High severity8.6CISA KEVNVD Advisory· Published May 28, 2024· Updated Aug 5, 2026
CVE-2024-24919
CVE-2024-24919
Description
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:checkpoint:cloudguard_network_security:r80.40:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:checkpoint:cloudguard_network_security:r80.40:*:*:*:*:*:*:*
- cpe:2.3:a:checkpoint:cloudguard_network_security:r81.10:*:*:*:*:*:*:*
- cpe:2.3:a:checkpoint:cloudguard_network_security:r81.20:*:*:*:*:*:*:*
- cpe:2.3:a:checkpoint:cloudguard_network_security:r81:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*
- cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.10:*:*:*:*:*:*:*
- cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.20:*:*:*:*:*:*:*
- cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:quantum_spark_firmware:r80.20:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:checkpoint:quantum_spark_firmware:r80.20:*:*:*:*:*:*:*
- cpe:2.3:o:checkpoint:quantum_spark_firmware:r80.40:*:*:*:*:*:*:*
- cpe:2.3:o:checkpoint:quantum_spark_firmware:r81.10:*:*:*:*:*:*:*
- cpe:2.3:o:checkpoint:quantum_spark_firmware:r81:*:*:*:*:*:*:*
- checkpoint/Check Point Quantum Gateway, Spark Gateway and CloudGuard Networkv5Range: Check Point Quantum Gateway and CloudGuard Network versions R81.20, R81.10, R81, R80.40 and Check Point Spark versions R81.10, R80.20.
Patches
Vulnerability mechanics
References
3- support.checkpoint.com/results/sk/sk182336nvdMitigationPatchVendor Advisory
- www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
5- CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the WildRapid7 Blog · Jul 23, 2026
- New Check Point Zero-Day Vulnerability Exploited in the WildSecurityWeek · Jul 23, 2026
- Check Point warns of SmartConsole zero-day exploited in attacksBleepingComputer · Jul 23, 2026
- CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-dayBleepingComputer · Jun 9, 2026
- Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)Rapid7 Blog · Jun 8, 2026