Check Point links VPN zero-day attacks to Qilin ransomware gang
Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. [...]
AI Analysis
Technical Summary
CVE-2026-50751 is a critical authentication bypass vulnerability in Check Point Remote Access VPN and Mobile Access products that use the deprecated IKEv1 key exchange protocol. It permits unauthenticated, remote attackers to bypass authentication and establish VPN connections. Exploitation has been confirmed in the wild, including attacks linked to the Qilin ransomware gang. The vulnerability affects configurations that accept legacy Remote Access clients and do not require machine certificates. Check Point also identified CVE-2026-50752, a certificate validation flaw in IKEv1, which could facilitate man-in-the-middle attacks on site-to-site VPNs but has not been exploited yet. Check Point has released patches and recommends disabling IKEv1 in favor of IKEv2, enforcing machine certificate authentication, and enabling IPS protections.
Potential Impact
Successful exploitation of CVE-2026-50751 allows unauthenticated remote attackers to bypass VPN authentication controls, potentially granting unauthorized remote access to internal networks. This has led to targeted attacks against a limited number of organizations globally, including confirmed post-compromise activity by the Qilin ransomware affiliate. CVE-2026-50752, if exploited, could enable man-in-the-middle attacks on site-to-site VPN connections, potentially compromising data confidentiality and integrity, though no exploitation has been observed to date.
Mitigation Recommendations
Check Point has released official security updates that patch both CVE-2026-50751 and CVE-2026-50752. Customers are strongly advised to apply these updates immediately. For those unable to patch promptly, Check Point recommends removing support for legacy remote access clients, configuring Remote Access VPN Authentication to use IKEv2 only, making machine certificate authentication mandatory, and enabling IPS with updated signatures. These measures mitigate the vulnerabilities until patches can be applied.
Check Point links VPN zero-day attacks to Qilin ransomware gang
Description
Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-50751 is a critical authentication bypass vulnerability in Check Point Remote Access VPN and Mobile Access products that use the deprecated IKEv1 key exchange protocol. It permits unauthenticated, remote attackers to bypass authentication and establish VPN connections. Exploitation has been confirmed in the wild, including attacks linked to the Qilin ransomware gang. The vulnerability affects configurations that accept legacy Remote Access clients and do not require machine certificates. Check Point also identified CVE-2026-50752, a certificate validation flaw in IKEv1, which could facilitate man-in-the-middle attacks on site-to-site VPNs but has not been exploited yet. Check Point has released patches and recommends disabling IKEv1 in favor of IKEv2, enforcing machine certificate authentication, and enabling IPS protections.
Potential Impact
Successful exploitation of CVE-2026-50751 allows unauthenticated remote attackers to bypass VPN authentication controls, potentially granting unauthorized remote access to internal networks. This has led to targeted attacks against a limited number of organizations globally, including confirmed post-compromise activity by the Qilin ransomware affiliate. CVE-2026-50752, if exploited, could enable man-in-the-middle attacks on site-to-site VPN connections, potentially compromising data confidentiality and integrity, though no exploitation has been observed to date.
Mitigation Recommendations
Check Point has released official security updates that patch both CVE-2026-50751 and CVE-2026-50752. Customers are strongly advised to apply these updates immediately. For those unable to patch promptly, Check Point recommends removing support for legacy remote access clients, configuring Remote Access VPN Authentication to use IKEv2 only, making machine certificate authentication mandatory, and enabling IPS with updated signatures. These measures mitigate the vulnerabilities until patches can be applied.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/","fetched":true,"fetchedAt":"2026-06-08T13:18:39.341Z","wordCount":691}
Threat ID: 6a26c12fe29bf47b50e7ba1e
Added to database: 6/8/2026, 1:18:39 PM
Last enriched: 6/8/2026, 1:18:46 PM
Last updated: 6/9/2026, 6:53:51 AM
Views: 32
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.