news.mlab.sh
Back to the feed
vulnerability

Check Point links VPN zero-day attacks to Qilin ransomware gang

High
Summary

Check Point identified a zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access deployments, exploited by the Qilin ransomware gang. The flaw allowed unauthenticated attackers to bypass authentication and establish remote access connections, primarily targeting systems using the IKEv1 protocol. This incident highlights the ongoing risk of legacy protocol vulnerabilities and the evolving tactics of ransomware groups.

On May 7th, Check Point began tracking a critical zero-day vulnerability (CVE-2026-50751) within its Remote Access VPN and Mobile Access products. This flaw allowed attackers to bypass authentication protocols, enabling unauthorized remote access connections. The vulnerability specifically targeted deployments utilizing the IKEv1 key exchange protocol, a legacy system that Check Point advises against using due to its inherent security weaknesses. The initial exploitation was limited to approximately "a few dozen" organizations globally, with confirmed activity linked to the Qilin ransomware operation, which has previously targeted numerous high-profile entities.

Read the full article at BleepingComputer