CVE-2024-24919 in Check Point Gateways
CVE-2024-24919 exposed Check Point gateways to credential theft and was used in ransomware and APT campaigns, with regional relevance for Brazil.
CVE-2024-24919 became one of the most sensitive flaws in Check Point remote access gateways because it was not a simple stability issue or an isolated weakness, but an information disclosure vulnerability that could expose secrets on internet-facing perimeter devices. According to the research material, it affects certain Check Point Security Gateways with IPSec VPN, Remote Access VPN, or Mobile Access enabled, and in practice it was used to extract credentials from exposed gateways. That is the core of the risk, when the device that concentrates remote access and network trust leaks credentials or certificates, an attacker does not need much effort to turn partial exposure into operational access inside the organization.
The picture described by the sources is consistent. Senserva rates the flaw at CVSS 8.6 with an EPSS of 100%, Fortinet reports active exploitation and says attacks focused mainly on devices with local accounts protected only by passwords, while Check Point reportedly released a hotfix to fix it. SecurityWeek and Cyber Management Alliance place the vulnerability within a broader sequence of real-world exploitation, including its early addition to CISA's KEV catalog and its use by ransomware gangs to gain unauthorized access to target networks. The technical pattern also matches what MITRE ATT&CK defines as initial access, credential access, and lateral movement, compromise the entry point, extract reusable secrets, and move deeper into the network.
The analytical value of the case is not just historical. Penligent argues that the connection between CVE-2024-24919 and newer Check Point flaws is architectural, not technical, since all of these events hit the management plane and internet-exposed gateways, where policies, routing, authentication, certificates, and logs are concentrated. CyberDesserts describes the same pattern from the perspective of ransomware campaigns against firewalls and VPNs, first the perimeter is compromised, then remote access tools are deployed, and later lateral movement is enabled. In that context, Senserva's recommendation to rotate credentials and certificates after the hotfix is especially relevant, because information disclosure leaves little forensic trace and makes it hard to know which secrets were exposed.
For Brazil, the material does not provide publicly detailed local incidents, but it does offer enough institutional and operational signal to include the risk in a regional assessment. CERT.br is the national last-resort CSIRT, which reinforces the need for a coordinated response path if signs of compromise appear in organizations running Check Point gateways. Brazilian coverage from CaveiraTech also places CVE-2024-24919 within the regional discussion about ransomware exploitation. In an environment where remote access depends on internet-facing perimeter devices, the flaw remains a reference point for understanding the sustained interest ransomware and APT actors have shown in Check Point.
Executive summary
CVE-2024-24919 emerged as a high-value operational flaw in the Check Point ecosystem because it affects internet-exposed security gateways with remote access features enabled, especially IPSec VPN, Remote Access VPN, and Mobile Access. The research material agrees on the central point, this is an information disclosure vulnerability that can leak sensitive data from the gateway, with evidence that it was used in practice to extract credentials from exposed devices. That combination, leaked secrets plus direct perimeter exposure, makes it especially useful for ransomware and APT operators looking for initial access without relying on noisy exploitation or long attack chains.
The technical characterization is also consistent across sources. Senserva rates it CVSS 8.6 and EPSS 100%, and adds a critical nuance that does not always appear in surface-level alerts, the problem does not end with patching. If an attacker managed to extract credentials or certificates before remediation, the organization may remain compromised even after the hotfix is installed. That is why Senserva recommends reinstalling the Check Point hotfix and also resetting all credentials and certificates stored on or used through the affected gateway. The reason is straightforward and troubling, information disclosure attacks leave little forensic evidence, making it difficult to know which secrets were leaked and which were not.
The real-world exploitation picture reinforces the urgency. Fortinet says Check Point reported active exploitation of the flaw, with campaigns focused mainly on configurations that use local accounts protected only by passwords. Fortinet's guidance adds a practical recommendation, avoid local accounts whenever possible and, if they are necessary, add extra layers of authentication instead of relying on passwords alone. On top of that, Fortinet relays Check Point's claim that a hotfix was already available for Security Gateways. SecurityWeek, Cyber Management Alliance, and CaveiraTech place CVE-2024-24919 within a broader sequence of abuse in the wild, including its early inclusion in CISA's KEV catalog and its use by ransomware gangs to gain unauthorized access to target networks.
