Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)

2026-06-09T07:23:47Zf913e2e372ca95293a5f725ad73e0dd955be01474be9c1d7969fd14131c3ba3d
Apache ActiveMQCVSS 9.3CWE-287Check PointHP PolyICEIKEv1JolokiaMetasploitMobile AccessQilin ransomwareRCERemote Access VPNSpark FirewallVPNVoIPactive exploitationauthentication bypassstack-based buffer overflowzero-day

What happened

Rapid7 posts highlight multiple high-impact vulnerabilities and active exploitation: CVE-2026-50751 is a critical (CVSS 9.3) authentication-bypass in Check Point Remote Access VPN, Mobile Access, and Spark Firewall when using deprecated IKEv1 and not requiring machine certificates — it allows unauthenticated attackers to establish VPN sessions and is being actively exploited in the wild (activity observed since May 7, 2026; campaign limited in scope and at least one incident linked to a Qilin ransomware affiliate). Rapid7 also notes new Metasploit modules for Apache ActiveMQ RCE (CVE-2026-3417

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
f913e2e372ca95293a5f725ad73e0dd955be01474be9c1d7969fd14131c3ba3d
Enrichment time
2026-06-09T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751) · Baitaphish