CISA has mandated that U.S. government agencies address a critical vulnerability in Check Point Remote Access VPN and Mobile Access systems, due to its exploitation in zero-day attacks by Qilin ransomware affiliates. The vulnerability, identified as CVE-2026-50751, allows unauthenticated remote attackers to bypass authentication and create VPN connections on affected systems. It specifically impacts configurations using the outdated IKEv1 key exchange protocol, requiring immediate security measures to be implemented.
U.S. Agencies Ordered to Patch CVE-2026-50751 in Check Point VPN
CyberSIXT Evidence Panel
Primary Source
support.checkpoint.com
CVE Intel
CISA KEV
Listed in KEV
Patch
Patch Available
Threat Actor
Qilin
Article by CyberSIXT