logo

Critical Zero-Day Exploited in Check Point VPNs by Qilin Ransomware Gang

ID: 5fd1bc5b-67b6-5624-9938-b3299596367e

STIX ID: report--5fd1bc5b-67b6-5624-9938-b3299596367e

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-08

Date Updated: 2026-06-09

...
...

Check Point disclosed a critical CVE-2026-50751 zero-day in Remote Access and Mobile Access VPNs (CVSS 9.3) that allows authentication bypass via an IKEv1 certificate validation logic flaw and has been actively exploited since May 7, 2026 by a Qilin ransomware affiliate targeting dozens of organizations; patches and mitigations (including disabling IKEv1 and applying hotfixes) were issued immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.