A Qilin ransomware affiliate exploited a Check Point VPN zero-day for a month before a patch existed

Chronological Source Flow
Back

AI Fusion Summary

Check Point disclosed and patched a critical zero-day vulnerability, CVE-2026-50751, in its Remote Access VPN and Mobile Access products. The flaw carries a CVSS score of 9.3, enabling unauthenticated attackers to bypass password authentication entirely. A Qilin ransomware affiliate exploited this vulnerability for approximately one month, starting on May 7, before a patch became available. The security hole provided ransomware criminals a significant head start in targeting systems before the official fix was deployed by the company.
Community Comments
Loading updates...
0