Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks
Check Point on Monday warned that a critical-severity authentication bypass vulnerability affecting its VPN and firewall products has been exploited in the wild as a zero-day.
Tracked as CVE-2026-50751 (CVSS score of 9.3), the security defect is described as a logic flow weakness in the validation process of Remote Access and Mobile Access certificates.
It exists in the deprecated IKEv1 key exchange and allows remote attackers to establish VPN sessions without a valid password.
According to Check Point, the vulnerability has been exploited in the wild since May 7, with activity surrounding it increasing in early June.
“To date, the observed exploitation has been limited to a few dozen targeted organizations globally,” the company notes in its advisory.
Check Point also says that at least one attack was confirmed to have been mounted by a Qilin ransomware affiliate.
Advertisement. Scroll to continue reading.
“Based on the post-exploitation activity we...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE