logo

Check Point VPN Zero-Day Exploited Since Early May by Qilin Ransomware

ID: 18878816-1acb-5bce-b342-2685ac2f20ff

STIX ID: report--18878816-1acb-5bce-b342-2685ac2f20ff

Feed Name: CosmicBytez Labs

Threat Score
92/100

Date Published: 2026-06-14

Date Updated: 2026-06-14

...
...

A critical zero-day authentication-bypass in Check Point VPN products (Quantum Spark, CloudGuard Network Security, Quantum Security Gateways) has been actively exploited since early May 2026 and is linked to a Qilin ransomware affiliate; CISA added the flaw to its Known Exploited Vulnerabilities catalog with a 72-hour remediation directive and Check Point published patches and guidance. The report provides impact details, a timeline, recommended immediate mitigations (apply patch, review logs, disable VPN if needed, enable MFA, network segmentation), and indicators of compromise for hunting and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.