Last updated 1 month ago
Check Point, an Israel-based technology company, disclosed a critical zero-day vulnerability in its VPN product that has been under active exploitation since early May 2026. The vulnerability, which has not yet been assigned a CVE, allows attackers to bypass authentication and gain unauthorized access to affected VPN appliances. At least one incident has been attributed to a Qilin ransomware affiliate, indicating the flaw is being leveraged for initial access in ransomware campaigns.
The attack chain involves exploitation of the zero-day vulnerability in Check Point VPN appliances, providing the threat actor with initial access to target networks. The Qilin ransomware affiliate, known for deploying ransomware and exfiltrating data, has been linked to at least one confirmed incident. No specific data types have been reported as compromised, but the access gained could enable lateral movement and data theft.
No post-incident developments have been reported beyond the initial disclosure and attribution to the Qilin ransomware affiliate. Check Point has not released a patch or mitigation details at the time of reporting.
Exploitation of a critical zero-day vulnerability in Check Point VPN
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Threat Actor