logo

Check Point Warns of Zero-Day Attacks on its VPN Gateway Products

ID: c556c394-e5f5-59b1-a59a-8c3c27a0e14e

STIX ID: report--c556c394-e5f5-59b1-a59a-8c3c27a0e14e

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-05-29

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Check Point and multiple security firms have disclosed a critical zero-day (CVE-2024-24919, CVSS 8.6) in Check Point Network Security gateway products (CloudGuard, Quantum series, Quantum Spark) being actively exploited since early April 2024; the flaw enables attackers to enumerate and extract local password hashes and read sensitive files (reported as path traversal, with /etc/shadow referenced), has a public PoC, affects thousands of internet-facing devices, and has been used to harvest AD data and conduct lateral movement—vendors have published hotfixes and customers are urged to patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.