AI Stories on SHORT INFO are generated & curated with AI
unverified 09 Jun, 10:40

Qilin ransomware exploits critical Check Point VPN zero-day (CVE-2026-50751)

A Qilin ransomware affiliate exploited a critical zero-day in Check Point VPN gateways to bypass authentication without a valid password. The flaw, CVE-2026-50751 (CVSS 9.3), affects Remote Access and Mobile Access deployments that still use the deprecated IKEv1 protocol. CISA ga

Check Point $CHKP has released a hotfix for CVE-2026-50751, a critical authentication-bypass zero-day (CVSS 9.3) in its Remote Access and Mobile Access VPN gateways, exploitable only when the deprecated IKEv1 key exchange is enabled. A ransomware affiliate linked to the Qilin group used it to connect without a valid password, with the earliest observed exploitation dating to May 7, 2026, nearly a month before a patch existed. So far a few dozen organizations worldwide have been hit, with at least one case ending in a ransomware deployment. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by June 11.

#cyber
Published on
TikTokYouTubeBlueskyX