A Qilin ransomware affiliate exploited a Check Point VPN zero-day for a month before a patch existed
Check Point has patched a critical zero-day vulnerability (CVE-2026-50751, CVSS 9.3) in its Remote Access VPN and Mobile Access products that was actively exploited by a Qilin ransomware affiliate for roughly a month before a fix was available. The flaw allows unauthenticated attackers to bypass password authentication and establish a VPN session by exploiting a logic error in certificate validation in the deprecated IKEv1 protocol. Exploitation began as early as May 7, targeting dozens of organizations globally. A second related vulnerability (CVE-2026-50752, CVSS 7.4) enabling adversary-in-the-middle attacks was also patched, though it shows no evidence of in-the-wild exploitation. The Qilin group is also known to exploit VPN flaws from Palo Alto Networks, Fortinet, and F5.