ClosedMedium impactAI Refreshed

CISA Orders Federal Patch for Check Point VPN Zero-Day Exploited by Ransomware

Occurred 8 May 2026·Detected 9 Jun 2026·
🇺🇸 United States (federal government and Check Point VPN deployments globally)7 reportsEnded 10 Jun 2026
CyberPropertyCyberCasualty & Liability

CISA has issued an emergency directive requiring U.S. federal agencies to patch a critical Check Point Remote Access VPN and Mobile Access vulnerability within 3 days, with the flaw confirmed to be actively exploited as a zero-day by Qilin ransomware affiliates. The vulnerability poses significant risk to enterprise VPN edge devices, potentially enabling initial access for ransomware deployment across government and private sector organizations. Multiple independent sources corroborate active in-the-wild exploitation.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. MEDIUM: A critical zero-day VPN vulnerability actively exploited by ransomware affiliates (Qilin) represents a plausible pathway to multi-sector cyber insurance claims across Cyber, Property (for cyber-triggered BI), and Casualty books. Check Point VPN is widely deployed among large enterprise insureds, and active zero-day exploitation elevates likelihood of claims. The CISA emergency directive signals severity, though no specific insured losses or named victims are reported, and impact is limited to individual organisational exposure rather than a systemic market event.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

3 active matches

  • TRIA Certified Areas
    Rule-basedConfidence 100%
  • Pacific Ring of Fire
    Rule-basedConfidence 100%
  • Caribbean Hurricane Zone
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

🇺🇸 United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts