logo

Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)

ID: ee706436-3123-5ef2-9c35-b4fccfbaa4dc

STIX ID: report--ee706436-3123-5ef2-9c35-b4fccfbaa4dc

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Zeljka Zorz

...
...

Check Point disclosed CVE-2026-50751, an authentication-bypass in Remote Access VPN, Mobile Access and Spark firewalls when configured to use deprecated IKEv1; exploitation has been observed since early May 2026 and increased in June, with a Qilin ransomware affiliate linked to at least one confirmed post-compromise case, use of VPS infrastructure and Rclone for exfiltration, and published IoCs and mitigations (patch, disable IKEv1, require machine certificates, review logs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.