News
MARKET SIGNAL:

Check Point VPN Exploitation Puts Legacy IKEv1 Access In The Ransomware Spotlight

Newsroom brief

A critical Check Point VPN flaw, CVE-2026-50751, is being exploited against legacy IKEv1 remote-access configurations, with activity tied in one case to a Qilin ransomware affiliate and a second related VPN issue also disclosed.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
Check Point VPN Exploitation Puts Legacy IKEv1 Access In The Ransomware Spotlight
Image source: Thehackernews

Exploitation Narrows Around Legacy VPN Settings

A critical Check Point vulnerability is now an active perimeter-security issue for organizations that still allow Remote Access VPN or Mobile Access deployments to negotiate through IKEv1.

The flaw is tracked as CVE-2026-50751 and carries a CVSS score of 9.3, placing it in the critical range.

The weakness sits in certificate validation logic.

Under the exposed configuration, an unauthenticated remote attacker can create a remote access VPN session without a valid user password.

That does not automatically equal full internal compromise, because additional post-authentication actions are still needed before internal resources can be reached or privileges can be raised.

It does, however, move the attacker past a control that is supposed to stop unauthorized VPN entry at the edge.

Affected Gateways Share A Legacy Exposure Pattern

For Security Gateway deployments, the affected branches span R82.10 at Jumbo Hotfix Take 19 or earlier, R82 at Jumbo Hotfix Take 103 or earlier, R81.20 at Jumbo Hotfix Take 141 or earlier, plus R81.10, R81 and R80.40.

Spark Firewall exposure covers R80.20.X, R81.10.X and R82.00.X.

The exposure is narrower than a universal product compromise.

Exploitation depends on several configuration conditions being present at the same time: VPN Remote Access or Mobile Access must be enabled, IKEv1 must be available for remote access, legacy Remote Access clients must be accepted, and gateways must not require a machine certificate for connections.

That combination makes the operational priority clear: defenders need to identify gateways where legacy access settings remain active, not just inventory Check Point appliances in general.

Timeline Points To Targeted Ransomware-Relevant Activity

Suspicious activity was first identified on June 4, 2026, while the earliest observed exploitation dates back to May 7, 2026.

Activity increased this month, but the known victim set is described as limited to a few dozen targeted organizations globally.

One observed post-exploitation case has been associated with a Qilin ransomware affiliate.

The activity also used virtual private server infrastructure, with servers geolocated to a target country used against organizations inside that country.

After access was established, the attackers attempted to retrieve malicious ELF files from infrastructure they controlled.

The same infrastructure may be linked to attempts against other VPN-related vulnerabilities affecting Palo Alto Networks, Fortinet and F5 environments.

Indicators also suggest possible use of the Tox protocol for communication, a pattern commonly seen in financially motivated ransomware operations.

Patch Scope Extends Beyond The Exploited Bug

A second issue, CVE-2026-50752, was found during further review of affected VPN components.

That vulnerability has a CVSS score of 7.40 and may enable an adversary-in-the-middle attack on VPN site-to-site connections.

There is no evidence in the source material that CVE-2026-50752 has been exploited in real-world attacks.

For security teams, the immediate watchpoint is the intersection of patch status and legacy VPN configuration.

The strongest remediation signal is whether exposed gateways have removed the unsafe IKEv1 path, stopped accepting vulnerable legacy client conditions, and applied the relevant fixes across Security Gateway and Spark Firewall deployments.

Share this article
inXf

Related articles

More
NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test
Cybersecurity

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test

The National Federation of Subpostmasters was hit by ransomware after a cPanel-related hosting software bug was exploited. The NFSP was targeted on 30 April, and the Post Office paused some email interactions with the federation while saying branch operations were not affected. The immediate test is whether trusted communications can resume without pushing subpostmasters toward insecure workaround channels.

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure
Cybersecurity

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure

Cisco disclosed fixed-release guidance for a critical Unified Communications Manager flaw that can let attackers gain root privileges when WebDialer is enabled. Cisco PSIRT is aware of public proof-of-concept exploit code for CVE-2026-20230, though it has not found active exploitation or targeting. The immediate test is whether administrators patch Unified CM or disable WebDialer before proof-of-concept code turns into wider exposure.

AI-Built Ransomware Toolkit Turns EDR Evasion Into a Faster Cybercrime Workflow
Cybersecurity

AI-Built Ransomware Toolkit Turns EDR Evasion Into a Faster Cybercrime Workflow

A ransomware-focused threat actor adopted an AI-built toolkit for Active Directory discovery and endpoint detection and response evasion. Sophos found Cursor and Claude Opus agents assisted development, with close to 80 modules tested against more than 70 techniques. The practical question is whether defenders can shorten validation cycles as AI accelerates the move from offensive research to working malware components.

