Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

6 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.3Check Point Exploited

Critical [CVE-2026-18574] authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

CVE-2026-18574
Security Management
Aug 3, 2026
Critical9.1Check Point

Critical [CVE-2026-62144] authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients. Affected products named by the advisory: Quantum Security Management.

CVE-2026-62144
Quantum Gateway / GaiaSecurity Management
Jul 22, 2026
Critical9.3Check Point Exploited CISA KEV

Critical [CVE-2026-16232] authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers. Affected products named by the advisory: Quantum Security Management; Multi-Domain Security Management.

CVE-2026-16232
Quantum Gateway / GaiaSecurity Management
Jul 22, 2026
Critical9.3Check Point Exploited CISA KEV

Critical [CVE-2026-50751] User Authentication Bypass in VPN Remote Access and Mobile Access

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Affected products named by the advisory: Quantum Security Gateway; Spark Firewalls.

CVE-2026-50751
Quantum Gateway / Gaia
Jun 8, 2026
Critical9.6Check Point

Critical [CVE-2023-28131] vulnerability in the expo.io framework

A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).

CVE-2023-28131
Unclassified
Apr 24, 2023
Critical9.8Check Point

Critical [CVE-2022-23747] In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.

CVE-2022-23747
Unclassified
Aug 17, 2022