Applied Cybernetics Group
Threat intel → detection pipeline
Friday, September 18, 2026
Data as of 13:09 UTC

known ransomware use

Check Point Quantum Security Gateways Information Disclosure Vulnerability

Added to KEV
2024-05-30
Federal due date
2024-06-20
Vendor
Check Point
Product
Quantum Security Gateways
EPSS
100.0th percentile (score 1.000, as of 2026-09-16)
NVD CVSS v3.1
8.6 (HIGH)
Ransomware use
Known
ATT&CK
T1003.003 , T1003.008 , T1005 , T1059.004 , T1202 · signal rollup
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2024-24919

CISA short description

Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

NVD description

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.