Web_Logo
Remote Support
Security Alert: Check Point VPN Zero-Day Under Active Ransomware Attack
Home » Security Alerts  »  Security Alert: Check Point VPN Zero-Day Under Active Ransomware Attack

Security Alert: Check Point VPN Zero-Day Under Active Ransomware Attack

Check Point has released an emergency patch for a critical vulnerability in its VPN products that is being actively exploited by ransomware gangs. If your business uses a Check Point firewall with Remote Access VPN, this requires immediate action.

  • What it is: A flaw (CVE-2026-50751, CVSS 9.3) in Check Point's Remote Access VPN that allows attackers to bypass the login process entirely and connect to your network without valid credentials. A proof-of-concept exploit was published on 12 June 2026, significantly increasing the risk of widespread attacks.
  • Who is affected: Businesses running Check Point Security Gateway, Mobile Access, or Spark Firewall with Remote Access VPN enabled, particularly those using the older IKEv1 protocol.
  • What the risk is: Unauthorised access to your internal network. Active exploitation has been linked to Qilin ransomware attacks, with incidents traced back to early May 2026. CISA added this vulnerability to its Known Exploited Vulnerabilities catalogue and ordered US agencies to patch by 11 June.
  • What to do: Apply Check Point's hotfix immediately. Do not wait for your next scheduled maintenance window. Contact your IT provider today to confirm whether your firewall is affected and whether the patch has been applied.

If you are an OzComm client using a Check Point product, contact us today to confirm your patch status. Sources: Check Point Advisory, Rapid7, BleepingComputer.