ClosedLow impactAI Refreshed

Check Point VPN Zero-Day Exploited by Qilin Ransomware Gang

Occurred 8 May 2026·Detected 8 Jun 2026·
Global — Check Point VPN products are deployed worldwide; the vendor is headquartered in Israel2 reportsEnded 29 Jun 2026
CyberPropertyCyberCasualty & Liability

Check Point has released security updates to patch a critical zero-day vulnerability in its Remote Access VPN and Mobile Access products (IKEv1) that a Qilin ransomware affiliate is reported to have exploited in the wild for approximately one month prior to remediation. The event is a developing cyber-threat story with potential relevance to cyber-underwriting portfolios but no confirmed insured losses, named victims, or claim filings have been publicly disclosed.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Low impact. LOW: Vendor patch confirmed and exploitation attributed to a known ransomware brand support a developing cyber-threat narrative, but materiality is capped by the absence of any named insured loss, claim filings, or victim disclosure. The event is a threat-landscape story with cyber-portfolio underwriting relevance, not a confirmed loss.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts