Skip to main content
See every side of every news story
Published loading...Updated

Check Point links VPN zero-day attacks to Qilin ransomware gang

Check Point said the flaw let attackers bypass VPN authentication and confirmed at least one post-compromise case linked to a Qilin affiliate.

  • On Monday, Check Point released an emergency fix for CVE-2026-50751, a critical authentication bypass vulnerability affecting Remote Access VPN and Mobile Access deployments that attackers exploited for a month.
  • Attacks against the bug began on May 7, according to Check Point VP of research Lotem Finkelstein, targeting deployments configured to use the deprecated IKEv1 key exchange protocol.
  • At least one incident involved the Qilin ransomware operation, which claims responsibility for nearly 400 victims including Nissan, Asahi, and Lee Enterprises.
  • While investigating the first flaw, Check Point found a second vulnerability, CVE-2026-50752, affecting certificate validation in deprecated IKEv1 key exchange that could enable man-in-the-middle attacks.
  • Check Point urges customers to apply updates immediately, remove legacy remote access client support, configure Remote Access VPN Authentication to IKEv2 only, and set Machine Certificate Authentication as mandatory.
Insights by Ground AI

14 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 83% of the sources are Center
83% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in Melville, United States on Monday, June 8, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal