惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
H
Help Net Security
V
Visual Studio Blog
J
Java Code Geeks
Stack Overflow Blog
Stack Overflow Blog
Microsoft Security Blog
Microsoft Security Blog
Apple Machine Learning Research
Apple Machine Learning Research
MyScale Blog
MyScale Blog
The Cloudflare Blog
Martin Fowler
Martin Fowler
D
Docker
腾讯CDC
F
Fortinet All Blogs
雷峰网
雷峰网
GbyAI
GbyAI
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Blog — PlanetScale
Blog — PlanetScale
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
博客园 - 叶小钗

Arctic Wolf

Home-Field Disadvantage: AiTM, QR-Code Phishing, and Infostealers at the 2026 FIFA World Cup arcticwolf.com arcticwolf.com Celebrating Arctic Wolf’s 2026 Partner of the Year Winners at Global Partner Kickoff Die Auswahl Einer Vulnerability Management-Lösung The Hidden Economics of the Agentic SOC The Hidden Economics of the Agentic SOC | Arctic Wolf Security Operations in Maschinen-Geschwindigkeit Aurora Mobile Threat Defense — Addressing Your Highest‑Trusted, Least Protected Endpoints - Arctic Wolf Aurora Mobile Threat Defense — Addressing Your Highest‑Trusted, Least Protected Endpoints - Arctic Wolf How Aurora Managed Endpoint Defense Combines Experts and Technology to Simplify Security Aurora Endpoint Sicherheitsportfolioa | Arctic Wolf From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services arcticwolf.com arcticwolf.com Arctic Wolf Product Updates: May 2026 arcticwolf.com Arctic Wolf Product Updates: May 2026 FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch - Arctic Wolf FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch What’s New What’s Next with Arctic Wolf: May 2026 Update Cybersecurity Trends in the Age of AI arcticwolf.com Arctic Wolf、AI搭載のモバイル脅威防御ソリューションを発表、 増加するモバイル端末を標的としたサイバー攻撃から組織を保護 How Arctic Wolf Aurora Mobile Threat Defense Protects the Mobile Attack Surface How AI Is Transforming Detection Engineering 「Aurora Mobile Threat Defense」の提供が開始されました Accelerating Cloud Security Outcomes Together: Why Arctic Wolf and Wiz are Redefining What’s Possible - Arctic Wolf InfoSecurity Europe 2026
CVE-2026-50751 | Arctic Wolf
Arctic Wolf · 2026-06-10 · via Arctic Wolf

Security bulletin with an exclamation point in the middle of the screen

Security bulletin with an exclamation point in the middle of the screen

CVE-2026-50751 is a critical vulnerability (CVSS 9.3) in Check Point Remote Access VPN, Mobile Access, and Spark Firewall products using the deprecated IKEv1 key exchange protocol.

Security bulletin with an exclamation point in the middle of the screen

Threat Summary 

CVE-2026-50751 is a critical vulnerability (CVSS 9.3) in Check Point Remote Access VPN, Mobile Access, and Spark Firewall products using the deprecated IKEv1 key exchange protocol. The flaw is due to a logic error in certificate validation during the IKEv1 handshake that enables unauthenticated attackers to bypass user authentication entirely and initiate VPN connections. Once exploited, attackers gain remote access to internal systems as an authenticated VPN user. 

The vulnerability affects numerous Check Point releases—specifically, all remote or mobile access configurations permitting IKEv1; supported versions include R81.20, R82, R82.10, while earlier versions (R81.10, R81, R80.40, R80.20.X) are end-of-support and will not receive patches. The exploit works if IKEv1 is enabled, legacy client support is present, and machine certificates are not required. 

The timeline of exploitation began on May 7, 2026, with Check Point’s investigation starting June 4 and public advisory, hotfix, and CVE publication occurring on June 8. On the same day, CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating urgent remediation by all federal civilian executive branch agencies by June 11, 2026. Community forums and technical analyses highlight concern about the extended exploitation window and the criticality of swift mitigation. 

Check Point has released emergency hotfixes (SK185033) for supported versions and provided immediate workarounds. No public proof-of-concept exploit is currently available, but active exploitation in the wild is confirmed and likely coordinated through skilled threat actors using VPS infrastructure. Indicators of Compromise (IOCs) and specific attack vectors have been shared. Organizations with affected deployments face a substantial risk of unauthorized access, ransomware, and data theft. 

Recommendations for CVE-2026-50751

1. Immediate Actions 

    • Review all Check Point Security Gateway deployments for usage of IKEv1 in Remote Access or Mobile Access VPN configurations. 
    • Apply the official Check Point hotfix (SK185033) to all supported versions (R81.20 Jumbo Hotfix Take 142+, R82, R82.10); ensure the environment matches published criteria before patching. 
    • For unsupported versions (R81.10, R81, R80.40, R80.20.X), upgrade immediately to a supported, patched version. No hotfixes are issued for end-of-support (EoS) releases. 
  • Configuration and Hardening 
    • Disable IKEv1 for all remote access use cases on affected gateways; enforce IKEv2-only VPN encryption. 
    • Remove support for legacy remote access clients. 
    • Require machine certificate authentication for VPN endpoints where possible. 
    • Enable and update Intrusion Prevention System (IPS) signatures to block known attack vectors. 

2. Detection, Monitoring and Incident Response 

  1. Block the following known attacker IP addresses at the network perimeter: 
    • 45.77.149[.]152 
    • 209.182.225[.]136 
    • 38.60.157[.]139 
    • 162.33.177[.]101 
    • 45.76.26[.]42 
    • 144.208.127[.]155 
    • 38.54.88[.]201 
    • 38.54.107[.]167 
    • 66.42.99[.]200 

3. Monitor for anomalous VPN session activity, successful remote connections with IKEv1 but missing expected authentication. 

4. Review VPN and firewall logs dating back to May 7, 2026, for suspicious activity. 

5. If compromise is suspected, initiate incident response, including credential resets, internal lateral movement checks, and forensic analysis. 

Long-Term Measures

  • Permanently deprecate IKEv1 and legacy VPN clients in all environments. 
  • Regularly review and limit VPN access, enforce least privilege and multi-factor authentication (MFA) where possible. 
  • Conduct ongoing security awareness and update response playbooks for future zero-day and VPN risks. 

For U.S. Federal Agencies

  • Comply with CISA BOD 22-01: Remediate by June 11, 2026, per KEV catalog requirements. 

Temporary Workarounds 

  • Disable IKEv1 Protocol: The primary workaround is to configure all gateways to operate in IKEv2-only mode for remote and mobile access VPN, using SmartConsole or the relevant CLI/configuration tools. This immediately blocks the exploit vector. 
  • Refuse Legacy Clients: Remove or block all legacy VPN clients that cannot operate using IKEv2. 
  • Mandate Machine Certificates: Enforce requirement for machine certificate authentication; this breaks the authentication bypass even on IKEv1. 
  • Community Script/Automation: Check Point community (CheckMates) provides validated mitigation scripts to automate IKEv1 disabling and client exclusion (review and test before deployment). 
  • Limitations: These workarounds may affect connectivity for legacy devices or clients; careful validation and communication with affected users is advised. If you are unable to apply patches, you must implement one or more of these measures immediately. 
  • Block Attacker IPs: As an added perimeter measure, block provided malicious IPs (see above) at firewalls and VPN concentrators. 

References 

Share this post:

What to read next

Arctic Wolf Blog Featured Image

10 min read

Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257

June 11, 2026

Arctic Wolf Blog Featured Image

4 min read

Closing the Gap Between Vulnerability Detection and Real Risk Reduction

June 10, 2026