Search

Find a vulnerability

Search criteria

    278 vulnerabilities by checkpoint

    CVE-2026-93616 (GCVE-0-2026-93616)

    Vulnerability from nvd – Published: 2026-09-22 12:59 – Updated: 2026-09-23 03:55
    VLAI CISA ENISA Previdian
    Title
    Directory Traversal and File upload allows execution of arbitrary script on the Management Server
    Summary
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 00:00 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.20 with no Jumbo Hotfix
    Affected: R82.10 with Jumbo Hotfix Take 44 or below
    Affected: R82 with Jumbo Hotfix Take 126 or below
    Affected: R81.20 with Jumbo Hotfix Take 166 or below
    Affected: R81.10 (EOS) with Jumbo Hotfix Take 190 or below
    Affected: R81 (EOS)
    Affected: R80.40 (EOS)
    Affected: R80.30 (EOS)
    Affected: R80.20 (EOS)
    Affected: R80.10 (EOS)
    Affected: R80 (EOS)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93616",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-22",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T03:55:59.259Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory"
                ],
                "url": "https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-09-22T00:00:00.000Z",
                "value": "CVE-2026-93616 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.20 with no Jumbo Hotfix"
                },
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 44 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 126 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 166 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10 (EOS) with Jumbo Hotfix Take 190 or below"
                },
                {
                  "status": "affected",
                  "version": "R81 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.40 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.30 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.20 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.10 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80 (EOS)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027).",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T12:59:01.057Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk1000171"
            }
          ],
          "title": "Directory Traversal and File upload allows execution of arbitrary script on the Management Server",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-93616",
        "datePublished": "2026-09-22T12:59:01.057Z",
        "dateReserved": "2026-09-18T11:08:38.818Z",
        "dateUpdated": "2026-09-23T03:55:59.259Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91843 (GCVE-0-2026-91843)

    Vulnerability from nvd – Published: 2026-09-16 13:03 – Updated: 2026-09-17 11:39
    VLAI
    Title
    Stack overflow in login process to the Security Management and Log Servers
    Summary
    A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 03:56 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 44 or below
    Affected: R82 with Jumbo Hotfix Take 126 or below
    Affected: R81.20 with Jumbo Hotfix Take 166 or below
    Affected: R81.10 (EOS) with Jumbo Hotfix Take 190 or below
    Affected: R81 (EOS)
    Affected: R80.40 (EOS)
    Affected: R80.30 (EOS)
    Affected: R80.20 (EOS)
    Affected: R80.10 (EOS)
    Affected: R80 (EOS)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91843",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T03:56:52.301574Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T11:39:25.299Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 44 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 126 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 166 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10 (EOS) with Jumbo Hotfix Take 190 or below"
                },
                {
                  "status": "affected",
                  "version": "R81 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.40 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.30 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.20 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.10 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80 (EOS)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:03:40.553Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk1000155"
            }
          ],
          "title": "Stack overflow in login process to the Security Management and Log Servers",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-91843",
        "datePublished": "2026-09-16T13:03:40.553Z",
        "dateReserved": "2026-09-15T08:30:18.206Z",
        "dateUpdated": "2026-09-17T11:39:25.299Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85103 (GCVE-0-2026-85103)

    Vulnerability from nvd – Published: 2026-09-09 13:00 – Updated: 2026-09-10 03:56
    VLAI
    Title
    Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
    Summary
    A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-09 00:00 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 43 or below
    Affected: R82 with Jumbo Hotfix Take 125 or below
    Affected: R81.20 with Jumbo Hotfix Take 165 or below
    Create a notification for this product.
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 43 or below
    Affected: R82 with Jumbo Hotfix Take 125 or below
    Affected: R81.20 with Jumbo Hotfix Take 165 or below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-85103",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-09T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T03:56:41.934Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 43 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 125 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 165 or below"
                }
              ]
            },
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 43 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 125 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 165 or below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122: Heap-based Buffer Overflow.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-09T13:00:42.088Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk1000118"
            }
          ],
          "title": "Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-85103",
        "datePublished": "2026-09-09T13:00:42.088Z",
        "dateReserved": "2026-09-03T06:38:15.701Z",
        "dateUpdated": "2026-09-10T03:56:41.934Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-18574 (GCVE-0-2026-18574)

    Vulnerability from nvd – Published: 2026-08-03 12:07 – Updated: 2026-08-05 03:56
    VLAI
    Title
    Authentication Bypass in Check Point Security Management Server
    Summary
    An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-04 00:00 UTC
    CWE
    • CWE-288 - Authentication Bypass Using an Alternate Path or Channel
    References
    Impacted products
    Vendor Product Version
    checkpoint Security Management Server Affected: R82.10 with Jumbo Hotfix Accumulator Take 39 or below
    Affected: R82 with Jumbo Hotfix Accumulator Take 121 or below
    Affected: R81.20 with Jumbo Hotfix Accumulator Take 160 or below
    Affected: R81.10
    Affected: R81
    Affected: R80.40
    Affected: R80.30
    Affected: R80.20
    Affected: R80.10
    Affected: R80
    Create a notification for this product.
    checkpoint Multi-Domain Security Management Server Affected: R82.10 with Jumbo Hotfix Accumulator Take 39 or below
    Affected: R82 with Jumbo Hotfix Accumulator Take 121 or below
    Affected: R81.20 with Jumbo Hotfix Accumulator Take 160 or below
    Affected: R81.10
    Affected: R81
    Affected: R80.40
    Affected: R80.30
    Affected: R80.20
    Affected: R80.10
    Affected: R80
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-18574",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-04T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-05T03:56:59.065Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Security Management Server",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Accumulator Take 39 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Accumulator Take 121 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Accumulator Take 160 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10"
                },
                {
                  "status": "affected",
                  "version": "R81"
                },
                {
                  "status": "affected",
                  "version": "R80.40"
                },
                {
                  "status": "affected",
                  "version": "R80.30"
                },
                {
                  "status": "affected",
                  "version": "R80.20"
                },
                {
                  "status": "affected",
                  "version": "R80.10"
                },
                {
                  "status": "affected",
                  "version": "R80"
                }
              ]
            },
            {
              "product": "Multi-Domain Security Management Server",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Accumulator Take 39 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Accumulator Take 121 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Accumulator Take 160 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10"
                },
                {
                  "status": "affected",
                  "version": "R81"
                },
                {
                  "status": "affected",
                  "version": "R80.40"
                },
                {
                  "status": "affected",
                  "version": "R80.30"
                },
                {
                  "status": "affected",
                  "version": "R80.20"
                },
                {
                  "status": "affected",
                  "version": "R80.10"
                },
                {
                  "status": "affected",
                  "version": "R80"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-288",
                  "description": "CWE-288: Authentication Bypass Using an Alternate Path or Channel",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-03T12:07:33.976Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "name": "Check Point Security Advisory sk185222",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.checkpoint.com/results/sk/sk185222"
            }
          ],
          "title": "Authentication Bypass in Check Point Security Management Server",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-18574",
        "datePublished": "2026-08-03T12:07:33.976Z",
        "dateReserved": "2026-08-02T06:50:57.353Z",
        "dateUpdated": "2026-08-05T03:56:59.065Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-62145 (GCVE-0-2026-62145)

    Vulnerability from nvd – Published: 2026-07-22 13:53 – Updated: 2026-07-24 03:56
    VLAI
    Title
    Local Privilege Escalation in Gaia Portal
    Summary
    A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 00:00 UTC
    CWE
    • CWE-269 - Improper Privilege Management.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-62145",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-24T03:56:05.075Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            },
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-22T13:57:12.312Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185153"
            }
          ],
          "title": "Local Privilege Escalation in Gaia Portal"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-62145",
        "datePublished": "2026-07-22T13:53:53.656Z",
        "dateReserved": "2026-07-13T10:24:07.648Z",
        "dateUpdated": "2026-07-24T03:56:05.075Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-62144 (GCVE-0-2026-62144)

    Vulnerability from nvd – Published: 2026-07-22 13:53 – Updated: 2026-07-24 03:56
    VLAI
    Title
    Management Authentication Bypass and Privilege Escalation
    Summary
    An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 00:00 UTC
    CWE
    • CWE-287 - Improper Authentication.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    checkpoint Multi-Domain Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 9.1,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-62144",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-24T03:56:14.016Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            },
            {
              "product": "Multi-Domain Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients."
            }
          ],
          "metrics": [
            {
              "format": "CVSS",
              "other": {
                "content": {
                  "attackComplexity": "LOW",
                  "attackRequirements": "NONE",
                  "attackVector": "NETWORK",
                  "baseScore": 9.3,
                  "baseSeverity": "CRITICAL",
                  "privilegesRequired": "NONE",
                  "subAvailabilityImpact": "NONE",
                  "subConfidentialityImpact": "NONE",
                  "subIntegrityImpact": "NONE",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                  "version": "4.0",
                  "vulnAvailabilityImpact": "HIGH",
                  "vulnConfidentialityImpact": "HIGH",
                  "vulnIntegrityImpact": "HIGH"
                },
                "type": "CVSSv4.0"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-22T13:57:08.986Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185152"
            }
          ],
          "title": "Management Authentication Bypass and Privilege Escalation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-62144",
        "datePublished": "2026-07-22T13:53:35.969Z",
        "dateReserved": "2026-07-13T10:24:07.648Z",
        "dateUpdated": "2026-07-24T03:56:14.016Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-16232 (GCVE-0-2026-16232)

    Vulnerability from nvd – Published: 2026-07-22 13:53 – Updated: 2026-08-10 18:34
    VLAI CISA CIRCL Previdian
    Title
    Authentication Bypass in the SmartConsole Login Process Using an Application Token
    Summary
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 03:55 UTC
    CWE
    • CWE-287 - Improper Authentication.
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    checkpoint Multi-Domain Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-16232",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T03:55:51.690584Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-07-22",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-10T18:34:01.548Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            },
            {
              "product": "Multi-Domain Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-02T07:06:06.363Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185169"
            }
          ],
          "title": "Authentication Bypass in the SmartConsole Login Process Using an Application Token",
          "x_generator": {
            "engine": "cveClient/1.0.25"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-16232",
        "datePublished": "2026-07-22T13:53:09.830Z",
        "dateReserved": "2026-07-19T12:14:17.233Z",
        "dateUpdated": "2026-08-10T18:34:01.548Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-10847 (GCVE-0-2026-10847)

    Vulnerability from nvd – Published: 2026-06-11 13:52 – Updated: 2026-06-11 14:20
    VLAI
    Title
    Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS
    Summary
    A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-11 14:19 UTC
    CWE
    • CWE-427 - Uncontrolled Search Path Element
    References
    Impacted products
    Vendor Product Version
    checkpoint Identity Agent Affected: Versions prior to 81.087.0000
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-10847",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-11T14:19:16.357809Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-11T14:20:43.159Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Identity Agent",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "Versions prior to 81.087.0000"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "Uncontrolled Search Path Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-11T13:52:11.651Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "name": "Check Point Security Advisory for CVE-2026-10847",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.checkpoint.com/results/sk/sk185052"
            }
          ],
          "title": "Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-10847",
        "datePublished": "2026-06-11T13:52:11.651Z",
        "dateReserved": "2026-06-04T12:13:32.828Z",
        "dateUpdated": "2026-06-11T14:20:43.159Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-50752 (GCVE-0-2026-50752)

    Vulnerability from nvd – Published: 2026-06-08 11:00 – Updated: 2026-06-10 13:36
    VLAI
    Title
    Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1
    Summary
    A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-09 03:55 UTC
    CWE
    • CWE-295 - Improper Certificate Validation.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 19 or below
    Affected: R82 with Jumbo Hotfix Take 103 or below
    Affected: R81.20 with Jumbo Hotfix Take 141 or below
    Affected: R81.10, R81, and R80.40
    Create a notification for this product.
    checkpoint Spark Firewalls Affected: R80.20.X, R81.10.X, and R82.00.X
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-50752",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-09T03:55:37.901004Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-10T13:36:24.946Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 19 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 103 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 141 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, and R80.40"
                }
              ]
            },
            {
              "product": "Spark Firewalls",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R80.20.X, R81.10.X, and R82.00.X"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295: Improper Certificate Validation.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-08T11:00:38.563Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185035"
            }
          ],
          "title": "Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-50752",
        "datePublished": "2026-06-08T11:00:38.563Z",
        "dateReserved": "2026-06-07T09:42:08.252Z",
        "dateUpdated": "2026-06-10T13:36:24.946Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48136 (GCVE-0-2026-48136)

