CVE-2024-24919Active Exploitation(checkpoint / cloudguard_network_security)

MEDIUMCVSS 8.6 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch checkpoint cloudguard_network_security systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

4.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-06-20. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloudguard_network_security
  • quantum_security_gateway
  • quantum_security_gateway_firmware
  • quantum_spark

Threat summary

  • Active exploitation appears in 8 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 8 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-07-23); latest day: 1
  • 11 total mentions across 10 days

Affected systems

Vendors
Products
cloudguard_network_securityquantum_security_gatewayquantum_security_gateway_firmwarequantum_sparkquantum_spark_firmware

6 versions affected across 5 products

Deep dive

Activity timeline11 mentions / 10d
01122Mentions · 2026-02-24: 1Mentions · 2026-03-26: 1Mentions · 2026-05-01: 1Mentions · 2026-05-11: 1Mentions · 2026-06-08: 1Mentions · 2026-06-09: 1Mentions · 2026-07-23: 2Mentions · 2026-08-04: 1Mentions · 2026-09-24: 1Mentions · 2026-10-02: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-07-23: 2Active Exploitation · 2026-08-04: 1Active Exploitation · 2026-09-24: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-07-23: 1Technical Details · 2026-03-26: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-09: 1Technical Details · 2026-07-23: 2Technical Details · 2026-08-04: 1Technical Details · 2026-09-24: 102-2403-2605-0105-1106-0806-0907-2308-0409-2410-02
Signal classification3 categories
Active Exploitation
880.0%
General
110.0%
Disclosure
110.0%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-241
General1
2026-03-261
Disclosure1
2026-05-011
Active Exploitation1
2026-05-111
Active Exploitation1
2026-06-081
Active Exploitation1
2026-06-091
Active Exploitation1
2026-07-232
Active Exploitation2
2026-08-041
Active Exploitation1
2026-09-241
Active Exploitation1
Full discourse11 posts
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #LowCompleteness CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild | 23-07-2026 Source: https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication-bypass-exploited-in-the-wild Key details below ↓ 🎯Victims: Network security, Firewall management, Cybersecurity 🔓CVEs: CVE-2026-62144 \[[Vulners](https://vulners.com/cve/CVE-2026-62144)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: Unknown CVE-2024-24919 \[[Vulners](https://vulners.com/cve/CVE-2024-24919)] - CVSS V3.1: *8.6*, - Vulners: Exploitation: True Soft: - checkpoint quantum_spark_firmware (r80.40) CVE-2026-50751 \[[Vulners](https://vulners.com/cve/CVE-2026-50751)] - CVSS V3.1: *9.3*, - Vulners: Exploitation: True Soft: - checkpoint gaia_os (<r81.20, r82, r82.10) CVE-2026-62145 \[[Vulners](https://vulners.com/cve/CVE-2026-62145)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: Unknown CVE-2026-16232 \[[Vulners](https://vulners.com/cve/CVE-2026-16232)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True 📚TTPs: ⚔️Tactics: 1 🛠️Technics: 0 🤖LLM extracted TTPs:` T1098, T1190, T1210, T1550.001, T1562 🧨IOCs: - IP: 6 #threatreport: CVE-2026-16232, a critical vulnerability identified in Check Point's SmartConsole, has been classified as an authentication bypass and has been assigned a CVSS score of 9.1. This vulnerability, associated with improper authentication (CWE-287), allows remote attackers—without requiring authentication—to acquire an application login token. Consequently, they can authenticate to the management server with full administrative privileges, providing them the capacity to modify essential security policies and configurations. The vulnerability is particularly severe as it compromises the Security Management Server, which is crucial in the trust hierarchy of security management. An attacker with administrative access can manipulate various configurations, including altering administrator permissions and VPN settings, potentially undermining logging and monitoring mechanisms. Check Point noted that this flaw had been actively exploited in the wild and detected in a limited number of customer environments. Remote exploitation necessitates that the attacker has network access to the Management Server IP address in systems where Trusted Clients are not restricted. CVE-2026-16232 was included on the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities following Check Point's advisory published on July 22, 2026. Organizations were given an urgent three-day window to respond to this vulnerability before a remediation deadline of July 25, 2026. This vulnerability highlights ongoing issues with Check Point's products, which have recently faced multiple in-the-wild vulnerabilities, underscoring the critical need for timely updates and patches in network security environments. To mitigate CVE-2026-16232, Check Point released Jumbo Hotfixes, also addressing vulnerabilities CVE-2026-62144 and CVE-2026-62145, on the same day as their advisory. Affected organizations are advised to implement these patches on an emergency basis without waiting for the normal patch cycle, especially for versions R81.10, R81.20, R82, and R82.10. Additionally, tools such as Exposure Command, InsightVM, and Nexpose are expected to provide authenticated vulnerability checks to help organizations assess their exposure to this critical vulnerability in their networks.

