Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)

2026-06-08T19:23:48Z4799f35bc315bfe60e3768a92737f9d9da7c307d36ca061b1544851a664ee7fa
IKEv1active_exploitationapache_activemqauthentication_bypasscheck_pointcriticalcve-2026-0826cve-2026-34197cve-2026-50751hp_polyjolokiametasploitqilin_ransomwareremote_code_executionstack_buffer_overflowvoipvpnzero-day

What happened

Rapid7 reports multiple high-impact vulnerabilities: a critical Check Point Remote Access VPN/Mobile Access/Spark Firewall authentication bypass zero-day (CVE-2026-50751, CVSS 9.3) affecting deployments using deprecated IKEv1 without machine certificates — actively exploited in the wild since May 7, 2026 and linked to a Qilin ransomware affiliate. Other notable items include an Apache ActiveMQ RCE (CVE-2026-34197) with a new Metasploit module targeting Jolokia addNetworkConnector, and a critical unauthenticated stack-buffer-overflow RCE in HP Poly VVX/Trio VoIP phones (CVE-2026-0826) requiring

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
4799f35bc315bfe60e3768a92737f9d9da7c307d36ca061b1544851a664ee7fa
Enrichment time
2026-06-08T19:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751) · Baitaphish