More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Israeli firm Check Point rolled out urgent patches for a critical flaw in its Remote Access and Mobile Access VPNs. Tracked as CVE-2026-50751, the bug lets unauthenticated attackers bypass login on SSL VPNs, Remote Access VPNs or Spark firewalls that still use the outdated IKEv1 key exchange and don’t require machine certificates. Exploitation began on May 7 and ramped up in early June, hitting a few dozen organizations worldwide. In at least one case, the breach led straight to a Qilin ransomware incident.
If you can’t patch right away, Check Point advises dropping the legacy client, switching Remote Access authentication to IKEv2 only, making machine-cert authentication mandatory and turning on IPS with updated signatures. While probing CVE-2026-50751, researchers uncovered a second flaw, CVE-2026-50752, in the IKEv1 certificate validation. It could open the door to man-in-the-middle attacks on site-to-site VPN links, though there’s no proof it’s been abused yet. Patching both vulnerabilities closes off that risk.
Qilin emerged in August 2022 under the “Agenda” banner, operating as a Ransomware-as-a-Service outfit. Its dark web leak site lists nearly 400 victims, including big names like Yangfeng, Nissan, Asahi, Lee Enterprises, Synnovis and Australia’s Court Services Victoria. The confirmed compromise tied to CVE-2026-50751 shows Qilin affiliates moving from VPN breach to ransomware deployment. That swift chain of events underlines how critical timely patching and protocol upgrades have become.
Questions about this article
No questions yet.