without valid credentials.
In addition, IT security researchers have identified a further vulnerability: CVE-2026-50752, with a CVSS score of 7.4 (risk rating "high"). It enables attackers in a man-in-the-middle position to intercept or manipulate VPN traffic.
Attack timeline and observations
Check Point observed suspicious activity on 4 June 2026. The investigation revealed that the vulnerability had already been under attack since 7 May 2026. Attack attempts increased significantly at the beginning of June.
Ransomware gang Qilin the prime suspect
With medium confidence, Check Point attributes the attacks to the financially motivated ransomware gang Qilin. The group apparently uses the "Tox protocol" for its attacks and operates from a virtual private server (VPS) infrastructure.
The geographical proximity of the attacks is particularly striking: the attackers select VPS servers close to their targets. For instance, they attacked targets in Taiwan from Taiwanese infrastructure.
Further attack targets
Following successful attacks, IT security researchers found Qilin ransomware binaries and observed attempts to download malicious ELF files from infrastructure controlled by the attackers. Check Point suspects that Qilin is also behind attacks on VPN solutions from Palo Alto Networks and Fortinet FortiClient EMS.
Assessment for the security industry
These attacks once again illustrate the critical importance of VPN security in modern IT infrastructure. Especially at a time of increased remote working, VPN solutions have become a preferred attack target. The fact that an established ransomware gang is systematically targeting various VPN vendors demonstrates the professionalisation of cybercrime.
For companies in the security technology sector, this is further proof that multi-layered security concepts are indispensable. Alongside technical solutions such as access control systems and physical security measures, digital access routes must also be secured accordingly.
Immediate countermeasures required
As the primary countermeasure, Check Point recommends installing software updates immediately. In addition, administrators should disable support for outdated remote access client connections, as described in the update instructions.
Checking for compromise
The company provides indicators of compromise (IOC) that administrators can use to examine their systems for attack attempts. These indicators make it possible to identify attacks that have already occurred and to initiate appropriate remediation measures.
IT managers should check their systems for suspicious activity without delay, in particular unusual VPN connections or login attempts from unknown geographical regions.
Long-term security strategy
This incident underlines the need for a holistic security strategy. Companies should not only update their VPN infrastructure regularly, but also implement alternative authentication methods and review their network segmentation.
The observation that attackers use geographically nearby VPS infrastructure also shows the importance of behaviour-based security analysis. Anomaly detection can help to identify such targeted attacks at an early stage.
For the security industry, this is another wake-up call that both physical and digital security measures must be developed continuously in order to keep pace with the evolving threat landscape.