CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
- On Monday, CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities Catalog, ordering Federal Civilian Executive Branch agencies to secure their Check Point Remote Access VPN deployments by June 11.
- Unauthenticated remote attackers can exploit this flaw to bypass authentication on Check Point Quantum Security Gateways configured with the deprecated IKEv1 key exchange protocol lacking Machine Certificate Authentication.
- Israeli cybersecurity company Check Point released updates Monday after confirming attacks surged since May 7, linking one incident to the Qilin Ransomware-as-a-Service operation.
- CISA noted this vulnerability poses "significant risks to the federal enterprise," while Check Point advises configuring Remote Access VPN Authentication to IKEv2 only to mitigate threats.
- Two years ago, CISA tagged CVE-2024-24919 as actively exploited in Check Point gateways; security teams currently log 54% of successful attacks and alert on just 14%.
16 Articles
16 Articles
CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
CISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day attacks by Qilin ransomware affiliates.
Critical RCE Flaw CVE-2025-24987 Actively Exploited in Check Point VPNs
Security researchers have identified active exploitation of a critical vulnerability in Check Point's VPN appliances that allows unauthenticated attackers to execute arbitrary code on targeted systems. According to reporting from The Hacker News, the flaw tracked as CVE-2025-24987 carries a severity rating of 9.8 out of 10 and affects multiple versions of Check Point's Quantum Security Gateway and CloudGuard Network Security products. The vulner…
Critical VPN vulnerability actively exploited to bypass authentication without passwords
CVE-2026-50751 lets attackers bypass VPN authentication without passwords via IKEv1 flaw; CISA added it to KEV, hotfixes released 8 June. Check Point Software has issued an urgent warning about active exploitation of a critical vulnerability in its VPN and mobile access products. The flaw, identified as CVE-2026-50751 with a CVSS score of 9.3, enables unauthenticated attackers to bypass user authentication entirely and establish VPN connections …
Why did CISA give federal agencies 3 days?
CISA response to an actively exploited VPN bug CISA directed US federal agencies to fix a VPN vulnerability within three days after a ransomware gang began exploiting it. The issue affected security tools used across the federal government, meaning the operational blast radius could be broad if…
LiteLLM Vulnerability CVE-2026-42271: 7 Things to Know
CISA added CVE-2026-42271, a command injection flaw in LiteLLM, to its Known Exploited Vulnerabilities catalog this morning. Researchers at Horizon3.ai have confirmed a chained exploit path that achieves unauthenticated remote code execution with no credentials required. Here is what you need to know. 1. What LiteLLM is and why it’s a target LiteLLM is an […] The post Top 7 Things to Know About the LiteLLM CVE-2026-42271 Exploit appeared first o…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




