Check Point VPN Zero-Day Tied to Qilin
Check Point pushed patches for a Remote Access VPN and Mobile Access flaw hit by zero-day attacks.
The flaw lets attackers bypass authentication and reach internal networks. One observed case was tied, with medium confidence, to a Qilin ransomware affiliate.
Affects only deployments using the deprecated IKEv1 key exchange protocol (Remote Access VPN, Mobile Access, Spark). Tracked as CVE-2026-50751, CVSS 9.3.
Check Point released updates across multiple gateway models and versions in a single coordinated push.