    Vulnerability from nvd – Published: 2026-05-26 12:57 – Updated: 2026-06-02 14:17
    VLAI
    Title
    Authenticated Administrator Role-Based Access Control Bypass in Compliance
    Summary
    When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-26 18:41 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48136",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-26T18:41:27.298316Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-02T14:17:00.827Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:34.470Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184992"
            }
          ],
          "title": "Authenticated Administrator Role-Based Access Control Bypass in Compliance"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48136",
        "datePublished": "2026-05-26T12:57:29.298Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-06-02T14:17:00.827Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48135 (GCVE-0-2026-48135)

    Vulnerability from nvd – Published: 2026-05-26 12:57 – Updated: 2026-05-27 18:36
    VLAI
    Title
    HTTP service can incorrectly process malformed HTTP requests
    Summary
    A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-26 14:48 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48135",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-26T14:48:38.051261Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-27T18:36:10.600Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A Check Point HTTP-based service can incorrectly handle malformed HTTP requests.\nThe issue is related to HTTP request parsing and validation."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122: Heap-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:28.067Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184991"
            }
          ],
          "title": "HTTP service can incorrectly process malformed HTTP requests"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48135",
        "datePublished": "2026-05-26T12:57:19.074Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-05-27T18:36:10.600Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48134 (GCVE-0-2026-48134)

    Vulnerability from nvd – Published: 2026-05-26 12:57 – Updated: 2026-06-02 14:15
    VLAI
    Title
    SQL injection issue in UserCheck Portal when DLP Software Blade is active
    Summary
    When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-02 14:15 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48134",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-02T14:15:04.599414Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-02T14:15:31.285Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway\u0027s stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly.\nExposure is reduced if the UserCheck Portal is not accessible from untrusted networks."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:21.332Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184983"
            }
          ],
          "title": "SQL injection issue in UserCheck Portal when DLP Software Blade is active"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48134",
        "datePublished": "2026-05-26T12:57:07.767Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-06-02T14:15:31.285Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48133 (GCVE-0-2026-48133)

    Vulnerability from nvd – Published: 2026-05-26 12:56 – Updated: 2026-06-02 14:14
    VLAI
    Title
    Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
    Summary
    When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-02 14:14 UTC
    CWE
    • CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48133",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-02T14:14:15.264635Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-02T14:14:24.478Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-98",
                  "description": "CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:14.984Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184993"
            }
          ],
          "title": "Identity Awareness Captive Portal - Unauthenticated Local File Inclusion"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48133",
        "datePublished": "2026-05-26T12:56:56.250Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-06-02T14:14:24.478Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48132 (GCVE-0-2026-48132)

    Vulnerability from nvd – Published: 2026-05-26 12:56 – Updated: 2026-06-02 14:09
    VLAI
    Title
    VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP
    Summary
    The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic).
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-02 14:09 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48132",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-02T14:09:04.979541Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-02T14:09:19.968Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125: Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:07.343Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184982"
            }
          ],
          "title": "VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48132",
        "datePublished": "2026-05-26T12:56:47.693Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-06-02T14:09:19.968Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48131 (GCVE-0-2026-48131)

    Vulnerability from nvd – Published: 2026-05-26 12:56 – Updated: 2026-05-26 15:18
    VLAI
    Title
    VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero
    Summary
    The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-26 15:12 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48131",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-26T15:12:47.698813Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-26T15:18:43.287Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122: Heap-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:15:50.325Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184981"
            }
          ],
          "title": "VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48131",
        "datePublished": "2026-05-26T12:56:08.817Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-05-26T15:18:43.287Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-93616 (GCVE-0-2026-93616)

