CISA has mandated that U.S. government agencies address a critical vulnerability in Check Point Remote Access VPN and Mobile Access systems, due to its exploitation in zero-day attacks by Qilin ransomware affiliates. The vulnerability, identified as CVE-2026-50751, allows unauthenticated remote attackers to bypass authentication and create VPN connections on affected systems. It specifically impacts configurations using the outdated IKEv1 key exchange protocol, requiring immediate security measures to be implemented.
U.S. Agencies Ordered to Patch CVE-2026-50751 in Check Point VPN
CyberSIXT Evidence Panel
Primary Source
support.checkpoint.com
CVE Intel
CISA KEV
Listed in KEV
Patch
Patch Available
Threat Actor
Qilin
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CVE-2026-50751 Hits Check Point VPN as OpenAI Considers Price Cut
securityonline.info
-
Check Point VPN under attack as Splunk issues urgent patches
securityonline.info
-
Check Point VPN exploited, GreatXML bypasses BitLocker protection
securityonline.info
-
Important GitLab Security Updates Address 12 Vulnerabilities
securityonline.info
-
Check Point VPN and NVIDIA DALI flaws let attackers execute code
securityonline.info
-
Check Point VPN flaw fuels VerdantBamboo espionage campaign
securityonline.info
-
AI Browser Extensions Abuse CVE-2026-50751 to Harvest Chat Data
securityonline.info
-
Ivanti patches CVE-2026-10520 gateway flaw after urgent alert
securityonline.info
-
U.S. Agencies Ordered to Patch CVE-2026-50751 in Check Point VPN
databreaches.net