<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day-v4jbko8vp" -->

---
title: CISA gives feds 3 days to patch Check Point VPN bug...
description: CISA has ordered U.S. federal agencies to patch CVE-2026-50751, a critical authentication bypass vulnerability in Check Point Remote Access VPN and Mobile...
canonical: https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day-v4jbko8vp
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day | daily.dev
og:description: CISA has ordered U.S. federal agencies to patch CVE-2026-50751, a critical authentication bypass vulnerability in Check Point Remote Access VPN and Mobile...
og:url: https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day-v4jbko8vp
og:image: https://api.daily.dev/og/posts/v4jbKO8vp.png
og:image:alt: CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

CISA has ordered U.S. federal agencies to patch CVE-2026-50751, a critical authentication bypass vulnerability in Check Point Remote Access VPN and Mobile Access products, by June 11. The flaw allows unauthenticated remote attackers to establish VPN connections and affects instances using the deprecated IKEv1 protocol without mandatory machine certificate authentication. Check Point released patches after detecting active exploitation beginning May 7, with at least one confirmed incident linked to the Qilin ransomware gang. Mitigation options for those unable to patch include disabling legacy remote access clients, switching to IKEv2-only authentication, enabling IPS signatures, and enforcing machine certificate authentication.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs>

## Similar posts on daily.dev

- [CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang](https://daily.dev/posts/cisa-gives-us-federal-agencies-three-days-to-fix-a-vpn-bug-under-attack-by-a-ransomware-gang-qaktop01p) · TechCrunch · 0 upvotes · 0 comments
- [Check Point links VPN zero-day attacks to Qilin ransomware gang](https://daily.dev/posts/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang-lxnnqkhtj) · BleepingComputer · 0 upvotes · 0 comments
- [Critical Check Point VPN Zero-Day Exploited in the Wild \(CVE-2026-50751\)](https://daily.dev/posts/critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751--8lk5ari1g) · Rapid7 Cybersecurity Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ransomware](https://daily.dev/tags/ransomware), [#vpn](https://daily.dev/tags/vpn), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day-v4jbko8vp)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day","url":"https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day-v4jbko8vp","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day-v4jbko8vp"},"datePublished":"2026-06-09T08:22:20.940Z","dateModified":"2026-06-09T08:22:49.858Z","description":"CISA has ordered U.S. federal agencies to patch CVE-2026-50751, a critical authentication bypass vulnerability in Check Point Remote Access VPN and Mobile...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3536228e363c291a8b5671c819f6c669?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3536228e363c291a8b5671c819f6c669?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day-v4jbko8vp","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ransomware,vpn,zero-day","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day"}]}
```

