A zero-day in Check Point's VPN software let a ransomware crew skip past password authentication for about a month with no vendor fix available.
Check Point disclosed and patched CVE-2026-50751, a critical flaw in its Remote Access VPN and Mobile Access products rated 9.3 on the CVSS severity scale. The vulnerability allowed an unauthenticated attacker to bypass password authentication entirely. A Qilin ransomware affiliate had been exploiting it for roughly a month before the patch landed, meaning anyone targeted during that window had no vendor-supplied remedy while the attacks were underway.
An auth bypass at 9.3 severity doesn't require phishing, credential theft, or patience — anyone aware of the flaw could walk straight in. VPN appliances have become a favored ransomware entry point precisely because they sit at the network perimeter and typically receive less scrutiny than internal servers. Check Point's products are broadly deployed in enterprise environments, so the exposure window was wide.
This isn't the first time Check Point's VPN line has drawn unwanted attention: a separate vulnerability in the same product family was actively exploited in the wild in 2024. Two critical VPN flaws in two years is a signal that perimeter appliances deserve the same continuous monitoring enterprises apply to their most exposed servers — maybe more.