    Post summary

    The post reports that Check Point’s SmartConsole authentication bypass (CVE-2026-16232) is actively exploited in the wild, has received CISA notice, and that vendors have issued hotfixes. The vulnerability allows remote attackers to gain full administrative access.

    10020307
    792 followersView on X
  • Julio Bandeira de Melo@juliobmelo
    Active Exploitation

    CVE-2026-16232 is an authentication bypass in Check Point's SmartConsole management interface, actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog this week. It is the third authentication bypass in Check Point's management products in eighteen months. The second, CVE-2026-50751, was exploited in zero-day attacks by the Qilin ransomware gang in June. The first, CVE-2024-24919, was exploited by ransomware gangs two years ago. The pattern is not the individual vulnerability. It is that management interfaces, which control every security policy an organization has deployed, keep becoming the entry point. The administrative plane is the highest-value target in the estate, and it keeps presenting the same structural weakness. https://www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks/ #CISO

    Post summary

    CVE‑2026‑16232 is an authentication bypass in Check Point’s SmartConsole that is being actively exploited in the wild, as confirmed by its inclusion in CISA’s Known Exploited Vulnerabilities catalog.

    00001404
    48.8K followersView on X
  • GoCocoaAI@GoCocoaAI
    Active Exploitation

    The floor drops out from under Check Point's VPN gateways this morning. CVE-2026-50751 is an authentication bypass on Check Point VPN Remote Access — no credentials required, no user interaction, fully remote — and a Qilin ransomware affiliate is already using it for initial access. Check Point Research confirmed the attribution themselves, which is notable: the vendor naming the attacker in their own threat intel report is not standard practice. The exposure window is open, globally, right now, on every internet-facing Check Point Mobile Access gateway. The pre-auth bypass is the critical escalation from Check Point's prior VPN CVEs. CVE-2024-24919 — CVSS 8.6, KEV-listed, exploited within days of its 2024 disclosure — still required some foothold to leverage. CVE-2026-50751 strips that requirement entirely. The attacker walks in through the front door. No phishing. No credentials to steal. No user to fool. It always does come down to the perimeter when the perimeter has a door with no lock. Qilin's 2026 victim count is past 500 claimed on their leak site, putting them in the top tier of active ransomware groups — second-highest Q1 on record against 2,122 total ransomware victims globally per Check Point Research. Their RaaS model means the affiliate base is broad and the tooling is mature. MoxFive published a full Qilin TTP guide this week. A fresh zero-day in a widely deployed VPN product is exactly the kind of initial access vector a well-resourced affiliate operation goes shopping for. MITRE framing: T1190 (Exploit Public-Facing Application) is the primary initial access vector. T1133 (External Remote Services) for post-exploitation persistence and lateral reach. T1078 (Valid Accounts) for credential harvest and movement once inside. T1486 (Data Encrypted for Impact) and T1657 (Financial Extortion) for the inevitable downstream. The playbook is documented. The tooling is mature. The zero-day is fresh. KEV listing is not yet confirmed as of this morning — CVE-2026-50751 was disclosed today, June 8, and the pipeline lag is expected — but it is effectively certain within 24 to 48 hours given active exploitation by a named ransomware gang with 500+ victims already this year. The 2024 Check Point VPN KEV moved fast. Expect the same cadence. Federal agencies should not wait for the CISA clock to start. The risk calculus here is straightforward. VPN gateways sit at the edge of internal networks, carry broad lateral movement potential post-access, and are frequently over-permissioned. Qilin's 2026 pace suggests they are not being selective about targets. This is not a "patch in the next sprint" situation. It is an "identify every exposed Check Point Mobile Access gateway in the next hour" situation. Patch tonight. Seriously.

