CISA Orders Federal Agencies to Patch Exploited Check Point VPN Flaw Within Three Days
CISA is forcing an emergency patch after Qilin ransomware exploited a Check Point VPN/remote-access flaw in the wild, directing civilian agencies to remediate it by end of day June 11, 2026. Check Point says exploitation began May 7 and impacted a few dozen targeted organizations, per BOD 22-01 covering DHS, State, and Treasury.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered all civilian federal agencies to patch a vulnerability in Check Point Software’s security products by end of day June 11, 2026, after a ransomware group was found actively exploiting the flaw.
Check Point confirmed the bug affects several of its remote access tools, firewalls, and VPNs — products used as digital gatekeepers to protect networks from unauthorized access. The company said a ransomware group known as Qilin has exploited the vulnerability to hack into “a few dozen targeted organizations globally” that rely on the affected tools.
Exploitation activity began on May 7, 2026, but increased significantly in the week prior to CISA’s Monday directive. CISA cited BOD 22-01, its operational guidance memo that authorizes the agency to direct agencies to take security action when an active cyber threat to government networks exists.
The order applies to civilian federal agencies including the Department of Homeland Security, the Department of State, and the Treasury Department. Any agency running the affected Check Point products must remediate the vulnerability by the Wednesday deadline.
The three-day window reflects the urgency of an active ransomware campaign targeting tools embedded in federal infrastructure. The tight remediation timeline suggests the vulnerability poses a significant risk to government enterprise networks if left unpatched.