    Vulnerability from cvelistv5 – Published: 2026-09-22 12:59 – Updated: 2026-09-23 03:55
    VLAI CISA ENISA Previdian
    Title
    Directory Traversal and File upload allows execution of arbitrary script on the Management Server
    Summary
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 00:00 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.20 with no Jumbo Hotfix
    Affected: R82.10 with Jumbo Hotfix Take 44 or below
    Affected: R82 with Jumbo Hotfix Take 126 or below
    Affected: R81.20 with Jumbo Hotfix Take 166 or below
    Affected: R81.10 (EOS) with Jumbo Hotfix Take 190 or below
    Affected: R81 (EOS)
    Affected: R80.40 (EOS)
    Affected: R80.30 (EOS)
    Affected: R80.20 (EOS)
    Affected: R80.10 (EOS)
    Affected: R80 (EOS)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93616",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-22",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T03:55:59.259Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory"
                ],
                "url": "https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-09-22T00:00:00.000Z",
                "value": "CVE-2026-93616 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.20 with no Jumbo Hotfix"
                },
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 44 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 126 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 166 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10 (EOS) with Jumbo Hotfix Take 190 or below"
                },
                {
                  "status": "affected",
                  "version": "R81 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.40 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.30 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.20 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.10 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80 (EOS)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027).",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T12:59:01.057Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk1000171"
            }
          ],
          "title": "Directory Traversal and File upload allows execution of arbitrary script on the Management Server",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-93616",
        "datePublished": "2026-09-22T12:59:01.057Z",
        "dateReserved": "2026-09-18T11:08:38.818Z",
        "dateUpdated": "2026-09-23T03:55:59.259Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91843 (GCVE-0-2026-91843)

    Vulnerability from cvelistv5 – Published: 2026-09-16 13:03 – Updated: 2026-09-17 11:39
    VLAI
    Title
    Stack overflow in login process to the Security Management and Log Servers
    Summary
    A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 03:56 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 44 or below
    Affected: R82 with Jumbo Hotfix Take 126 or below
    Affected: R81.20 with Jumbo Hotfix Take 166 or below
    Affected: R81.10 (EOS) with Jumbo Hotfix Take 190 or below
    Affected: R81 (EOS)
    Affected: R80.40 (EOS)
    Affected: R80.30 (EOS)
    Affected: R80.20 (EOS)
    Affected: R80.10 (EOS)
    Affected: R80 (EOS)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91843",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T03:56:52.301574Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T11:39:25.299Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 44 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 126 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 166 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10 (EOS) with Jumbo Hotfix Take 190 or below"
                },
                {
                  "status": "affected",
                  "version": "R81 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.40 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.30 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.20 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.10 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80 (EOS)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:03:40.553Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk1000155"
            }
          ],
          "title": "Stack overflow in login process to the Security Management and Log Servers",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-91843",
        "datePublished": "2026-09-16T13:03:40.553Z",
        "dateReserved": "2026-09-15T08:30:18.206Z",
        "dateUpdated": "2026-09-17T11:39:25.299Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85103 (GCVE-0-2026-85103)

    Vulnerability from cvelistv5 – Published: 2026-09-09 13:00 – Updated: 2026-09-10 03:56
    VLAI
    Title
    Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
    Summary
    A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-09 00:00 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 43 or below
    Affected: R82 with Jumbo Hotfix Take 125 or below
    Affected: R81.20 with Jumbo Hotfix Take 165 or below
    Create a notification for this product.
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 43 or below
    Affected: R82 with Jumbo Hotfix Take 125 or below
    Affected: R81.20 with Jumbo Hotfix Take 165 or below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-85103",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-09T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T03:56:41.934Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 43 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 125 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 165 or below"
                }
              ]
            },
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 43 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 125 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 165 or below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122: Heap-based Buffer Overflow.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-09T13:00:42.088Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk1000118"
            }
          ],
          "title": "Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-85103",
        "datePublished": "2026-09-09T13:00:42.088Z",
        "dateReserved": "2026-09-03T06:38:15.701Z",
        "dateUpdated": "2026-09-10T03:56:41.934Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-18574 (GCVE-0-2026-18574)

    Vulnerability from cvelistv5 – Published: 2026-08-03 12:07 – Updated: 2026-08-05 03:56
    VLAI
    Title
    Authentication Bypass in Check Point Security Management Server
    Summary
    An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-04 00:00 UTC
    CWE
    • CWE-288 - Authentication Bypass Using an Alternate Path or Channel
    References
    Impacted products
    Vendor Product Version
    checkpoint Security Management Server Affected: R82.10 with Jumbo Hotfix Accumulator Take 39 or below
    Affected: R82 with Jumbo Hotfix Accumulator Take 121 or below
    Affected: R81.20 with Jumbo Hotfix Accumulator Take 160 or below
    Affected: R81.10
    Affected: R81
    Affected: R80.40
    Affected: R80.30
    Affected: R80.20
    Affected: R80.10
    Affected: R80
    Create a notification for this product.
    checkpoint Multi-Domain Security Management Server Affected: R82.10 with Jumbo Hotfix Accumulator Take 39 or below
    Affected: R82 with Jumbo Hotfix Accumulator Take 121 or below
    Affected: R81.20 with Jumbo Hotfix Accumulator Take 160 or below
    Affected: R81.10
    Affected: R81
    Affected: R80.40
    Affected: R80.30
    Affected: R80.20
    Affected: R80.10
    Affected: R80
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-18574",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-04T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-05T03:56:59.065Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Security Management Server",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Accumulator Take 39 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Accumulator Take 121 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Accumulator Take 160 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10"
                },
                {
                  "status": "affected",
                  "version": "R81"
                },
                {
                  "status": "affected",
                  "version": "R80.40"
                },
                {
                  "status": "affected",
                  "version": "R80.30"
                },
                {
                  "status": "affected",
                  "version": "R80.20"
                },
                {
                  "status": "affected",
                  "version": "R80.10"
                },
                {
                  "status": "affected",
                  "version": "R80"
                }
              ]
            },
            {
              "product": "Multi-Domain Security Management Server",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Accumulator Take 39 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Accumulator Take 121 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Accumulator Take 160 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10"
                },
                {
                  "status": "affected",
                  "version": "R81"
                },
                {
                  "status": "affected",
                  "version": "R80.40"
                },
                {
                  "status": "affected",
                  "version": "R80.30"
                },
                {
                  "status": "affected",
                  "version": "R80.20"
                },
                {
                  "status": "affected",
                  "version": "R80.10"
                },
                {
                  "status": "affected",
                  "version": "R80"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-288",
                  "description": "CWE-288: Authentication Bypass Using an Alternate Path or Channel",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-03T12:07:33.976Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "name": "Check Point Security Advisory sk185222",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.checkpoint.com/results/sk/sk185222"
            }
          ],
          "title": "Authentication Bypass in Check Point Security Management Server",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-18574",
        "datePublished": "2026-08-03T12:07:33.976Z",
        "dateReserved": "2026-08-02T06:50:57.353Z",
        "dateUpdated": "2026-08-05T03:56:59.065Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-62145 (GCVE-0-2026-62145)

    Vulnerability from cvelistv5 – Published: 2026-07-22 13:53 – Updated: 2026-07-24 03:56
    VLAI
    Title
    Local Privilege Escalation in Gaia Portal
    Summary
    A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 00:00 UTC
    CWE
    • CWE-269 - Improper Privilege Management.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-62145",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-24T03:56:05.075Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            },
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-22T13:57:12.312Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185153"
            }
          ],
          "title": "Local Privilege Escalation in Gaia Portal"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-62145",
        "datePublished": "2026-07-22T13:53:53.656Z",
        "dateReserved": "2026-07-13T10:24:07.648Z",
        "dateUpdated": "2026-07-24T03:56:05.075Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-62144 (GCVE-0-2026-62144)

