Check Point VPN Flaw Targeted by Ransomware Actors
The vulnerability is a critical one and Check Point Research said that it’s likely that the actor targeting the bug is a financially motivated group.

The vulnerability is a critical one and Check Point Research said that it’s likely that the actor targeting the bug is a financially motivated group.
June 8, 2026 | 2 min read

Check Point is warning customers that an authentication bypass flaw in its Remote Access VPN and Mobile Access products has been exploited in targeted attacks since at least May 7. In at least one case, the attackers deployed ransomware after the initial compromise.
The vulnerability is a critical one and Check Point Research said that based on the exploitation activity thus far, it’s likely that the actor targeting the bug is a financially motivated group. As part of its investigation into the authentication flaw (CVE-2026-50751), Check Point discovered a separate bug (CVE-2026-50752) but that has not yet been exploited in the wild.
“By exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements.
Additional post-authentication activity is required to access internal resources or escalate privileges,” the Check Point advisory says.
“To date, the observed exploitation has been limited to a few dozen targeted organizations globally. One case involved confirmed post-compromise activity associated with Qilin ransomware affiliate.”
Check Point has released hotfixes for both of the vulnerabilities and recommends that customers running affected versions of Remote Access VPN and Mobile Access apply those as quickly as possible.
The company’s first indications of exploitation of CVE-2026-50751 came on June 4 and the company’s researchers then began looking into the activity and discovered the vulnerabilities and specific attacker behavior. Qilin is a ransomware-as-a-service operation that has been active for several years and its affiliates are known for targeting edge security device bugs and have a history of compromising big targets, including critical infrastructure operators and financial institutions.
“Based on the post-exploitation activity we observed, we assess with medium confidence that the actor behind the exploitation of CVE-2026-50752 is financially motivated, uses Qilin ransomware. We believe that this threat actor infrastructure is exploiting other VPN related vulnerabilities such as the ones published by Palo Alto, Fortinet and F5,” the Check Point advisory says.
“We identified indicators suggesting the actor may use the Tox protocol for communication, a pattern commonly associated with financially motivated ransomware actors.”
June 8, 2026 | 2 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.