Skip to main content

CVE detail

CVE-2024-24919

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

CVSS 8.6 · HighBuzz score 72.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 72.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
21 evidence mentions in the snapshot
Diversity score
17.5
7 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
2
within the 30d window
Peak daily
2
highest bucket

Evidence

Source links by recency

Newest mentions first
21 source links · newest first
  • nerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process classified as improper authentication ( CWE-287 ). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated

    vendorwww.rapid7.comJul 23, 2026, 11:57 AM
  • n actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. Tracked as CVE-2026-16232 , this authentication bypass vulnerability allows unauthenticated attackers to obtain an application login token that can be used to authenticate with administrator privileges. After gaining access to a vulnerable Secur

    newswww.bleepingcomputer.comJul 23, 2026, 8:13 AM
  • Enterprises have long relied on firewalls, routers, VPN servers, and email gateways to protect their networks from attacks. Increasingly, however, these network edge devices are becoming security liabilities themselves. Every few weeks, another crisis plays out: Security teams scramble to patch and scan their network appliances for malware implants after another zero-day attack is newly […]

    newswww.csoonline.comOct 20, 2025, 7:00 AM
  • A Chinese state-sponsored hacker group called RedNovember has conducted a global espionage campaign targeting critical infrastructure between June 2024 and July 2025, compromising defense contractors, government agencies, and major corporations while exploiting vulnerabilities faster than organizations could deploy security patches. The attacks included breaches of at least two US defense contractors and more than 30 […]

    newswww.csoonline.comSep 29, 2025, 12:28 PM
  • The FBI is warning that cybercriminals are exploiting end-of-life (EOL) routers that are no longer being patched by manufacturers. Specifically, the “5Socks” and “Anyproxy” criminal networks are using publicly available exploits and injecting persistent malware to gain entry to obsolete routers from Linksys and Cisco. Once compromised, the devices are added to residential proxy botnets […]

    newswww.csoonline.comMay 9, 2025, 11:06 PM
  • Two of the top three vulnerabilities that threat actors tried to leverage in 2024 were in end of life (EOL) network devices that manufacturers have stopped issuing patches for, says a new report. “This underscores the importance of decommissioning and replacing EOL components of an organization’s network as soon as possible,” says the 2024 annual […]

    newswww.csoonline.comApr 1, 2025, 1:39 AM
  • 24th February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 24h February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Check Point Research covers the recent ByBit hack, one of the largest thefts in digital asset history, its implications for crypto security, and security recommendations. In this event, hackers gained access to […]

    vendorresearch.checkpoint.comFeb 24, 2025, 4:58 PM
  • NailaoLocker ransomware is a new threat that targeted European healthcare organizations from June to October 2024. Orange Cyberdefense CERT uncovered a malware campaign, tracked as The Green Nailao campaign, that targeted European organizations, including healthcare, in late 2024, using ShadowPad, PlugX, and the previously undocumented NailaoLocker ransomware. The Orange Cyberdefense CERT investigated four attackers with […]

    newssecurityaffairs.comFeb 20, 2025, 3:47 PM
  • In 2024, hackers had a field day finding sneaky ways into systems — from convincing phishing scams that played on human curiosity to brutal software flaws that exposed gaps in tech upkeep. It was a year of clever breaches, showing just how wide the gap is between user habits and security practices. “While every year […]

    newswww.csoonline.comDec 31, 2024, 6:00 AM
  • Zero-day vulnerabilities saw big growth once again in 2024. With no patch available, zero-day flaws give attackers a significant jump on cybersecurity defense teams, making them a critical weapon for attacking enterprise systems. But while all zero-days are essential for CISOs and their team to be aware of, and for vendors to remedy in a […]

    newswww.csoonline.comDec 23, 2024, 9:00 AM
  • Warnings went out this week to infosec leaders about two groups of Iranian threat actors attacking American and other organizations. The US Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the Defense Department’s Cyber Crime Centre said a group of Iranian hackers are working with ransomware gangs on attacks. “The Iranian cyber actors’ involvement […]

    newswww.csoonline.comAug 29, 2024, 6:31 PM
  • GreyNoise has observed a rapid increase in the number of exploitation attempts targeting a recent Check Point VPN zero-day.

    newswww.securityweek.comJun 6, 2024, 12:30 PM
  • PoC code targeting a recent Check Point VPN zero-day has been released as Censys identifies 14,000 internet-accessible appliances.

    newswww.securityweek.comJun 3, 2024, 12:17 PM
  • 3rd June – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 3rd June, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES ShinyHunters, a notorious cybercrime gang offered for sale on a cybercrime forum data of Ticketmaster, ticket sales and distribution company, and of Santander bank. The alleged breaches have resulted in the potential exposure […]

    vendorresearch.checkpoint.comJun 3, 2024, 12:13 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Ticketmaster confirms data breach impacting 560 million customers Critical Apache Log4j2 flaw still threatens global finance […]

    newssecurityaffairs.comJun 2, 2024, 11:33 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: RansomLord: Open-source anti-ransomware exploit tool RansomLord is an open-source tool that automates the creation of PE files, which are used to exploit ransomware pre-encryption. Attackers are probing Check Point Remote Access VPN devices Attackers are trying to gain access to Check Point VPN devices via local accounts protected only by passwords, the company has warned on Monday. Snowflake denies breach, … More →

    newswww.helpnetsecurity.comJun 2, 2024, 8:00 AM
  • Attackers have been exploiting CVE-2024-24919, a zero-day vulnerability in Check Point Security Gateways, to pinpoint and extract password hashes for local accounts, which they then used to move laterally in the target organizations’ network. “The vulnerability is particularly critical because it does not require any user interaction or privileges, making it easy to exploit remotely,” IT security service provider Mnemonic noted, and shared that they have observed several attacks that included CVE-2024-24919 exploitation. About CVE-2024-24919 … More →

    newswww.helpnetsecurity.comMay 31, 2024, 11:27 AM
  • CISA adds Check Point Quantum Security Gateways and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The vulnerability CVE-2024-24919 is a Quantum Gateway information disclosure issue. Threat actors exploited the flaw to gain remote firewall access […]

    newssecurityaffairs.comMay 30, 2024, 8:08 PM
  • The recently disclosed Check Point VPN attacks involve the zero-day vulnerability CVE-2024-24919, which allows hackers to obtain passwords.

    newswww.securityweek.comMay 30, 2024, 8:48 AM
  • Check Point released hotfixes for a VPN zero-day vulnerability, tracked as CVE-2024-24919, which is actively exploited in attacks in the wild. Check Point released hotfixes to address a VPN zero-day vulnerability, tracked as CVE-2024-24919, which is actively being exploited in attacks in the wild. The vulnerability CVE-2024-24919 is a Quantum Gateway information disclosure issue. Threat actors […]

    newssecurityaffairs.comMay 29, 2024, 6:27 PM
  • Cybersecurity provider Check Point has advised its VPN customers to patch the Security Gateways service immediately to prevent threat actors from gaining initial access to enterprise networks through vulnerable VPN configurations. The company has released an advisory to help fix the vulnerability. “Check Point’s dedicated task force continues investigating attempts to gain unauthorized access to VPN […]

    newswww.csoonline.comMay 29, 2024, 11:02 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence