Vulnerability Management Check Point patches critical VPN flaw exploited in zero-day attacks June 8, 2026 Share By SC Staff (Adobe Stock) Check Point has released security updates to address a critical vulnerability in its Remote Access VPN and Mobile Access deployments that was exploited in zero-day attacks. The flaw, tracked as CVE-2026-50751, allows unauthenticated remote attackers to bypass authentication and establish a VPN connection. This vulnerability affects deployments configured to use the deprecated IKEv1 key exchange protocol. The attacks began on May 7 and have impacted a few dozen organizations worldwide, with at least one incident linked to the Qilin ransomware operation, as reported by Bleeping Computer. Check Point also identified a second vulnerability, CVE-2026-50752, related to certificate validation in IKEv1, which could be used in man-in-the-middle attacks on site-to-site VPNs, though no exploitation has been confirmed in the wild for this second flaw. Mitigation advice includes removing support for legacy remote access clients, enforcing IKEv2, mandating machine certificate authentication, and enabling IPS. The Qilin ransomware group has a history of targeting prominent organizations across various sectors. Source: Bleeping Computer SC Staff Related Vulnerability Management Ubiquiti UniFi OS server vulnerabilities allow unauthenticated remote code execution SC Staff June 8, 2026 The security flaws, tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, were addressed in May and impacted UniFi OS Server versions 5.0.6 and earlier. Vulnerability Management AI helps uncover critical 4-year-old Zcash vulnerability SC Staff June 8, 2026 The bug, which existed from Orchard's activation in May 2022 until an emergency fix on June 1, 2026, involved a flawed validation check for transaction inputs. Vulnerability Management Hackers exploit critical Everest Forms Pro vulnerability for website control SC Staff June 8, 2026 The vulnerability resides within the plugin's Complex Calculation feature, which processes user input and inserts it into a PHP code string for execution via the "eval()" function. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds