Network Security · 4 min read

Critical VPN zero-day (CVE-2026-50751) exploited by ransomware gangs

A critical authentication-bypass flaw (CVSS 9.3) in a widely used remote-access VPN was exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog, with federal agencies given just three days to patch.

Network equipment in a data centre

Published 9 June 2026

On 8 June 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-50751 to its Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to patch within three days — an unusually short deadline reserved for flaws under active attack.

What happened

The vulnerability is a critical authentication-bypass weakness, rated CVSS 9.3, in a widely deployed remote-access VPN. It affects gateways still configured to accept the deprecated IKEv1 key-exchange protocol with legacy remote-access clients that do not require a machine certificate. A logic flaw in how the VPN validates certificates during the IKEv1 exchange lets an unauthenticated attacker negotiate a session and connect with no valid credentials.

Security researchers observed exploitation in the wild as early as 7 May 2026, rising through early June. The campaign has so far been limited to several dozen organisations, and at least one intrusion has been linked — with medium confidence — to an affiliate of the Qilin ransomware operation. A related flaw, CVE-2026-50752 (CVSS 7.4) in the same IKEv1 code path, could enable man-in-the-middle attacks against site-to-site tunnels under certain configurations.

Why it matters

VPN and firewall appliances sit at the network edge and are trusted to gate remote access. An authentication bypass turns that trust into an open door: attackers gain a foothold without phishing or malware, then escalate privileges and move laterally toward data and backups — the classic precursor to a ransomware deployment. Edge devices are also notoriously hard to patch quickly when they are numerous, business-critical, and only reachable during maintenance windows.

The lesson is not that one vendor is uniquely flawed — every edge platform issues critical fixes — but that organisations need a way to retire weak protocols, enforce strong authentication, and push emergency patches across the whole fleet fast.

How iconnet helps

A modern next-generation firewall closes this class of risk: enforce certificate-based authentication, retire deprecated protocols such as IKEv1, and centrally push emergency hotfixes across every gateway in minutes. Forcepoint NGFW combines hardened VPN, deep packet inspection and built-in IPS — all managed from a single console (the SMC) — so a perimeter flaw can be patched and policy-enforced fleet-wide before attackers reach the network.

Talk to a security specialist

Tell us about your environment and goals. Our engineers will help you scope the right solution — no obligation.