    Vulnerability from cvelistv5 – Published: 2026-07-22 13:53 – Updated: 2026-07-24 03:56
    VLAI
    Title
    Management Authentication Bypass and Privilege Escalation
    Summary
    An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 00:00 UTC
    CWE
    • CWE-287 - Improper Authentication.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    checkpoint Multi-Domain Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 9.1,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-62144",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-24T03:56:14.016Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            },
            {
              "product": "Multi-Domain Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients."
            }
          ],
          "metrics": [
            {
              "format": "CVSS",
              "other": {
                "content": {
                  "attackComplexity": "LOW",
                  "attackRequirements": "NONE",
                  "attackVector": "NETWORK",
                  "baseScore": 9.3,
                  "baseSeverity": "CRITICAL",
                  "privilegesRequired": "NONE",
                  "subAvailabilityImpact": "NONE",
                  "subConfidentialityImpact": "NONE",
                  "subIntegrityImpact": "NONE",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                  "version": "4.0",
                  "vulnAvailabilityImpact": "HIGH",
                  "vulnConfidentialityImpact": "HIGH",
                  "vulnIntegrityImpact": "HIGH"
                },
                "type": "CVSSv4.0"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-22T13:57:08.986Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185152"
            }
          ],
          "title": "Management Authentication Bypass and Privilege Escalation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-62144",
        "datePublished": "2026-07-22T13:53:35.969Z",
        "dateReserved": "2026-07-13T10:24:07.648Z",
        "dateUpdated": "2026-07-24T03:56:14.016Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-16232 (GCVE-0-2026-16232)

    Vulnerability from cvelistv5 – Published: 2026-07-22 13:53 – Updated: 2026-08-10 18:34
    VLAI CISA CIRCL Previdian
    Title
    Authentication Bypass in the SmartConsole Login Process Using an Application Token
    Summary
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 03:55 UTC
    CWE
    • CWE-287 - Improper Authentication.
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    checkpoint Multi-Domain Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-16232",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T03:55:51.690584Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-07-22",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-10T18:34:01.548Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            },
            {
              "product": "Multi-Domain Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-02T07:06:06.363Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185169"
            }
          ],
          "title": "Authentication Bypass in the SmartConsole Login Process Using an Application Token",
          "x_generator": {
            "engine": "cveClient/1.0.25"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-16232",
        "datePublished": "2026-07-22T13:53:09.830Z",
        "dateReserved": "2026-07-19T12:14:17.233Z",
        "dateUpdated": "2026-08-10T18:34:01.548Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-10847 (GCVE-0-2026-10847)

    Vulnerability from cvelistv5 – Published: 2026-06-11 13:52 – Updated: 2026-06-11 14:20
    VLAI
    Title
    Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS
    Summary
    A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-11 14:19 UTC
    CWE
    • CWE-427 - Uncontrolled Search Path Element
    References
    Impacted products
    Vendor Product Version
    checkpoint Identity Agent Affected: Versions prior to 81.087.0000
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-10847",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-11T14:19:16.357809Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-11T14:20:43.159Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Identity Agent",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "Versions prior to 81.087.0000"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "Uncontrolled Search Path Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-11T13:52:11.651Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "name": "Check Point Security Advisory for CVE-2026-10847",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://support.checkpoint.com/results/sk/sk185052"
            }
          ],
          "title": "Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-10847",
        "datePublished": "2026-06-11T13:52:11.651Z",
        "dateReserved": "2026-06-04T12:13:32.828Z",
        "dateUpdated": "2026-06-11T14:20:43.159Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-50752 (GCVE-0-2026-50752)

    Vulnerability from cvelistv5 – Published: 2026-06-08 11:00 – Updated: 2026-06-10 13:36
    VLAI
    Title
    Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1
    Summary
    A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-09 03:55 UTC
    CWE
    • CWE-295 - Improper Certificate Validation.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 19 or below
    Affected: R82 with Jumbo Hotfix Take 103 or below
    Affected: R81.20 with Jumbo Hotfix Take 141 or below
    Affected: R81.10, R81, and R80.40
    Create a notification for this product.
    checkpoint Spark Firewalls Affected: R80.20.X, R81.10.X, and R82.00.X
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-50752",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-09T03:55:37.901004Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-10T13:36:24.946Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 19 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 103 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 141 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, and R80.40"
                }
              ]
            },
            {
              "product": "Spark Firewalls",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R80.20.X, R81.10.X, and R82.00.X"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295: Improper Certificate Validation.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-08T11:00:38.563Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185035"
            }
          ],
          "title": "Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-50752",
        "datePublished": "2026-06-08T11:00:38.563Z",
        "dateReserved": "2026-06-07T09:42:08.252Z",
        "dateUpdated": "2026-06-10T13:36:24.946Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48136 (GCVE-0-2026-48136)

