Check Point VPN: Critical Vulnerability Allows Authentication Bypass (heise.de)
0xBASE INTEL BRIEF
- Critical Check Point VPN flaw allows authentication bypass (CVE-2026-50751, CVSS 9.3).
- Exploitation by Qilin ransomware group since May 2026; victims include Taiwanese targets.
- BSI warning issued; software updates and workaround available; second MITM vulnerability (CVE-2026-50752).
"Check Point warns of a critical vulnerability (CVE-2026-50751, CVSS 9.3) in its VPN software allowing authentication bypass. The Qilin ransomware group has been exploiting it since May 2026. Germany's BSI issued a warning. A second flaw (CVE-2026-50752, CVSS 7.4) enables man-in-the-middle attacks. Updates are available."
no comments yet.