CVE-2026-50751: Check Point VPN Zero-Day Exploited by Qilin Ransomware

How Qilin ransomware operators exploited a Check Point VPN zero-day to gain initial network access.

CVE-2026-50751: Check Point VPN Zero-Day Exploited by Qilin Ransomware
Photo by Scott Rodgerson / Unsplash
📌
Security Roundup Series: Week of August 3, 2026 • 5 min read deep dive

Qilin ransomware operators weaponized a zero-day authentication bypass in Check Point Security Gateways configured with IPsec and Remote Access VPN, exploiting perimeter appliances to establish enterprise-wide ransomware deployments.

🚨
Vulnerability Intelligence: CVE ID: CVE-2026-50751 (CWE-287: Improper Authentication) Threat Actor: Qilin Ransomware Group Severity: Critical 9.8 Vector: Remote Access VPN / Mobile Access Blade

What's Affected

Check Point Quantum Security Gateway appliances with Remote Access VPN or Mobile Access software blades enabled when configured with local password authentication.

Attack Chain Breakdown

Qilin affiliates used this zero-day to bypass Active Directory authentication checks on the gateway, extract local password hashes, and pivot through internal subnets before staging ransomware lockers.

Remediation

✅
Remediation Steps: Deploy Check Point's emergency hotfix immediately. Enforce Multi-Factor Authentication (MFA) across all VPN access policies. Review authentication logs for anomalous VPN logins from external IP addresses.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther