Check Point Issues Emergency Patches After IKEv1 Auth Bypass Draws Qilin Affiliate

Two certificate-validation flaws in Check Point's VPN stack — one already exploited, one caught during the ensuing review — have prompted hotfixes across nine Quantum software versions.

ThreatVectr Newsdesk· 2 min read
Check Point Issues Emergency Patches After IKEv1 Auth Bypass Draws Qilin Affiliate
Share

Check Point has released emergency hotfixes for two vulnerabilities in its VPN products, confirming that one is under active exploitation and has been linked to at least one Qilin ransomware affiliate.

The primary flaw, CVE-2026-50571, carries a CVSS score of 9.3 and falls under CWE-287 (Improper Authentication). It affects deployments still accepting Internet Key Exchange version 1 (IKEv1) connections through Remote Access VPN and Mobile Access VPN components. The defect sits in how those components validate certificates during authentication: an unauthenticated attacker can complete a VPN handshake without supplying a valid user password.

Exploitation began no later than early May. Check Point's vice president of research, Lotem Finkelstein, put the victim count at "a few dozen targeted organizations globally" in a public advisory, noting one confirmed case of post-compromise activity tied to a Qilin affiliate. IKEv1 has carried an end-of-support designation for years, but compatibility requirements have kept it live in enough environments to make it a workable target.

Affected Quantum Gaia versions span a wide range: R80.20.X (end-of-support), R80.40 (end-of-support), R81 (end-of-support), R81.10 (end-of-support), R81.10.X, R81.20, R82, R82.00.X, and R82.10.

The second vulnerability, CVE-2026-50752, surfaced during Check Point's internal investigation into the first flaw. Researchers used the company's BLAST agentic security platform to audit affected VPN components and found additional weaknesses in certificate validation logic. This one scores 7.4. It does not permit direct authentication bypass; instead, under specific conditions, it could allow a man-in-the-middle attacker to interfere with site-to-site VPN traffic. No exploitation attempts appear in the wild.

Check Point's advisory prescribes four remediation steps. First, apply the version-specific hotfixes — the most complete fix available. Second, audit SmartConsole logs for certificate authentication attempts matching known attacker infrastructure and certificate subject names; Check Point published query templates covering attacker IP, VPN/IKE activity, and time range. Third, remove support for legacy Remote Access client connections. Fourth, enforce IKEv2-only authentication under Global Properties for Remote Access VPN and set machine certificate authentication as mandatory.

Organizations running end-of-support Gaia releases face a harder choice: hotfixes exist for those versions, but the underlying unsupported posture remains a long-term liability. Migration to IKEv2 eliminates the vulnerable code path entirely.

© 2026 Threat Vectr