CISA Gives Feds Three Days to Patch Check Point VPN Bug—Qilin Ransomware Already Exploiting It
CISA ordered federal agencies to patch a critical Check Point VPN zero-day exploited by Qilin ransomware within 72 hours. The flaw affects IKEv1-configured gateways and gave attackers a month-long head start.
In Brief
- CISA ordered federal agencies to patch CVE-2026-50751 by June 11 under Binding Operational Directive 22-01.
- The vulnerability was exploited as a zero-day for over a month before Check Point released a fix.
- Only systems using the deprecated IKEv1 protocol with legacy client support are vulnerable.
The U.S. Cybersecurity and Infrastructure Security Agency gave federal civilian agencies 72 hours to secure Check Point Remote Access VPN and Mobile Access deployments against a critical authentication bypass flaw. The vulnerability, tracked as CVE-2026-50751, has been actively exploited since at least May 7 by affiliates of the Qilin ransomware operation.
Check Point disclosed the flaw on June 8, acknowledging that attackers had a month-long head start. The company linked at least one confirmed breach to Qilin, a ransomware-as-a-service group that has claimed over 400 victims on its leak site since August 2022. Exploitation remains limited to “a few dozen” organizations globally, per Check Point research.
How the Check Point VPN Vulnerability Works
The flaw resides in the IKEv1 key exchange protocol—deprecated but still supported for legacy Remote Access clients. When a security gateway accepts IKEv1 connections without requiring a machine certificate, unauthenticated remote attackers can bypass authentication entirely and establish a rogue VPN session. The vulnerability affects Remote Access VPN, Mobile Access/SSL VPN, and Spark firewalls configured with this legacy setup.
Check Point released hotfixes on June 8, and CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities Catalog the same day. CISA’s emergency directive, issued under Binding Operational Directive 22-01, mandates that Federal Civilian Executive Branch agencies apply mitigations or discontinue use by June 11. The agency urged private-sector organizations to patch with equal urgency.
While investigating the primary flaw, Check Point researchers discovered a second vulnerability, CVE-2026-50752, affecting certificate validation in the same deprecated IKEv1 implementation. That bug could enable man-in-the-middle attacks on site-to-site VPN connections, though no in-the-wild exploitation has been observed. Check Point advised customers to apply updates for both CVEs.
Mitigation options for organizations unable to patch immediately include disabling legacy Remote Access client support, enforcing IKEv2-only authentication, requiring machine certificate authentication, and enabling IPS signatures to detect exploitation attempts.
FAQ
What is CVE-2026-50751?
CVE-2026-50751 is a critical authentication bypass vulnerability in Check Point Remote Access VPN, Mobile Access, and Spark firewall products. It allows unauthenticated remote attackers to establish VPN connections without valid credentials when the deprecated IKEv1 protocol is enabled with legacy client support.
Who is exploiting this vulnerability?
Check Point attributed active exploitation to affiliates of the Qilin ransomware-as-a-service operation. The group has claimed over 400 victims since its emergence in August 2022. Exploitation began on May 7 and surged in early June 2026.
Which Check Point products are affected?
The vulnerability affects Remote Access VPN, Mobile Access/SSL VPN, and Spark firewalls configured to use the IKEv1 key exchange protocol without mandatory machine certificate authentication. Modern IKEv2-only deployments are not vulnerable.
What is the patch deadline for federal agencies?
CISA’s emergency directive under Binding Operational Directive 22-01 requires Federal Civilian Executive Branch agencies to secure affected devices by June 11, 2026.
Are there workarounds if immediate patching is not possible?
Yes. Check Point recommends disabling legacy Remote Access client support, configuring VPN authentication to IKEv2 only, enforcing machine certificate authentication, and deploying IPS signatures to detect exploitation attempts. [Editor’s note: This article was updated on 2026-06-09 to correct the attribution of the Known Exploited Vulnerabilities Catalog. The catalog is maintained by CISA, not Check Point. Original text stated Check Point added the CVE to its catalog; corrected to reflect CISA’s addition.]