A CVSS 9.3 flaw in Check Point Remote Access VPN let unauthenticated attackers bypass certificate validation by supplying a crafted IKEv1 VendorID payload — exploited for 32 days before a patch, with one confirmed Qilin ransomware post-compromise chain. Check Point VPN Authentication Bypass (CVE-2026-50751): Client-Controlled IKEv1 Auth Flipped by Ransomware Affiliate on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Te…
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
Read the full article on stephaneLarue.com A critical flaw (CVE-2026-50751) allows you to connect to VPN Check Point without a password. The ransomware Qilin has been exploiting it since May 7th; CISA and ANSSI call for urgent correction.