A ransomware gang is actively exploiting a vulnerability in widely deployed Check Point VPN products, and US federal agencies have three days to close the door.
Check Point confirmed that attackers used the flaw to break into dozens of organizations before the campaign came to light. The bug affects several of its VPN products in use across government networks. CISA responded with a binding 72-hour patch deadline — one of its tighter mandates — for agencies still running the vulnerable software.
VPN infrastructure is particularly dangerous to leave exposed. It sits at the network perimeter, handling all remote access traffic, so a foothold there can mean access to everything behind it. Three-day deadlines exist precisely because at this stage, every unpatched hour is another window for intrusion.
CISA's Known Exploited Vulnerabilities catalog and its binding operational directives have steadily shortened the gap between disclosure and patching — but 72 hours is a tight window for production VPN gear that agencies generally can't take offline without cutting off remote workers. Tight, but that's the point.
