The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMENEWSFEEDEVENTS
—STORIES—VERIFIED
BOOKMARKS
RSSSOURCESABOUTCORRECTIONS
RSS
© 2026 The Circuitry
About UsContactCorrections
  • Home
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

CISA's directive on patching Check Point VPN CVE-2026-50751 by June 11 is corroborated by the agency's KEV catalog and reports from Check Point, Rapid7, The Hacker News, and Help Net Security.

Sourcing
1source

via BleepingComputer

BleepingComputer · track record
28Stories
100%Verified
2330d
All sources →
Home/Tech
VERIFIEDBy Xavier Rivera· ·2.5 min read

CISA Orders Feds to Patch Check Point VPN Zero-Day by June 11

CISA has ordered federal agencies to patch CVE-2026-50751 in Check Point VPN products by June 11 after it was exploited as a zero-day by Qilin ransomware affiliates. The critical authentication bypass flaw affects only IKEv1 configurations and has breached a few dozen organizations worldwide so far.

Source:BleepingComputer
Post
CISA Orders Feds to Patch Check Point VPN Zero-Day by June 11
TL;DRAI · 60 sec read

CISA orders federal agencies to patch Check Point VPN flaw CVE-2026-50751 by June 11. The zero-day enables unauthenticated remote access on IKEv1 setups and has been exploited since May 7 in attacks tied to Qilin ransomware. Check Point released fixes and workarounds, while urging private sector action to limit breach risks.

CISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day attacks by Qilin ransomware affiliates.

CISA adds CVE-2026-50751 to its Known Exploited Vulnerabilities catalog. The agency directed Federal Civilian Executive Branch agencies to apply fixes by June 11 under Binding Operational Directive 22-01. This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

CISA also urged all security teams in the private sector to deploy patches for CVE-2026-50751 and secure their organizations' networks as soon as possible. The directive applies only to federal agencies but the warning extends broadly.
Although these attacks have only led to breaches at a few dozen organizations worldwide, Check Point has linked at least one incident to the Qilin Ransomware-as-a-Service operation.

Check Point discloses the flaw as actively exploited since May 7. The Israeli cybersecurity company released security updates on Monday for CVE-2026-50751. It flagged the vulnerability as exploited in attacks that began on May 7 and surged over the weekend.

Unauthenticated remote attackers can exploit the flaw to bypass authentication and establish a remote access VPN connection on targeted Mobile Access/SSL VPNs, Remote Access VPNs, or Spark firewalls. The vulnerability affects only instances configured to use the deprecated IKEv1 key exchange protocol, with security gateways that do not require a machine certificate for connections and accept legacy Remote Access clients.

Exploitation linked to Qilin ransomware with limited global impact so far. Although these attacks have only led to breaches at a few dozen organizations worldwide, Check Point has linked at least one incident to the Qilin Ransomware-as-a-Service operation. Qilin has claimed over 400 victims on its dark web leak site since it surfaced in August 2022.
Two years ago, CISA tagged another vulnerability in Check Point's Quantum Security Gateways as actively exploited by ransomware gangs.

"To date, the observed exploitation has been limited to a few dozen targeted organizations globally. One case involved confirmed post-compromise activity associated with Qilin ransomware affiliate," the company said. Customers using IKEv1 key exchange protocol are strongly encouraged to apply the available security updates immediately.

Workarounds provided for systems that cannot be patched immediately. Check Point shared mitigation measures including removing support for the legacy remote access client, configuring global properties for Remote Access VPN Authentication to IKEv2 only, enabling IPS and downloading the signatures, and configuring Machine Certificate Authentication as mandatory. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Check Point VPN flaws previously targeted by ransomware groups. Two years ago, CISA tagged another vulnerability in Check Point's Quantum Security Gateways as actively exploited by ransomware gangs. That earlier flaw was linked to NailaoLocker ransomware attacks.

EXPERT TAKE

Federal agencies face a tight three-day window to remediate an actively exploited VPN flaw, underscoring how quickly CISA moves on KEV catalog additions when ransomware post-exploitation is confirmed.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →

Reader-supported · Daily Brief

Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.

HELP US IMPROVE

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
CISACheck PointZero-DayRansomware
More fromBleepingComputer
  • Google patches fifth Chrome zero-day exploited in 2026

    Tech · 20h
  • French Government Tchap Messaging Service Breached

    Tech · 20h
  • WhatsApp disrupts new NSO spyware phishing campaigns

    Tech · 1d
More inTech
  • Apple expands App Store bundles to include third-party subscriptions

    Tech · 11h
  • EU Orders Meta to Restore Rival AI Access to WhatsApp

    Tech · 12h
  • Anthropic releases public Mythos-class Claude Fable 5

    Tech · 15h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Daily brief at 7 AM ET. Top tech stories, every morning.

MORE IN TECH

Apple expands App Store bundles to include third-party subscriptions

Apple is expanding App Store bundles to include subscriptions from different companies and introducing Suites that combine subscriptions unavailable on their own. The changes, announced at WWDC alongside iOS 27, will roll out later this year with more details expected this summer.

EU Orders Meta to Restore Rival AI Access to WhatsApp

The European Commission ordered Meta to restore rival AI chatbots' access to the WhatsApp Business API under pre-ban terms within five days. The move escalates an antitrust investigation into whether Meta abused its dominance by reserving AI features for itself, with potential fines up to 10% of global revenue.

Anthropic releases public Mythos-class Claude Fable 5

Anthropic has released Claude Fable 5 as its first publicly available Mythos-class model, which it describes as exceeding any prior generally available model on nearly all benchmarks. The release includes conservative safeguards that redirect some queries to Claude Opus 4.8, while a less-restricted Mythos 5 version stays limited to select cyberdefenders.