AI Stories on SHORT INFO are generated & curated with AI
unverified 27 Jun, 18:43

Check Point confirms a critical VPN zero-day exploited by a Qilin ransomware affiliate

Check Point $CHKP has confirmed a critical flaw in its Remote Access and Mobile Access VPN, rated 9.3 out of 10, that lets an unauthenticated attacker open a VPN session without a valid password when a legacy key exchange protocol is enabled. The company says exploitation goes ba

Check Point $CHKP has confirmed CVE-2026-50751, a critical authentication-bypass flaw rated 9.3 out of 10 affecting its Remote Access and Mobile Access VPN blades, as well as Spark firewalls used by smaller businesses, on gateways still configured for the deprecated IKEv1 key exchange protocol. A remote, unauthenticated attacker can establish a VPN session without any valid password. According to Check Point, exploitation began in early May and climbed sharply in June, affecting a few dozen organizations so far, with at least one intrusion linked to an affiliate of the Qilin ransomware group. A VPN bypass is the kind of quiet entry point ransomware crews use to reach a whole network before defenders notice. Check Point has released emergency hotfixes and advises switching remote access to the newer IKEv2 protocol, and CISA has ordered US federal agencies to patch within days. Source: Check Point, BleepingComputer, SecurityWeek, Help Net Security, CISA.

#cyber
Published on
TikTokYouTubeBlueskyX