Back to Blog
2026-06-24· 5 min read

Check Point VPN Zero-Day (CVE-2026-50751): Qilin Ransomware Exploits Authentication Bypass

A critical CVSS 9.3 vulnerability in Check Point VPN allows unauthenticated access. Qilin ransomware affiliates have been exploiting it since May 2026. Patch immediately.

Zero-Day VPN Check Point Ransomware Qilin CVE

The Vulnerability


**CVE-2026-50751** is a critical (CVSS 9.3) improper authentication vulnerability in Check Point Security Gateway products. It allows unauthenticated remote attackers to bypass password screens and establish VPN connections without valid credentials.


Affected Products


  • Check Point Remote Access VPN
  • Check Point Mobile Access/SSL VPN
  • Check Point Spark Firewalls

  • The vulnerability targets deployments using the **deprecated IKEv1 protocol**.


    Timeline


  • |Date | Event
  • |------|-------|

  • |May 7, 2026 | First attacks observed
  • |June 4, 2026 | Check Point launches investigation
  • |June 9, 2026 | CISA adds to KEV catalog
  • |June 11, 2026 | Federal patch deadline
  • |June 2026 | Exploitation attempts spike globally

  • The Ransomware Connection


    Check Point confirmed that at least one network intrusion involved post-compromise activity linked to an **affiliate of the Qilin ransomware syndicate**.


    Security analysts assess with "medium confidence" that attackers used Qilin ransomware to target corporate VPN appliances after gaining initial access through CVE-2026-50751.


    How the Attack Works


    1. **Attacker identifies** Check Point VPN using IKEv1

    2. **Exploits certificate validation flaw** to bypass authentication

    3. **Establishes VPN session** without valid password

    4. **Gains network access** to internal resources

    5. **Deploys ransomware** (Qilin) post-compromise


    How to Protect Yourself


    Immediate Actions

    1. **Apply emergency hotfixes** from Check Point

    2. **Switch from IKEv1 to IKEv2** if possible

    3. **Remove support for legacy client connections**

    4. **Enforce machine certificate authentication**

    5. **Review forensic logs** dating back to May 7, 2026


    Detection Indicators

  • VPN connections without proper authentication
  • Unusual traffic patterns from VPN endpoints
  • Lateral movement after VPN establishment
  • Ransomware deployment indicators

  • Long-Term Security

  • Deprecate legacy protocols (IKEv1)
  • Implement zero-trust network access (ZTNA)
  • Regular vulnerability assessments
  • Network segmentation

  • Scope of Impact


    The vulnerability affects firmware versions from **R82.10 down to R80.20.X**, posing risks to both small businesses and enterprise networks. Check Point stated the "blast radius remains contained" with a few dozen targeted organizations globally.


    Check Your Domain


    Scan your domain for exposed services and security misconfigurations.


    [Free security scan at Vaarta.space](https://vaarta.space)


    Ready to check your domain security?

    Run a free scan to identify potential vulnerabilities.

    Start Free Scan