news.mlab.sh
Back to the feed
vulnerability

CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day

High
Summary

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive (BOD) 22-01, requiring U.S. federal agencies to patch a critical zero-day vulnerability in Check Point’s Remote Access VPN and Mobile Access products. This vulnerability, CVE-2026-50751, is being exploited by Qilin ransomware affiliates, posing a significant risk to organizations using the deprecated IKEv1 protocol. The directive emphasizes the urgency of patching and implementing mitigation strategies to prevent further attacks.

A critical vulnerability (CVE-2026-50751) within Check Point’s Remote Access VPN and Mobile Access products has been identified and exploited by Qilin ransomware affiliates. The flaw allows unauthenticated remote attackers to bypass authentication and establish VPN connections, particularly impacting systems configured with the IKEv1 key exchange protocol and lacking mandatory machine certificates. Check Point released security updates on Monday, following initial reports of exploitation beginning on May 7th and escalating over the weekend. CISA has ordered federal agencies to patch by June 11th, adding the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting the frequent use of such vulnerabilities as attack vectors.

Read the full article at BleepingComputer