This threat intelligence report highlights multiple critical vulnerabilities and active exploits, including a zero-day in Oracle PeopleSoft (CVE-2026-35273) exploited by ShinyHunters and an IKEv1 authentication bypass in Check Point VPNs (CVE-2026-50751) linked to Qilin ransomware. Additionally, the report details emerging AI-driven threats, a supply-chain compromise in the Arch User Repository deploying eBPF rootkits, and widespread patching efforts by Microsoft and Veeam.
CVE-2026-50751
5 posts
15th June – Threat Intelligence Report Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) Check Point Remote Access VPNs are vulnerable to a critical authentication bypass (CVE-2026-50751, CVSS 9.3) within the IKEv1 key exchange process. By sending a crafted 'VPNExtFeatures' Vendor ID payload, an attacker can manipulate the negotiation state to skip certificate signature verification, allowing full network access using only a valid username and the gateway's public ICA organization string.
Cyber Centre Daily Advisory Digest — 2026-06-09 (2 advisories) The Canadian Centre for Cyber Security issued advisories for actively exploited vulnerabilities in Check Point VPN/Firewall products (CVE-2026-50751, an authentication bypass) and Google Chrome (CVE-2026-11645). Both vulnerabilities have known exploits in the wild, with the Check Point flaw added to the CISA KEV database, necessitating immediate patching.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-42271, CVE-2026-50751) CISA has added CVE-2026-42271 (BerriAI LiteLLM Command Injection) and CVE-2026-50751 (Check Point Security Gateway Improper Authentication) to the Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. Organizations are strongly urged to prioritize remediation of these vulnerabilities to reduce exposure to cyberattacks.
Cyber Centre Daily Advisory Digest — 2026-06-08 (7 advisories) The Canadian Centre for Cyber Security released a daily digest covering seven security advisories from major vendors. Notably, Check Point has observed active exploitation of a critical authentication bypass vulnerability (CVE-2026-50751) affecting its VPN and Firewall products, requiring immediate mitigation.