CVE-2026-50751: Check Point VPN Zero-Day Exploited by Qilin Ransomware
How Qilin ransomware operators exploited a Check Point VPN zero-day to gain initial network access.
Qilin ransomware operators weaponized a zero-day authentication bypass in Check Point Security Gateways configured with IPsec and Remote Access VPN, exploiting perimeter appliances to establish enterprise-wide ransomware deployments.
CVE-2026-50751 (CWE-287: Improper Authentication)
Threat Actor: Qilin Ransomware Group
Severity: Critical 9.8
Vector: Remote Access VPN / Mobile Access Blade
What's Affected
Check Point Quantum Security Gateway appliances with Remote Access VPN or Mobile Access software blades enabled when configured with local password authentication.
Attack Chain Breakdown
Qilin affiliates used this zero-day to bypass Active Directory authentication checks on the gateway, extract local password hashes, and pivot through internal subnets before staging ransomware lockers.