CHECK POINT PATCHES CRITICAL VPN FLAW EXPLOITED IN RANSOMWARE ATTACKS
Check Point has patched a critical authentication bypass vulnerability in its VPN products that threat actors have been exploiting to launch ransomware attacks against organisations worldwide. The flaw, tracked as CVE-2026-50751, carries a severity score of 9.3 out of 10. It allowed remote attackers to establish VPN connections without valid user credentials. Check Point published a security advisory confirming the fix and urged customers to apply patches and mitigations immediately.
Check Point's VP of research, Lotem Finkelstein, confirmed that exploitation began on 7 May 2026, more than a month before the company identified the zero-day on 4 June. The vulnerability affects Mobile Access/SSL VPNs, Remote Access VPNs, and Spark Firewalls configured to use the deprecated IKEv1 key exchange protocol. Finkelstein described the volume of attacks as relatively limited, stating that exploitation affected several dozen organisations globally, primarily over recent days. In at least one confirmed case, attackers used the access gained through the flaw to deploy Qilin ransomware.
Check Point has published a full list of indicators of compromise alongside its advisory. The company did not disclose the identities or industries of the affected organisations. Qilin has previously targeted critical infrastructure providers, and in February 2026 claimed responsibility for a breach of Transport Workers Union of America Local 100, stating it had leaked stolen data onto the dark web. Check Point has directed all customers to apply the available fixes and additional hardening measures without delay.