Quick Facts
- CISA ordered civilian federal agencies to fix Check Point VPN vulnerability CVE-2026-50751 by June 11, 2026
- Qilin ransomware gang has exploited the flaw since May 7, targeting dozens of organizations globally
- The vulnerability allows attackers to bypass authentication and establish VPN connections without valid credentials
The Cybersecurity and Infrastructure Security Agency gave all civilian federal agencies 72 hours to patch a critical Check Point VPN vulnerability that ransomware attackers have actively exploited since May.
CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities Catalog on June 9, ordering agencies to secure affected systems by June 11. The vulnerability carries a CVSS score of 9.3 and affects Check Point Remote Access VPN, Mobile Access, and Spark firewalls using the deprecated IKEv1 protocol.
The Qilin ransomware gang began exploiting the flaw on May 7, targeting what Check Point described as “several dozen organizations globally.” Check Point discovered the active zero-day exploitation on June 4 and released patches on June 8.
“This allows attackers to establish a Check Point VPN session without valid credentials under certain configurations, effectively giving them a path through the organization’s front door,” said Matthew Hartman, chief strategy officer at the Merlin Group.
Check Point assessed “with medium confidence that the actor behind the exploitation of CVE-2026-50751 is financially motivated, uses Qilin ransomware.” The company confirmed at least one case involved post-compromise activity linked to a Qilin affiliate.
Qilin attacks surged 30% in the first half of 2026, with the group claiming 97 attacks in May alone. The gang has posted over 500 victim organizations in 2026, targeting 53.9% of its victims in North America across manufacturing, construction, professional services, technology, and retail sectors.
While CISA’s binding directive applies only to federal agencies, the agency urged all security teams to deploy patches immediately. Four of the nine affected Check Point product versions have reached end-of-service status and no longer receive support.
During its investigation, Check Point discovered a second vulnerability, CVE-2026-50752, involving certificate validation that could enable man-in-the-middle attacks. The company found no evidence of active exploitation of this second flaw.
The incident highlights the accelerating threat to VPN infrastructure. Two years ago, CISA tagged another Check Point vulnerability as actively exploited by ransomware groups, indicating a recurring pattern of attacks on the company’s network security products.
Read more: CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
