CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
CISA ordered U.S. agencies to patch a Check Point VPN flaw within three days after attackers used it in zero-day ransomware intrusions.
Intelligence analysis by GPT-5.4 Mini

CISA added a Check Point Remote Access VPN and Mobile Access flaw to its exploited-vulnerabilities list after Check Point said attacks began on May 7 and were linked to Qilin ransomware affiliates. The bug affects systems using legacy IKEv1 settings and can let unauthenticated attackers bypass login.
A security gate at the front door of some company networks had a bad lock that could be tricked open. CISA told U.S. agencies to fix it fast because thieves were already using it, like burglars finding a spare key before the owners noticed.
Analysis
What happened
CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog and told Federal Civilian Executive Branch agencies to patch by June 11 under Binding Operational Directive 22-01. The flaw affects Check Point Remote Access VPN, Mobile Access VPN, and some Spark firewalls when they are configured with deprecated IKEv1 settings, do not require a machine certificate, and still accept legacy remote access clients.
Why it is urgent
Check Point said it released fixes on Monday and that exploitation started on May 7, then picked up over the weekend. The company said the activity has been limited to a few dozen organizations globally, but it also linked at least one incident to a Qilin ransomware affiliate. The bug is serious because it can let unauthenticated remote attackers bypass authentication and create a VPN connection on exposed systems.
Mitigations and scope
For organizations that cannot patch immediately, Check Point advised removing support for the legacy remote access client, switching Remote Access VPN Authentication to IKEv2 only, enabling IPS signatures, and making machine certificate authentication mandatory. CISA echoed the concern for federal systems but also urged private-sector defenders to patch or mitigate as soon as possible.
Bigger pattern
The article notes this is not the first Check Point issue to attract ransomware interest. Two years ago, CISA flagged CVE-2024-24919 in Quantum Security Gateways as actively exploited in ransomware campaigns, reinforcing that edge devices remain a high-value target when they expose outdated access paths.
Key points
- CISA ordered federal civilian agencies to patch CVE-2026-50751 by June 11.
- The flaw can let unauthenticated attackers bypass Check Point VPN authentication on certain legacy configurations.
- Check Point said attacks began on May 7 and were tied to a Qilin ransomware affiliate in at least one case.
- The issue affects deployments using deprecated IKEv1 settings with no machine certificate requirement and legacy clients.
- Check Point recommended immediate patching or mitigation steps such as IKEv2-only authentication and IPS signatures.
If agencies patch quickly and remove legacy IKEv1 access, the attack path closes before wider exploitation spreads. The vendor’s mitigation steps also give defenders a way to reduce exposure even if patching takes time.
Organizations that keep legacy VPN settings in place may remain open to authentication-bypass attacks and follow-on ransomware activity. The fact that exploitation already reached multiple targets suggests other unpatched systems could still be at risk.