The strategic reading goes beyond the flaw itself. Penligent argues that the useful link between CVE-2024-24919 and other recent Check Point flaws is architectural, not technical, because all of them expose the management plane and internet-facing remote access gateways. That concentrates policies, routing, authentication, trust relationships, certificates, logs, and a privileged position inside the network. If a single perimeter device is compromised, the potential damage scales quickly. CyberDesserts describes the same pattern in ransomware campaigns against firewalls and VPNs, first the perimeter is exploited, then remote access tools are deployed, and then lateral movement is enabled. In MITRE ATT&CK terms, the sequence maps to Initial Access, Credential Access, and Lateral Movement.
For Brazil, the material does not document detailed local incidents, but it does support a concrete risk reading. CERT.br appears as the national last-resort CSIRT, which provides context for the coordination needed if findings emerge in Brazilian networks. At the same time, CaveiraTech's coverage links the flaw to ransomware exploitation in the regional public discussion. There are no confirmed local victims in the material, but there is enough to treat CVE-2024-24919 as a relevant threat for any Brazilian organization keeping Check Point gateways exposed to the internet with weak local authentication or no additional factors.
Context and background
The first defining trait of CVE-2024-24919 is its architectural position. It does not affect a minor peripheral application or an isolated service, but security gateways that serve as the main entry point for remote users and, in many environments, as trust concentrators as well. Fortinet describes the flaw in certain Check Point Security Gateways connected to the internet with IPSec VPN, Remote Access VPN, or Mobile Access enabled. Senserva places it in Check Point Quantum Security Gateways and classifies it as an information disclosure vulnerability with CVSS 8.6 severity. That mix of perimeter exposure and secret leakage explains why different sources treat it as one of the most sensitive flaws in the Check Point ecosystem.
The practical exploitation is more serious than the generic disclosure label suggests. According to Senserva, in the wild it was used to extract credentials from internet-exposed gateways. If an attacker gets the credentials for the device that manages remote access, the organization loses far more than a perimeter asset. It loses confidence in the entry channel. Senserva puts it plainly, the vulnerability hands over the organization's keys by compromising the main entry point to the network. That is not empty rhetoric, it is a useful way to describe the operational impact of secret leakage from a VPN gateway.
Fortinet adds another important detail, Check Point reportedly indicated active exploitation and the attacks mainly targeted devices with local accounts that rely only on password authentication. That narrows the risk surface even further, because it suggests adversaries do not need exotic techniques to get results, they only need to attack weak identity and access configurations on an internet-facing edge. Fortinet recommends avoiding local accounts whenever possible and, when they are unavoidable, adding extra authentication layers instead of trusting passwords alone.
The reported exploitation did not stay limited to a single moment in time. SecurityWeek reports that CVE-2024-24919 was one of the first Check Point vulnerabilities added to CISA's KEV catalog and that threat actors used it during 2024. Cyber Management Alliance says CISA ordered U.S. federal agencies to patch after the flaw was actively used by ransomware gangs to gain unauthorized access. CaveiraTech, in Brazilian coverage, notes that CISA had already flagged the Check Point Quantum gateway flaw in 2024 as actively exploited by ransomware groups. The common denominator is real-world exploitation, not theoretical possibility.
The campaign genealogy also matters. The material mentions links to ransomware, APT groups, and campaigns centered on organizations connected to the internet. There is an uncertain attribution linking the vulnerability to NailaoLocker and another, also uncertain, associating it with Fox Kitten through FortiGuard. The value of those references is not to close a definitive attribution, but to show that CVE-2024-24919 appears in different threat narratives involving persistent actors and ransomware campaigns. In other words, it is a vulnerability with tactical value for several attacker profiles.
At the response level, the material leaves one clear takeaway. The hotfix exists, but it is not enough on its own. Senserva insists that credentials and certificates stored on or used through the affected gateway must be rotated. The reason is both forensic and operational, information disclosure attacks leave little trace and defenders cannot assume that only what they can see today was exposed. In situations like this, technical remediation and secret rotation have to happen together.
