Check Point VPN CVE-2026-50751 Auth Bypass Exploited by Qilin Ransomware Affiliate (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- CVE-2026-50751 authentication bypass in Check Point Remote Access VPN/Mobile Access with IKEv1
- Exploited by Qilin ransomware affiliate since May 7, 2026; limited to dozens of organizations
- Second vulnerability CVE-2026-50752 (CVSS 7.4) found, not exploited
- Patches available via Check Point hotfix
"Check Point disclosed a critical authentication bypass vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access solutions, exploited by a Qilin ransomware affiliate since May 7, 2026. The flaw (CVSS 9.3) affects deployments using deprecated IKEv1. Attacks limited to dozens of organizations globally. Patches are available."
no comments yet.