    Post summary

    Check Point's CVE‑2026‑50751, a remote authentication bypass, is being actively exploited by the Qilin ransomware affiliate across worldwide VPN gateways, with over 500 reported victims, and urgent patching is required.

    10000125
    20 followersView on X
  • ZeroDay Post@ZeroDayPost
    Active Exploitation

    5/ Urgent alert for IT admins: A critical zero-day flaw (CVE-2024-24919) in Check Point's Security Gateways is being actively exploited, allowing attackers to steal credentials and move deep inside corporate networks.

    Post summary

    The text alerts that CVE‑2024‑24919, a critical zero‑day flaw in Check Point Security Gateways, is actively exploited to steal credentials and infiltrate corporate networks. No proof of concept, exploit tool, patch, or technical detail is provided.

    1000071
    5 followersView on X
  • Heinrich Kordewiner@kordewiner
    General

    @VceOfReason Weiß man selbst bei der @CDU, dass man in 🇩🇪 zwar zu doof für VPN (Zero Day, Check Point) ist, aber trotzdem laut KI-Fernsehen nur "Daten aus einem Kalender des Parteivorsitzenden abgeflossen sind". Nach @realDonaldTrump? 😂 https://nvd.nist.gov/vuln/detail/cve-2024-24919 https://www.zdfheute.de/politik/deutschland/cdu-cyber-angriff-merz-100.html https://t.co/EzIbvBgWf4

    Post summary

    The tweet references CVE‑2024‑24919 but offers no technical, exploit, or mitigation details.

    00010476
    385 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers exploiting CVE-2024-24919 to gain unauthenticated root access on Check Point management servers. The attack bypasses authentication by spoofing server identity, then uses directory traversal to achieve arbitrary file writes and code execution. Compromise of centralized management infrastructure positions attackers to manipulate firewall policies across entire gateway estates. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/check-point-management-cve-2026-93616-weaponizing

    0000045
    2.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2024-24919 in Check Point VPN gateways using crafted certificates to achieve pre-auth RCE. Following compromise, threat actors leveraged VPN infrastructure for lateral movement and data exfiltration through encrypted channels. Runtime segmentation helps contain post-compromise activity when perimeter defenses fail. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/check-point-security-gateway-vpn-rce-cve-2026-85102-exploitation

    Post summary

    The text reports active exploitation of CVE-2024-24919 via crafted certificates achieving pre-auth RCE, with details on post-compromise activity, but does not link a PoC or name a patch.

    0000052
    2.0K followersView on X
  • ScruteX@scrutexai
    Active Exploitation

    This week's takeaway? Attackers are aggressively exploiting: 🔴 CVE-2026-42897 (Microsoft OWA/Exchange) 🔴 CVE-2026-54121 (AD CS) - Privilege escalation for persistent domain access 🔴 CVE-2024-55591 &amp; CVE-2024-21762 🔴 CVE-2024-24919 https://scrutex.ai/blogs/weekly-ransomware-intelligence-report-august-2-2026

    Post summary

    The post reports active exploitation of several CVEs, notably Microsoft OWA/Exchange and AD CS privilege escalation, but does not provide PoC, exploit code, patches, or false-positive information.