Key facts table
| Date | Fact | Source | Confidence |
|---|---|---|---|
| 2026-07-23 | Fortinet describes CVE-2024-24919 as an information disclosure vulnerability in certain Check Point Security Gateways connected to the internet with VPN or Mobile Access enabled. | Fortinet | Confirmed |
| 2026-07-07 | Senserva classifies CVE-2024-24919 as an information disclosure vulnerability in Check Point Quantum Security Gateways with CVSS 8.6. | Senserva | Confirmed |
| 2026-07-07 | Senserva says the flaw can leak information to unauthenticated attackers and has been used to extract credentials from exposed gateways. | Senserva | Confirmed |
| 2026-07-07 | Senserva recommends patching and rotating credentials and certificates because disclosure leaves little forensic evidence. | Senserva | Confirmed |
| 2026-07-23 | Fortinet relays that Check Point reported active exploitation and attacks against local accounts protected only by passwords. | Fortinet | Confirmed |
| 2026-07-23 | Fortinet says Check Point made a hotfix available to correct the flaw. | Fortinet | Confirmed |
| 2026-07-24 | SecurityVulnerability.io summarizes CVE-2024-24919 as a severe remote access flaw in Check Point Quantum Gateways. | SecurityVulnerability.io | Confirmed |
| No confirmed date | Senserva reports an EPSS of 100% for CVE-2024-24919. | Senserva | Confirmed |
| No confirmed date | Cyber Management Alliance says the flaw was actively exploited by ransomware gangs and that CISA ordered federal agencies to patch it. | Cyber Management Alliance | Confirmed |
| 2026-07-23 | SecurityWeek says it was one of the first Check Point vulnerabilities added to CISA's KEV catalog. | SecurityWeek | Confirmed |
| 2026-07-23 | CaveiraTech recalls that CISA had already flagged the flaw in 2024 as actively exploited by ransomware groups. | CaveiraTech | Confirmed |
| 2026-07-17 | FortiGuard lists CVE-2024-24919 among vulnerabilities exploited by Fox Kitten. | Fortinet FortiGuard Labs | Attributed by source as uncertain |
| 2026-07-21 | LeMagIT reports, according to early information, that Germany's CDU may have been affected through exploitation of CVE-2024-24919. | LeMagIT | Attributed by source as uncertain |
| 2026-07-23 | An article in Revista TNE notes that Check Point added CVE-2024-24919 and CVE-2026-50751 to CISA's KEV catalog. | Revista TNE | Confirmed |
| 2026-07-24 | Senserva recommends reviewing Check Point advisories for CVE-2026-16232 and CVE-2024-24919 together. | Senserva | Confirmed |
| 2026-07-23 | Penligent concludes that the useful relationship between the older and newer Check Point flaws is architectural, because the management plane is exposed to the internet. | Penligent | Confirmed |
| 2026-07-23 | RST Cloud associates CVE-2024-24919 with a True exploit entry in Vulners and with Check Point Quantum Spark R80.40 firmware. | RST Cloud | Confirmed |
Operation timeline
| Date | Event | Actor/vector | Verified source |
|---|---|---|---|
| 2024 | CISA had already flagged CVE-2024-24919 as a vulnerability actively exploited by ransomware groups. | Active exploitation, ransomware | CaveiraTech |
| 2024 | SecurityWeek says threat actors used the flaw during 2024. | Real-world exploitation | SecurityWeek |
| 2024 | Cyber Management Alliance reports use by ransomware gangs to gain unauthorized access to target networks. | Ransomware, initial access | Cyber Management Alliance |
| 2024 | The vulnerability is added early to CISA's KEV catalog. | Defensive prioritization | SecurityWeek |
| 2024 to 2026 | Senserva reports practical use to extract credentials from internet-exposed gateways. | Credential Access | Senserva |
| 2026-07-07 | Senserva publishes its CVSS 8.6 classification and recommends a hotfix, plus credential and certificate rotation. | Mitigation, hardening | Senserva |
| 2026-07-17 | FortiGuard includes the flaw among those exploited by Fox Kitten. | APT attribution attributed by source as uncertain | Fortinet FortiGuard Labs |
| 2026-07-21 | LeMagIT suggests Germany's CDU may have been affected through exploitation of CVE-2024-24919. | Possible European incident | LeMagIT |
| 2026-07-23 | Fortinet reports active exploitation in password-only local accounts and says a hotfix is available. | Active exploitation, remediation | Fortinet |
| 2026-07-23 | Revista TNE and SecurityNews place CVE-2024-24919 alongside recent Check Point flaws in CISA's KEV catalog. | Persistent adversary interest | Revista TNE, SecurityNews |
| 2026-07-24 | Senserva recommends reviewing Check Point advisories together, not as isolated events. | Vulnerability management | Senserva |
| 2026-07-24 | SecurityVulnerability.io summarizes the flaw as a high-severity remote access issue in Check Point Quantum Gateways. | Sustained risk | SecurityVulnerability.io |
Attack chain and TTPs
The chain described by the sources is fairly coherent and, even without public IOCs, it allows a reconstruction of the operational logic. The first step is access to the internet-exposed gateway. Fortinet and Senserva place the flaw in devices with IPSec VPN, Remote Access VPN, or Mobile Access enabled. That turns the perimeter into a direct target. The attacker goes after an asset that is already authorized to receive traffic from outside the organization and also manages identity and trust.
