Check Point links VPN zero-day attacks to Qilin ransomware gang
Check Point patched two VPN flaws, including one used in zero-day attacks tied to Qilin ransomware activity. The exploitation hit only a few dozen organizations, but was active worldwide.
Intelligence analysis by GPT-5.4 Mini

Check Point says attackers abused a critical authentication-bypass bug in older VPN setups that use deprecated IKEv1. The company also found a second certificate-validation flaw and urged customers to patch or lock down legacy access paths immediately.
Check Point found a hole in some older VPN setups, which are like the locked front doors of a company’s network. Thieves used it to sneak in without a key, and in one case that trail led to ransomware crooks called Qilin.
Analysis
What happened
Check Point says it released security updates for a critical flaw, tracked as CVE-2026-50751, affecting Remote Access VPN and Mobile Access deployments. The bug can let unauthenticated remote attackers bypass authentication on certain VPN and firewall setups and establish a remote access VPN connection.
The company says the issue only affects systems configured to use the deprecated IKEv1 key exchange protocol, specifically gateways that accept legacy Remote Access clients and do not require a machine certificate. Check Point says exploitation began on May 7, increased in early June, and affected only “a few dozen” organizations worldwide.
Why the incident stands out
Check Point says at least one case involved post-compromise activity associated with a Qilin ransomware affiliate. That does not mean every attack was Qilin, but it does show the flaw was being used in real intrusion activity rather than just tested by researchers.
While investigating the first issue, Check Point also found CVE-2026-50752, a second flaw in certificate validation for deprecated IKEv1 use. The company says that bug could support man-in-the-middle attacks on site-to-site VPN connections, though it has not seen exploitation in the wild.
What defenders should do
Check Point urges customers to apply updates immediately. For organizations that cannot patch right away, it recommends removing support for the legacy remote access client, forcing Remote Access VPN authentication to IKEv2 only, making machine certificate authentication mandatory, and enabling IPS with the provided signatures.
The practical message is straightforward: older VPN settings are not just technical debt. In this case, they were the attack path.
Key points
- Check Point patched CVE-2026-50751, a critical authentication-bypass flaw in certain VPN and Mobile Access deployments.
- The company says attackers used the flaw in zero-day attacks starting on May 7 and intensifying in early June.
- At least one incident was linked to post-compromise activity associated with a Qilin ransomware affiliate.
- A second issue, CVE-2026-50752, affects certificate validation in deprecated IKEv1 use and may enable man-in-the-middle attacks.
- Check Point says only a few dozen organizations were affected, but urges immediate updates and legacy VPN hardening.
If organizations patch quickly and retire the older VPN setup, the attack path can be closed before wider abuse spreads. The extra mitigations Check Point lists could also reduce exposure for systems that cannot be updated immediately.
If companies keep legacy IKEv1 settings enabled, attackers may continue to use the same bypass to get inside network perimeters. Because VPN access can lead straight into internal systems, even a small number of successful intrusions can still become serious ransomware incidents.



