Check Point Links Exploited VPN Zero-Day to Qilin Ransomware Activity

Check Point Links Exploited VPN Zero-Day to Qilin Ransomware Activity

Share Facebook X LinkedIn Email

Check Point has patched a critical VPN authentication bypass flaw exploited as a zero-day, with at least one attack linked to the Qilin ransomware gang. The vulnerability affects legacy IKEv1 Remote Access VPN and Mobile Access deployments, allowing attackers to establish unauthorized VPN connections if systems are not updated or properly hardened.

Check Point has released security updates for a critical vulnerability affecting certain Remote Access VPN, Mobile Access, and Spark firewall deployments after confirming that the flaw was exploited in zero-day attacks.

The vulnerability, tracked as CVE-2026-50751, is an authentication bypass issue affecting deployments that still use the deprecated IKEv1 key exchange protocol. Successful exploitation can allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without valid user credentials.

According to Check Point, exploitation has so far been limited to a few dozen targeted organizations globally. However, at least one incident involved post-compromise activity associated with a Qilin ransomware affiliate, raising the severity of the threat for organizations still relying on legacy VPN configurations.

The flaw affects environments where security gateways accept legacy Remote Access clients, use deprecated IKEv1, and do not require machine certificate authentication. In these cases, an attacker can abuse a logic weakness in the VPN authentication flow to gain unauthorized remote access.

Check Point says attacks began on May 7 and increased in early June. The company is urging customers using IKEv1-based Remote Access VPN configurations to apply the available security updates immediately.

Remote access VPN flaws remain highly attractive to ransomware groups because they provide direct access into corporate networks. Once attackers establish VPN access, they may attempt credential theft, privilege escalation, lateral movement, data exfiltration, ransomware deployment, or persistence through additional remote access tools.

Check Point also identified a second vulnerability, CVE-2026-50752, during its investigation. This flaw affects certificate validation in deprecated IKEv1 site-to-site VPN configurations and could be exploited in man-in-the-middle attacks against site-to-site VPN connections. Check Point has not observed exploitation of CVE-2026-50752 in the wild, but customers are advised to apply updates to reduce exposure.

For organizations unable to immediately patch, Check Point recommends several mitigation steps. Customers should remove support for legacy remote access clients, configure Remote Access VPN authentication to use IKEv2 only, require machine certificate authentication, enable IPS protections, and download the latest signatures.

Security teams should also review VPN logs for unusual authentication activity, unexpected remote access sessions, failed or abnormal login attempts, new or unfamiliar VPN client connections, and suspicious access originating from unusual geographies or unmanaged devices.

Because this vulnerability can provide attackers with an initial access path, defenders should treat any exposed vulnerable gateway as a high-priority system. Organizations should also rotate potentially exposed credentials, verify VPN user accounts, check for unauthorized administrator changes, and inspect internal systems for signs of lateral movement.

The involvement of Qilin makes the issue especially concerning. Qilin, originally known as Agenda, emerged in 2022 as a ransomware-as-a-service operation and has since claimed hundreds of victims on its leak site. The group has targeted organizations across manufacturing, healthcare, legal services, government, education, and critical business services.

Qilin affiliates are known for double-extortion tactics, where attackers steal data before encrypting systems and then pressure victims by threatening to publish stolen information. In several recent ransomware campaigns, VPN appliances and edge devices have served as the initial access point, reinforcing the importance of quickly patching internet-facing security gateways.

The broader takeaway is clear: legacy VPN protocols and outdated remote access configurations remain a major enterprise risk. Even when a product is actively supported, deprecated settings such as IKEv1 can create attack paths that modern security controls may not fully compensate for.

Organizations using Check Point Remote Access VPN or Mobile Access should immediately verify whether IKEv1 is enabled, confirm whether machine certificate authentication is required, apply the latest hotfixes, and monitor for indicators of compromise associated with unauthorized VPN access.

Aaron Fare
More from this author

Aaron Fare

View this author’s public articles and updates.

View author profile →
Discussion

Comments

0 public comments

No comments yet

Be the first to add a comment to this article.

Add a comment

Sign In