The second step is the extraction of sensitive information. Senserva says the vulnerability has been used to extract credentials from exposed gateways, and also warns that the real impact may include certificates and other secrets stored on or used through the device. This is not generic data theft. It is key theft. Once the attacker has valid credentials, the issue stops being a simple disclosure and becomes reusable access.
The third step is using those credentials to move forward. In the research text, that lines up with two different sources. On one side, MITRE ATT&CK defines Initial Access as the techniques used to gain initial entry into a target network, Credential Access as the theft of reusable credentials, and Lateral Movement as movement inside the network after the initial compromise. On the other, CyberDesserts describes the ransomware pattern against perimeter firewalls and VPNs, where the edge is compromised first, remote access tools are deployed next, and lateral movement follows. The connection between those descriptions is clear.
Fortinet adds a useful defensive detail, the active exploitation appears to focus mainly on devices with local accounts and password-only authentication. That suggests the attack chain gets simpler when the organization keeps a weak identity layer on the gateway itself. If an attacker can rely on local credentials and leverage prior leaks, the operational cost of the campaign drops significantly.
Penligent offers a reading that helps preserve the larger context. Although CVE-2024-24919 and newer Check Point flaws do not share the same root cause, they do share the same risk model, they expose the management plane and remote access gateways to the internet. That architecture means a single compromise has a disproportionate effect. The value of the perimeter is not just that it sits at the front, but that it concentrates authentication, policy, certificates, and logs. When that breaks, the potential impact is no longer local.
The mitigation recommendation also reveals the implied attack chain. If Senserva asks for credential and certificate rotation after the hotfix, it is because the attacker may have read secrets before the patch and used them afterward. That fits ransomware campaigns in which initial access is not immediately used to encrypt anything, but instead to build persistence, steal credentials, and move laterally. In sequence terms, gateway exploitation is the threshold, not the end.
| TTP | Description | Source |
|---|---|---|
| TA0001 Initial Access | The vulnerability is used to gain initial entry to the network through the exposed gateway. | MITRE ATT&CK, Fortinet, Cyber Management Alliance |
| TA0006 Credential Access | The flaw allows credentials to be extracted from internet-exposed gateways. | MITRE ATT&CK, Senserva |
| TA0008 Lateral Movement | With valid credentials, the adversary can move inside the network after the initial compromise. | MITRE ATT&CK, CyberDesserts |
| Perimeter VPN exploitation | The operational target is perimeter firewalls and VPNs with exposed services. | Fortinet, CyberDesserts |
| Abuse of local accounts | Attacks mainly target configurations with local accounts and a single password. | Fortinet |
| Secret rotation | Remediation requires reissuing or rotating credentials and certificates due to possible prior leakage. | Senserva |
Regional impact
Regional overview
The material does not provide a closed geography or a precise distribution of victims by country, but it does support a very consistent regional thesis. CVE-2024-24919 affects exactly the kind of asset many Latin American and global organizations expose to the internet for operational reasons, the VPN gateway. That means the risk does not depend on a specific vertical, but on a common architecture, remote access through perimeter devices that concentrate authentication, certificates, and traffic control. If that device leaks secrets, the impact can spread from the border to the internal network quickly.
Penligent's reading helps explain why this kind of flaw is so attractive to ransomware and APT actors. Security appliances are high-value targets because they concentrate policies, routing, authentication, trust relationships, certificates, logs, and a privileged position in the network. In other words, they are both observation points and control points. When one is compromised, the attacker does not just get in. They also learn how the organization gets in, what trusts what, and which credentials can be used to move inside.
