logo

Check Point releases emergency fix for VPN zero-day exploited in attacks

ID: 6309a0f1-849f-50c6-a429-be1ac19aa409

STIX ID: report--6309a0f1-849f-50c6-a429-be1ac19aa409

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-05-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Check Point has released hotfixes for a zero-day (CVE-2024-24919) affecting internet-exposed Check Point Security Gateways with Remote Access VPN or Mobile Access enabled; attackers have been observed exploiting the flaw to read gateway information and attempt remote access using weak or legacy local credentials. The advisory lists affected product versions, installation steps (hotfix updates and manual EOL patches), and mitigation guidance including updating the AD account password used for gateway authentication and running the vendor's VPNcheck validation script; a reboot is required after applying the patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.