CISA Orders Federal Agencies To Patch Check Point VPN Bug Within Three Days
Image: Una Al Día

CISA Orders Federal Agencies To Patch Check Point VPN Bug Within Three Days

09 June, 2026.Technology and Science.7 sources

The story in 15 seconds

  • CISA ordered federal civilian agencies to patch the Check Point VPN vulnerability within three days.
  • Unauthenticated remote attackers can bypass authentication and access Check Point VPNs.
  • Ransomware groups actively exploiting the vulnerability across government and private deployments.

The divide · 1 of 3

Whether the vulnerability is framed as a zero-day vs earlier-known context.

Changes perceived attacker lead-time and urgency framing.

Who skipped what

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
7 sources
Other
4
Western Mainstream
2
Western Alternative
1

Other

BleepingComputer
BleepingComputer

CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day

09 June, 2026

Read the original →
Rescana
Rescana

CISA Issues 3-Day Emergency Directive to Patch Check Point VPN Zero-Day (CVE-2024-24919) Amid Active Qilin Ransomware Exploitation

09 June, 2026

Read the original →
SC Media
SC Media

CISA adds Check Point VPN bug to list of exploited vulnerabilities

09 June, 2026

Read the original →
Una Al Día
Una Al Día

Critical alert: Active exploitation of an RCE vulnerability in WatchGuard Firebox firewalls

09 June, 2026

Read the original →

Western Mainstream

Numerama
Numerama

"Urgent and Radical": Microsoft SharePoint has been hacked — governments and more than 50 companies are affected... and it's not over yet.

09 June, 2026

Read the original →
TechCrunch
TechCrunch

CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang

09 June, 2026

Read the original →

Western Alternative

The Tech Buzz
The Tech Buzz

CISA Orders Federal Agencies: Fix Check Point VPN Bug in 3 Days

09 June, 2026

Read the original →

Full story

CISA’s 72-hour VPN fix

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive ordering federal agencies to patch a critical Check Point VPN vulnerability within three days as ransomware attackers exploited it in the wild.

The Tech Buzz said CISA’s Known Exploited Vulnerabilities catalog directive gave agencies until June 12 to either patch the flaw or disconnect affected Check Point systems from their networks entirely.

Image from BleepingComputer
BleepingComputerBleepingComputer

SC Media reported that CISA added the bug to its exploited vulnerabilities list and gave federal agencies until June 11 to patch, while noting Check Point patched the flaw on June 8.

SC Media also quoted Matthew Hartman, chief strategy officer at the Merlin Group, saying, "This is a patch-now — not patch-soon — vulnerability," and tied the issue to CVE-2026-50751.

BleepingComputer added that CISA ordered Federal Civilian Executive Branch agencies to secure their devices by June 11, and described the flaw as enabling unauthenticated remote attackers to bypass authentication and establish a remote access VPN connection.

Qilin-linked exploitation details

Check Point said the exploitation has been limited to a few dozen targeted organizations globally, and TechCrunch reported that the ransomware group Qilin was actively exploiting the unpatched flaw.

TechCrunch said the hacks began on May 7 and that CISA ordered all civilian federal agencies to fix instances where agencies were using the affected products by end of day June 11.

Image from Numerama
NumeramaNumerama

SC Media described CVE-2026-50751 as a CVSS 9.3 flaw and said it allows attackers to establish a Check Point VPN session without valid credentials under certain configurations.

SC Media quoted Hartman explaining the bypass as enabling "a path through the organization’s front door," and it said a Qilin ransomware affiliate has already been linked to post-compromise activity.

Rescana framed the same urgency around a three-day emergency directive and said the vulnerability enables unauthenticated remote attackers to bypass authentication and gain access to internal networks via Check Point Remote Access VPN and Mobile Access gateways.

What agencies must do next

CISA’s directive is tied to Binding Operational Directive (BOD) 22-01, and BleepingComputer said CISA also added CVE-2026-50751 to its Known Exploited Vulnerabilities (KEV) Catalog.

Executive Summary The U

RescanaRescana

BleepingComputer quoted CISA urging action by saying, "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."

SC Media said the vulnerability only affects deployments still running the deprecated IKEv1 key exchange protocol and quoted Denis Calderone, principal and CTO at Suzu Labs, calling it a "patch now" situation.

SC Media also said Calderone recommended teams immediately apply Check Point's Hotfix 1, disable IKEv1, and enforce IKEv2 for remote access VPN connections.

The Tech Buzz added that federal IT teams had 72 hours to identify every affected system, test patches, and deploy them without disrupting critical operations, while noting Check Point released patches and mitigation guidance.

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on Technology and Science