CyberDesserts adds the operational pattern. Ransomware operators tend to compromise perimeter firewalls and VPNs first through zero-day or n-day vulnerabilities, deploy remote access tools, and then move laterally. That pattern matters for the region because many Latin American organizations maintain hybrid architectures with direct remote access to the perimeter and variable segmentation controls. Even without a confirmed local victim in the material, the threat is concrete enough to factor into contingency and response planning.
CISA's presence in the story is also important for the region. If a vulnerability enters CISA's KEV catalog early and U.S. federal agencies receive patching orders, the operational message for any internet-connected organization is clear, the risk is not hypothetical. The prioritization CISA gives CVE-2024-24919 is reflected in the 2024 and 2026 sources, which points to persistent adversary interest and residual exposure in unremediated environments.
Brazil
Brazil appears in the material on two levels. The first is institutional. CERT.br is defined as the national last-resort CSIRT, maintained by NIC.br and responsible for providing incident handling services to any network that uses resources administered by NIC.br. That matters because it places incident response within a formal national framework with the capacity to support complex events. If a Brazilian organization detected exploitation or credential exposure tied to a Check Point gateway, the existence of that institutional node reinforces the need for a coordinated reporting path.
The second level is media and risk perception. CaveiraTech, a Brazilian outlet, recalls that CISA had already flagged CVE-2024-24919 in 2024 on Check Point Quantum gateways as a vulnerability actively exploited by ransomware groups. That coverage does not add a confirmed local victim, but it does translate the risk into a regional language and connect it to the threats circulating in Brazil's security conversation. That is enough to say the issue is on the radar of the Brazilian cybersecurity community.
The material also suggests a scenario that deserves special attention in Brazil, the use of local accounts protected only by passwords on internet-exposed gateways. Fortinet notes that attacks mainly targeted that kind of setup. In a Brazilian organization whose remote access depends on Check Point, that means the combination of internet exposure, weak authentication, and possible credential leakage creates an attack surface that can be exploited without pivoting from an internal endpoint. The vulnerability hits the edge, but its effects extend into identity and internal trust.
There is no confirmed Brazilian case in the research provided, no named victim, no exact intrusion date, and no damage scope. There are also no public IOCs tied to the country. Even so, the operational risk is clear, if a Brazilian network uses Check Point gateways with remote access enabled, priority should not stop at patching. Secret rotation, log review, checks for unusual remote access, and removal of password-only local authentication are all part of the same problem.
Technical indicators
There are no verifiable public IOCs in the material provided. The available research discusses exploitation, affected product families, CISA prioritization, and mitigation guidance, but it does not publish hashes, domains, IPs, or concrete paths tied to campaigns identified with precision. That limits the ability to produce a classic indicators block and pushes the case toward perimeter exposure risk and credential rotation.
| Type | Value | Source |
|---|---|---|
| CVE | CVE-2024-24919 | Senserva, Fortinet, SecurityWeek, CaveiraTech |
| Severity | CVSS 8.6 | Senserva |
| Exploitation status | Active, exploited in the wild | Fortinet, SecurityWeek, Cyber Management Alliance, CaveiraTech |
| Product families | Check Point Quantum Security Gateways, Quantum Spark R80.40 | Senserva, RST Cloud |
| Affected functions | IPSec VPN, Remote Access VPN, Mobile Access | Fortinet, Senserva |
| Recommended action | Hotfix, credential and certificate rotation | Fortinet, Senserva |
Analysis for security teams
The first operational decision is to treat this as a perimeter exposure issue, not as a simple software advisory. If a Check Point gateway is connected to the internet and has remote access services enabled, the organization should assume the surface is within reach of ransomware operators and, potentially, groups capable of selective exploitation. The material does not describe a lab exploit, it describes active exploitation and practical use for credential extraction.
The second decision is to prioritize secret rotation. Senserva states this clearly, and the logic is hard to dispute. If the device may have leaked credentials or certificates, installing the hotfix without changing secrets leaves open the possibility that the attacker still has valid access. In that scenario, the patch fixes the door, but it does not necessarily revoke the key. This includes local accounts, credentials used through the gateway, and certificates stored on or referenced by it.
The third decision is to review authentication. Fortinet highlights that abuse focused on devices with local accounts relying only on passwords. That forces a review of access design, centralized authentication should be preferred, and if local accounts cannot be removed, additional authentication layers should be added. That aligns with the pattern CyberDesserts sees in ransomware campaigns, where the perimeter is the first target. The weaker the identity layer, the lower the attacker's cost.
The fourth decision is to examine logs with the assumption of pre-patch compromise. Reviewing logs is not only about finding ongoing exploitation, but also about estimating which users, sessions, or credentials may have been observed before the hotfix. Revista TNE recommends checking activity for signs of compromise, and that makes sense together with Senserva's warning about the limited forensic trail left by information disclosure. If it is impossible to know exactly what was leaked, the prudent stance is to assume broad exposure.
The fifth decision is to rethink remote access architecture. Penligent offers the strongest formulation in the material, the useful connection between the older and newer Check Point flaws is not technical but architectural. When the management plane is exposed to the internet, any vulnerability touching that plane becomes a risk multiplier. Taking management interfaces off the internet, segmenting administrative access more carefully, centralizing authentication, and sending logs to an external collector are not cosmetic measures. They are barriers meant to keep a single perimeter device from becoming the center of the compromise.
Material limitations
The material does not include concrete IOCs, confirmed victims with detail, or a step-by-step exploit dossier. There is also no publicly verifiable information on a specific campaign in Argentina, Chile, Paraguay, Bolivia, Peru, Colombia, Mexico, or Uruguay. For Brazil, the research provides institutional and media context, but it does not identify a local victim or a confirmed incident with attribution.
References to Fox Kitten, NailaoLocker, and the possible impact on Germany's CDU are attributed by some sources as uncertain or preliminary. They should therefore not be read as closed attributions, but as contextual clues showing how the flaw circulated in different threat narratives. The same applies to any link between CVE-2024-24919 and APT actors, the material supports discussion of use by sophisticated adversaries and association by some sources, but not a universally validated attribution.
The research also does not provide a complete taxonomy of affected variants beyond the names mentioned, nor a detailed breakdown of exact versions exposed in each campaign. It does, however, leave enough evidence to say that Check Point Quantum and Quantum Spark gateways are within the practical risk area, that internet-exposed remote access is the structural driver, and that defensive response should combine patching, credential rotation, log review, and authentication hardening.
Sources
- Blogscommunity.fortinet.com· Fortinet
- CVE-2024-24919 exploited in the wild: patch Check Point Quantum Security Gateways nowsenserva.com· Senserva
- Check Point SmartConsole Zero-Day CVE-2026-16232 ...senserva.com· Senserva
- Fox Kitten - Threat Actorfortiguard.com· Fortinet FortiGuard Labs
- June 2026: Biggest Cyber Attacks, Data Breaches ...cm-alliance.com· Cyber Management Alliance
- New Check Point Zero-Day Vulnerability Exploited in the Wildsecurityweek.com· SecurityWeek
- Check Point corrige falha no SmartConsole explorada para ...caveiratech.com· CaveiraTech
- Gestion des accès (MFA, FIDO, SSO, SAML, IDaaS, CIAM)lemagit.fr· LeMagIT
- Checkpoint Latest High Vulnerabilitiessecurityvulnerability.io· SecurityVulnerability.io
- Explotan vulnerabilidad crítica de Check Point - Revista TNEcirculotne.com· Revista TNE
- Initial Accessattack.mitre.org· MITRE ATT&CK
- Credential Accessattack.mitre.org· MITRE ATT&CK
- Lateral Movementattack.mitre.org· MITRE ATT&CK
- CVE-2026-16232: Check Point SmartConsole Improper ...penligent.ai· Penligent
- Threat report post on Check Point zero-day and related CVEsx.com· RST Cloud
- Why Ransomware Targets Firewalls: The FortiBleed Patternblog.cyberdesserts.com· CyberDesserts
- Are You Prepared for the New Check Point Zero-Day Attack?securitynews.com· SecurityNews
- Lewis Combs' Postlinkedin.com· LinkedIn
- CERT.br – Centro de Estudos, Resposta e Tratamento de ...cert.br· NIC.br / CERT.br