    Vulnerability from cvelistv5 – Published: 2026-05-26 12:57 – Updated: 2026-06-02 14:17
    VLAI
    Title
    Authenticated Administrator Role-Based Access Control Bypass in Compliance
    Summary
    When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-26 18:41 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48136",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-26T18:41:27.298316Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-02T14:17:00.827Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:34.470Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184992"
            }
          ],
          "title": "Authenticated Administrator Role-Based Access Control Bypass in Compliance"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48136",
        "datePublished": "2026-05-26T12:57:29.298Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-06-02T14:17:00.827Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48135 (GCVE-0-2026-48135)

    Vulnerability from cvelistv5 – Published: 2026-05-26 12:57 – Updated: 2026-05-27 18:36
    VLAI
    Title
    HTTP service can incorrectly process malformed HTTP requests
    Summary
    A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-26 14:48 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48135",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-26T14:48:38.051261Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-27T18:36:10.600Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A Check Point HTTP-based service can incorrectly handle malformed HTTP requests.\nThe issue is related to HTTP request parsing and validation."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122: Heap-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:28.067Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184991"
            }
          ],
          "title": "HTTP service can incorrectly process malformed HTTP requests"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48135",
        "datePublished": "2026-05-26T12:57:19.074Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-05-27T18:36:10.600Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48134 (GCVE-0-2026-48134)

    Vulnerability from cvelistv5 – Published: 2026-05-26 12:57 – Updated: 2026-06-02 14:15
    VLAI
    Title
    SQL injection issue in UserCheck Portal when DLP Software Blade is active
    Summary
    When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-02 14:15 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48134",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-02T14:15:04.599414Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-02T14:15:31.285Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway\u0027s stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly.\nExposure is reduced if the UserCheck Portal is not accessible from untrusted networks."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:21.332Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184983"
            }
          ],
          "title": "SQL injection issue in UserCheck Portal when DLP Software Blade is active"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48134",
        "datePublished": "2026-05-26T12:57:07.767Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-06-02T14:15:31.285Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48133 (GCVE-0-2026-48133)

    Vulnerability from cvelistv5 – Published: 2026-05-26 12:56 – Updated: 2026-06-02 14:14
    VLAI
    Title
    Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
    Summary
    When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-02 14:14 UTC
    CWE
    • CWE-98 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48133",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-02T14:14:15.264635Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-02T14:14:24.478Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-98",
                  "description": "CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:14.984Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184993"
            }
          ],
          "title": "Identity Awareness Captive Portal - Unauthenticated Local File Inclusion"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48133",
        "datePublished": "2026-05-26T12:56:56.250Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-06-02T14:14:24.478Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48132 (GCVE-0-2026-48132)

    Vulnerability from cvelistv5 – Published: 2026-05-26 12:56 – Updated: 2026-06-02 14:09
    VLAI
    Title
    VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP
    Summary
    The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic).
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-02 14:09 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48132",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-02T14:09:04.979541Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-02T14:09:19.968Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125: Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:07.343Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184982"
            }
          ],
          "title": "VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48132",
        "datePublished": "2026-05-26T12:56:47.693Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-06-02T14:09:19.968Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48131 (GCVE-0-2026-48131)

    Vulnerability from cvelistv5 – Published: 2026-05-26 12:56 – Updated: 2026-05-26 15:18
    VLAI
    Title
    VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero
    Summary
    The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-26 15:12 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48131",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-26T15:12:47.698813Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-26T15:18:43.287Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122: Heap-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:15:50.325Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184981"
            }
          ],
          "title": "VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48131",
        "datePublished": "2026-05-26T12:56:08.817Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-05-26T15:18:43.287Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }