Critical Check Point VPN Vulnerability Exploited by Ransomware Gang
ID: 7248664f-80ce-539f-9cb2-8ff5d60afc69
STIX ID: report--7248664f-80ce-539f-9cb2-8ff5d60afc69
Feed Name: ThreatCluster
Threat Score
Check Point disclosed CVE-2026-50751, a critical (CVSS 9.3) authentication-bypass in Remote Access VPN/Mobile Access (notably affecting IKEv1 setups) that has been exploited since May 7, 2026 by actors linked to the Qilin ransomware group; emergency hotfixes were released and CISA added the CVE to its KEV catalog, with organizations urged to patch immediately and monitor SmartConsole logs for suspicious certificate authentication and attacker IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
