Check Point VPN Zero-Day Exploited in Attacks
Check Point VPN Zero-Day Exploited in Ransomware Attacks A critical Check Point VPN zero-day vulnerability is being actively exploited in real-world attacks, including activity linked to Qilin ransomware. Tracked as CVE-2026-50751, the flaw affects Check Point Security Gateway products using Remote Access VPN and Mobile Access capabilities. The vulnerability allows an unauthenticated remote attacker to bypass user authentication and establish a VPN session without a valid user password. For enterprises, this is a serious perimeter security event. VPN systems are not just remote access tools. They are trusted gateways into internal networks, cloud-connected environments, administrative systems, sensitive applications, and business-critical infrastructure. When attackers bypass VPN authentication, they may gain the type of access defenders usually reserve for employees, contractors, administrators, and trusted users. What Happened: Check Point disclosed a critical authentication bypass v...