Monday, August 3, 2026

Policy & Regulation

US agencies given three days to fix active ransomware exploit

CISA has ordered all civilian federal agencies to patch a critical Check Point vulnerability within three days after it was exploited by the Qilin ransomware group.

US agencies given three days to fix active ransomware exploit

The Cybersecurity and Infrastructure Security Agency (CISA), which is a US federal agency, has issued an emergency directive ordering all civilian federal agencies to remediate a critical security vulnerability by end of day June 11. CISA issued the order on Monday, giving federal administrators exactly three days to patch the affected systems by the June 11 deadline. The urgent federal intervention follows reports from cybersecurity firm Check Point Software that the bug is actively exploiting an unpatched flaw and is under attack by a ransomware gang. Specifically, Check Point Software reported that the vulnerability is being exploited by Qilin, a known ransomware group, to hack into targeted organizations. CISA’s order requires these agencies to take immediate action to secure their networks.

According to Check Point Software, the security bug affects several of its remote access tools, firewalls, and virtual private networks (VPNs). These tools serve as digital gatekeepers that protect networks from unauthorized access. The cybersecurity firm reported that the hacks began on May 7, with malicious activity beginning to rise last week. In a separate blog post, Check Point Software confirmed that the security flaw has been used to hack into “a few dozen targeted organizations globally” that rely on the affected security tools. The company confirmed that the bug was being actively exploited by the ransomware group to target organizations relying on these specific security tools.

Given the immediate risk to the U.S. federal government’s enterprise network, CISA is mandating that civilian agencies identify and fix any instances where they are using the affected products. To enforce this action, CISA cited BOD 22-01, its operational guidance memo that allows the agency to instruct federal offices to take security action when there is an active cyber threat to government networks. The directive applies to all civilian federal agencies, including major departments such as Homeland Security, the Department of State, and the Treasury. Under the order, these departments must locate and secure any vulnerable systems running the affected Check Point Software products to protect the federal government’s enterprise network from the active threat before the June 11 deadline.

Why it matters

This directive highlights the critical role of supply chain security in government infrastructure, as a single vulnerability in widely used commercial security tools can expose federal networks to active ransomware threats.