iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Microsoft CEO Satya Nadella warns AI dominance could 'hollow out entire industries' Open-source Discord alternatives: What Stoat and Element actually fix - Engadget India launches producer price index; wholesale inflation gauge to be phased out in five years India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Why UK data sovereignty is the next competitive advantage for digital industries Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs Microsoft CEO Satya Nadella warns AI dominance could 'hollow out entire industries' Open-source Discord alternatives: What Stoat and Element actually fix - Engadget India launches producer price index; wholesale inflation gauge to be phased out in five years India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Why UK data sovereignty is the next competitive advantage for digital industries Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs
Home ›› Technology ›› Cybersecurity ›› Check Point Patches Critical VPN Flaw Exploited by Qilin Ransomware Group

Check Point Patches Critical VPN Flaw Exploited by Qilin Ransomware Group

Check Point addressed a critical VPN authentication bypass vulnerability (CVE-2026-50751, CVSS 9.3) that has been exploited by the Qilin ransomware group since early May 2026. The attacks affected dozens of organizations globally, with at least one case leading to Qilin ransomware deployment. Customers are urged to apply fixes and mitigations immediately.

iG
iGEN Editorial
June 14, 2026
Check Point Patches Critical VPN Flaw Exploited by Qilin Ransomware Group

Check Point has declared it fixed a critical vulnerability in its VPN products that has been exploited in ransomware attacks against dozens of organizations worldwide, according to a security advisory published by the company.

The authentication bypass flaw, tracked as CVE-2026-50751 with a CVSS severity score of 9.3/10 (critical), allowed remote threat actors to establish a remote access VPN connection without a valid user password, Check Point reported.

Attack Timeline and Scale

Check Point's VP of Research, Lotem Finkelstein, noted that attacks leveraging this bug started on May 7, 2026 – more than a month before the advisory. In early June, the attacks escalated in volume, drawing the company's attention, and on June 4 Check Point realized it was an actively exploited zero-day.

Finkelstein attempted to contextualize the attacks as relatively low volume: "We have observed indications that exploitation has been limited to a relatively small number of targeted organizations (several dozen globally), primarily over the past few days." He added that in at least one case, the compromise was used to deploy Qilin ransomware.

Vulnerability Detail Value
CVE ID CVE-2026-50751
Severity Score 9.3 (Critical)
Flaw Type Authentication bypass
Impact Remote VPN access without valid password
Affected Products Mobile Access/SSL VPNs, Remote Access VPNs, Spark Firewalls with deprecated IKEv1
Attack Start Date May 7, 2026
Exploitation Confirmed June 4, 2026

Qilin Ransomware and Infrastructure Targets

Qilin is a major ransomware player that frequently targets critical infrastructure providers. In February 2026, the group added the Transport Workers Union of America (TWU) Local 100 chapter to its data leak site, claiming it had exfiltrated and leaked all stolen data onto the dark web, according to previous reports cited in the advisory.

The bug affects Mobile Access/SSL VPNs, Remote Access VPNs, and Spark Firewalls configured to use the deprecated IKEv1 key exchange protocol. Check Point's advisory did not disclose the identities or industries of the victims, but the group's history suggests critical infrastructure sectors are at elevated risk.

Mitigation and Response

Check Point urged its customers to apply the provided fixes and to deploy mitigations and other hardening methods as soon as possible. A full list of indicators of compromise (IoC) has also been made available. The company did not discuss specific victims or attack vectors beyond the authentication bypass.

For enterprise technology decision-makers, especially those in supply chain and logistics that rely on Check Point VPNs for secure remote access, this incident underscores the need for immediate patching. Given Qilin's known targeting of transport unions, logistics companies using Check Point products should prioritize updating affected systems.

Check Point's advisory provides technical details and mitigation steps. Security teams should verify that their Mobile Access/SSL VPN, Remote Access VPN, and Spark Firewall configurations are not using deprecated IKEv1 and are patched against CVE-2026-50751.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Technology

Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives

Samsung MAX VPN ceased operations on June 15, 2026, affecting over 50 million users. The app remains as a dead shell unless uninstalled. Users are advised to switch to third-party VPNs for continued protection.

June 15, 2026
Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations Technology

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.

June 15, 2026
Microsoft Defender Zero-Day Exploit Threatens System Security Technology

Microsoft Defender Zero-Day Exploit Threatens System Security

A newly disclosed zero-day vulnerability in Microsoft Defender, named 'RoguePlanet', allows attackers to gain SYSTEM privileges on Windows 10 and 11. Security researcher Chaotic Eclipse revealed this exploit, highlighting ongoing tensions with Microsoft over vulnerability disclosures.

June 10, 2026
AI's Role in Accelerating Cyber Vulnerabilities Technology

AI's Role in Accelerating Cyber Vulnerabilities

AI is significantly reducing the time it takes for adversaries to exploit vulnerabilities, challenging traditional cybersecurity defenses. Organizations must shift focus from prevention to resilience to maintain operations.

June 10, 2026