    0000061
    85 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #LowCompleteness Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751) | 08-06-2026 Source: https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751 Key details below ↓ 💀Threats: Qilin_ransomware, Mitm_technique, 🎯Victims: Organizations 🔓CVEs: CVE-2026-50752 \[[Vulners](https://vulners.com/cve/CVE-2026-50752)] - CVSS V3.1: *Unknown*, - Vulners: Exploitation: Unknown CVE-2026-50751 \[[Vulners](https://vulners.com/cve/CVE-2026-50751)] - CVSS V3.1: *Unknown*, - Vulners: Exploitation: Unknown CVE-2024-24919 \[[Vulners](https://vulners.com/cve/CVE-2024-24919)] - CVSS V3.1: *Unknown*, - Vulners: Exploitation: Unknown 🤖LLM extracted TTPs:` T1190, T1557 🧨IOCs: - IP: 9 - Hash: 2 🔢Algorithms: md5 #threatreport: On June 8, 2026, Check Point disclosed a critical authentication bypass vulnerability, CVE-2026-50751, impacting its Remote Access VPN, Mobile Access, and Spark Firewall products. This vulnerability, rated with a CVSS score of 9.3, is particularly significant as it relates to the older IKEv1 key exchange protocol. It allows unauthenticated attackers to establish a VPN session without valid credentials due to a flaw in the validation of certificates during the IKEv1 key exchange process. Organizations using configurations that still accept these legacy Remote Access clients are at high risk. Although attackers can initiate a VPN session, they would require further post-authentication actions to access internal resources or escalate privileges. The exploitation of CVE-2026-50751 has already been observed in the wild, with reports of attacks dating back to May 7, 2026, and an uptick in activity noted in early June. This campaign has primarily targeted dozens of organizations, with notable affiliations to cyber criminal entities, including a Qilin ransomware affiliate. Rapid7 has confirmed at least one incident tied to this vulnerability with a high confidence level. In addition to CVE-2026-50751, Check Point identified a related flaw, CVE-2026-50752, which has a CVSS score of 7.4. This vulnerability could allow man-in-the-middle attacks on site-to-site VPN configurations, but no exploitation has been detected for this issue as of now. In light of these vulnerabilities, it is crucial for organizations utilizing Check Point products to promptly apply the hotfixes released for CVE-2026-50751, given the active exploitation. Check Point advises affected entities to eliminate support for legacy remote access clients, configure global properties to require IKEv2 authentication exclusively, mandate machine certificate authentication, and enable Intrusion Prevention System (IPS) features while ensuring that the latest signatures are downloaded. Organizations should not delay applying these updates and should prioritize their implementation to safeguard against emerging threats.

    Post summary

    Check Point's VPN flaw CVE‑2026‑50751 is actively exploited in the wild, allowing unauthenticated attackers to establish VPN sessions. Rapid7 confirmed at least one incident, and vendors have released hotfixes which organizations are urged to apply immediately.

    00000269
    659 followersView on X
  • ZeroDay Post@ZeroDayPost
    Active Exploitation

    4/ URGENT: A critical zero-day flaw (CVE-2024-24919) in Check Point VPNs is being actively exploited. Attackers are stealing credentials from corporate networks. CISA has issued a patch-now directive.

    Post summary

    The post reports that CVE-2024-24919 is being actively exploited in the wild, with attackers stealing credentials, and notes that CISA has issued a patch-now directive.

    0000039
    7 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 𝐅𝐫𝐞𝐬𝐡 𝐂𝐕𝐄 𝐚𝐥𝐞𝐫𝐭 𝐣𝐮𝐬𝐭 𝐢𝐧! Uncover how CVE-2024-24919 enables information disclosure on Check Point gateways and why rapid patching matters for preventing breach risk today. 🔗 Read the full breakdown → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/cve-2024-24919-checkpoint-flaw/ Join the discussion and tell us what you think!

    Post summary

    The post announces a new CVE-2024-24919 that allows information disclosure on Check Point gateways and urges prompt patching to mitigate breach risk.

    0000063
    96 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appcheckpointcloudguard_network_securityr80.40--
Appcheckpointcloudguard_network_securityr81--
Appcheckpointcloudguard_network_securityr81.10--
Appcheckpointcloudguard_network_securityr81.20--
HWcheckpointquantum_security_gateway---
OScheckpointquantum_security_gateway_firmwarer80.40--
OScheckpointquantum_security_gateway_firmwarer81--
OScheckpointquantum_security_gateway_firmwarer81.10--
OScheckpointquantum_security_gateway_firmwarer81.20--
HWcheckpointquantum_spark---
OScheckpointquantum_spark_firmwarer80.20--
OScheckpointquantum_spark_firmwarer80.40--
OScheckpointquantum_spark_firmwarer81--
OScheckpointquantum_spark_firmwarer81.10--

Explore more