iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering Saia’s Softer Q3 Margin Guidance Triggers 12% Share Drop Despite Record Q2 Results Buffalo meat and non-basmati rice lead 14% surge in India's Q1 agri exports Mahindra & Mahindra Records 34% Profit Jump Despite Commodity Cost Headwinds CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering Saia’s Softer Q3 Margin Guidance Triggers 12% Share Drop Despite Record Q2 Results Buffalo meat and non-basmati rice lead 14% surge in India's Q1 agri exports Mahindra & Mahindra Records 34% Profit Jump Despite Commodity Cost Headwinds
Home ›› Technology ›› Cybersecurity ›› Check Point Patches Critical VPN Flaw Exploited by Qilin Ransomware Group

Check Point Patches Critical VPN Flaw Exploited by Qilin Ransomware Group

Check Point addressed a critical VPN authentication bypass vulnerability (CVE-2026-50751, CVSS 9.3) that has been exploited by the Qilin ransomware group since early May 2026. The attacks affected dozens of organizations globally, with at least one case leading to Qilin ransomware deployment. Customers are urged to apply fixes and mitigations immediately.

iG
iGEN Editorial
June 14, 2026
Check Point Patches Critical VPN Flaw Exploited by Qilin Ransomware Group

Check Point has declared it fixed a critical vulnerability in its VPN products that has been exploited in ransomware attacks against dozens of organizations worldwide, according to a security advisory published by the company.

The authentication bypass flaw, tracked as CVE-2026-50751 with a CVSS severity score of 9.3/10 (critical), allowed remote threat actors to establish a remote access VPN connection without a valid user password, Check Point reported.

Attack Timeline and Scale

Check Point's VP of Research, Lotem Finkelstein, noted that attacks leveraging this bug started on May 7, 2026 – more than a month before the advisory. In early June, the attacks escalated in volume, drawing the company's attention, and on June 4 Check Point realized it was an actively exploited zero-day.

Finkelstein attempted to contextualize the attacks as relatively low volume: "We have observed indications that exploitation has been limited to a relatively small number of targeted organizations (several dozen globally), primarily over the past few days." He added that in at least one case, the compromise was used to deploy Qilin ransomware.

Vulnerability Detail Value
CVE ID CVE-2026-50751
Severity Score 9.3 (Critical)
Flaw Type Authentication bypass
Impact Remote VPN access without valid password
Affected Products Mobile Access/SSL VPNs, Remote Access VPNs, Spark Firewalls with deprecated IKEv1
Attack Start Date May 7, 2026
Exploitation Confirmed June 4, 2026

Qilin Ransomware and Infrastructure Targets

Qilin is a major ransomware player that frequently targets critical infrastructure providers. In February 2026, the group added the Transport Workers Union of America (TWU) Local 100 chapter to its data leak site, claiming it had exfiltrated and leaked all stolen data onto the dark web, according to previous reports cited in the advisory.

The bug affects Mobile Access/SSL VPNs, Remote Access VPNs, and Spark Firewalls configured to use the deprecated IKEv1 key exchange protocol. Check Point's advisory did not disclose the identities or industries of the victims, but the group's history suggests critical infrastructure sectors are at elevated risk.

Mitigation and Response

Check Point urged its customers to apply the provided fixes and to deploy mitigations and other hardening methods as soon as possible. A full list of indicators of compromise (IoC) has also been made available. The company did not discuss specific victims or attack vectors beyond the authentication bypass.

For enterprise technology decision-makers, especially those in supply chain and logistics that rely on Check Point VPNs for secure remote access, this incident underscores the need for immediate patching. Given Qilin's known targeting of transport unions, logistics companies using Check Point products should prioritize updating affected systems.

Check Point's advisory provides technical details and mitigation steps. Security teams should verify that their Mobile Access/SSL VPN, Remote Access VPN, and Spark Firewall configurations are not using deprecated IKEv1 and are patched against CVE-2026-50751.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year Technology

Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year

A vulnerability in Apple's Hide My Email service has been leaking users' real email addresses for at least a year, according to security researcher Tyler Murphy. In tests, all Hide My Email addresses were exploitable. Apple has acknowledged the issue but it remains unpatched. This story is part of a broader security roundup covering Pegasus spyware, Google's EU warnings, Meta chatbot testing, and the arrest of a Scattered Spider hacker.

July 4, 2026
Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Technology

Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives

Samsung MAX VPN ceased operations on June 15, 2026, affecting over 50 million users. The app remains as a dead shell unless uninstalled. Users are advised to switch to third-party VPNs for continued protection.

June 15, 2026
Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations Technology

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.

June 15, 2026
Microsoft Defender Zero-Day Exploit Threatens System Security Technology

Microsoft Defender Zero-Day Exploit Threatens System Security

A newly disclosed zero-day vulnerability in Microsoft Defender, named 'RoguePlanet', allows attackers to gain SYSTEM privileges on Windows 10 and 11. Security researcher Chaotic Eclipse revealed this exploit, highlighting ongoing tensions with Microsoft over vulnerability disclosures.

June 10, 2026