Check Point links VPN zero-day attacks to Qilin ransomware gang
Check Point said the flaw let attackers bypass VPN authentication and confirmed at least one post-compromise case linked to a Qilin affiliate.
- On Monday, Check Point released an emergency fix for CVE-2026-50751, a critical authentication bypass vulnerability affecting Remote Access VPN and Mobile Access deployments that attackers exploited for a month.
- Attacks against the bug began on May 7, according to Check Point VP of research Lotem Finkelstein, targeting deployments configured to use the deprecated IKEv1 key exchange protocol.
- At least one incident involved the Qilin ransomware operation, which claims responsibility for nearly 400 victims including Nissan, Asahi, and Lee Enterprises.
- While investigating the first flaw, Check Point found a second vulnerability, CVE-2026-50752, affecting certificate validation in deprecated IKEv1 key exchange that could enable man-in-the-middle attacks.
- Check Point urges customers to apply updates immediately, remove legacy remote access client support, configure Remote Access VPN Authentication to IKEv2 only, and set Machine Certificate Authentication as mandatory.
14 Articles
14 Articles
Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol
Check Point has issued emergency hotfixes for a pair of vulnerabilities affecting VPN deployments that still use the deprecated Internet Key Exchange version 1 (IKEv1) protocol, warning that one of the flaws is already being exploited in the wild. The more serious issue allows attackers to establish VPN sessions without a valid password, potentially giving them a foothold inside corporate networks. According to the company, attackers have been e…
A Qilin ransomware affiliate exploited a Check Point VPN zero-day for a month before a patch existed
Check Point patched CVE-2026-50751, a critical VPN auth bypass exploited since May 7. A Qilin ransomware affiliate used it to hit dozens of organisations.
Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix
Check Point released an emergency fix on Monday for a critical authentication bypass vulnerability affecting its Remote Access VPN and Mobile Access deployments - but attackers, including ransomware criminals, got a month-long head start. Attacks against the bug, tracked as CVE-2026-50751, began on May 7, according to Check Point VP of research Lotem Finkelstein, and picked up in early June. The security software vendor spotted suspicious activi…
Check Point links VPN zero-day attacks to Qilin ransomware gang
Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks.
Coverage Details
Bias Distribution
- 83% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