Union County Clues Point To $1 Million Kairos Data-Extortion Payment
Cybersecurity

Union County Clues Point To $1 Million Kairos Data-Extortion Payment

A Ransom-ISAC case study says Kairos took about $1 million after stealing files without encrypting systems. Clues point to Union County, Ohio, but the public record does not confirm the link or prove the data was deleted.

Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms
Cybersecurity

Silent Ransom Group Uses Fake IT Support Calls to Pressure Law Firms

Silent Ransom Group is targeting U.S. law firms and professional services organizations with fake IT support calls, remote access tools and rapid data-theft extortion. Mandiant links the activity to UNC3753, Luna Moth and Chatty Spider, while the FBI has warned of related social engineering and in-person theft attempts.

Bad Epoll Linux Flaw Reaches Android Without A Public Patch Timetable
Cybersecurity

Bad Epoll Linux Flaw Reaches Android Without A Public Patch Timetable

A newly disclosed Linux kernel flaw tracked as CVE-2026-46242 can let an unprivileged local user gain root access on Linux systems and may be reachable from Android or Chrome sandbox contexts, but public material did not give a distribution-by-distribution patch timetable.

Keep Reading

More Stories

Latest
Nvidia Opens Medical Simulation Framework For Healthcare Robot TrainingAIJul 24, 2026Nvidia Opens Medical Simulation Framework For Healthcare Robot TrainingNvidia's open-source Medical Physics Simulation framework is designed to generate training environments for healthcare robotics, while the named adopter list does not include a patient-side deployment.Selfie Video Recovery Gives Google Accounts A New Login PathCybersecurityJul 24, 2026Selfie Video Recovery Gives Google Accounts A New Login PathGoogle is adding opt-in selfie video account recovery while keeping Workspace, child and Advanced Protection accounts outside the feature, giving consumer users another login path tied to facial verification controls.FTC Orders Celsius Founders To Pay $16.5 Million Over Crypto Deposit ClaimsFintech & Digital PaymentsJul 24, 2026FTC Orders Celsius Founders To Pay $16.5 Million Over Crypto Deposit ClaimsA July 20 Federal Trade Commission settlement puts $16.5 million in Celsius founder payments alongside bans on deposit and crypto-trading products, with court approval still required.TSMC U.S. Fab Push Squeezes AI Chip MarginsChips & SemiconductorsJul 24, 2026TSMC U.S. Fab Push Squeezes AI Chip MarginsTSMC has announced $200 billion in U.S. manufacturing commitments since 2025, but overseas fab expansion is already diluting margins as AI chip customers face higher domestic production costs.OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider RiskCybersecurityJul 24, 2026OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider RiskSecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.BitMEX Wind-Down Ends A Perpetual-Swap Pioneer After 11 YearsCrypto/Web3Jul 23, 2026BitMEX Wind-Down Ends A Perpetual-Swap Pioneer After 11 YearsCoinDesk reported that BitMEX will shut down operations on September 23, 2026, with new registrations halted, user withdrawals urged and remaining contracts set for forced closure before the final deadline.South Korea Tests AI-RAN And 5G For Industrial Robot NetworksTelco & ConnectivityJul 23, 2026South Korea Tests AI-RAN And 5G For Industrial Robot NetworksRCR Wireless reports that South Korea has put KRW17.2 billion ($11.6 million) behind SK Telecom and KT-led AI-RAN trials for shipyards, factories and robot workloads.CXMT Pre-IPO Contract Tests Crypto Price Discovery For China Chip ListingCapital & PolicyJul 23, 2026CXMT Pre-IPO Contract Tests Crypto Price Discovery For China Chip ListingA Hyperliquid contract linked to ChangXin Memory Technologies is pricing the Chinese memory-chip maker far above its planned Shanghai offer before a restricted STAR market debut.Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsCapital & PolicyJul 23, 2026Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsA U.S. Treasury warning over alleged AI model distillation brings Moonshot’s Kimi K3 release into a policy test for Chinese open-weight models, Nvidia GB300 access and export-control enforcement.Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAIJul 23, 2026Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAlphabet told investors that its first compute-allocation priority is frontier AGI development, while Google Cloud demand and AI infrastructure spending are pushing the company to use third-party capacity as a bridge.White House Presses PJM Grid Reform As AI Power Demand RisesCloud & Data CentersJul 23, 2026White House Presses PJM Grid Reform As AI Power Demand RisesThe White House warned PJM Interconnection to reform its board governance and stakeholder process as AI data centres and other large loads intensify disputes over grid reliability, electricity prices and infrastructure cost allocation.OpenAI Presence Makes Enterprise AI Agents A Consulting SaleAIJul 22, 2026OpenAI Presence Makes Enterprise AI Agents A Consulting SaleOpenAI’s Presence service is available to eligible enterprise customers through deployed engineers, not as a self-service product, with pricing still scoped individually.