Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix
ID: 52db9ed2-5aad-56cf-a361-96c90a2f995c
STIX ID: report--52db9ed2-5aad-56cf-a361-96c90a2f995c
Feed Name: The Register (Security)
Check Point released an emergency hotfix for a critical authentication-bypass zero-day (CVE-2026-50751) in its Remote Access and Mobile Access VPN products after observing exploitation beginning May 7; investigators tied at least one compromise to a Qilin ransomware affiliate. A second related issue (CVE-2026-50752) affecting IKEv1 certificate validation was also identified, and Check Point published mitigations and indicators of compromise (attacker IPs, certificate subjects) for customers to hunt for suspicious VPN authentication attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
