Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.3Check Point Exploited

Critical [CVE-2026-18574] authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

CVE-2026-18574
Security Management
Aug 3, 2026
Critical9.1Check Point

Critical [CVE-2026-62144] authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients. Affected products named by the advisory: Quantum Security Management.

CVE-2026-62144
Quantum Gateway / GaiaSecurity Management
Jul 22, 2026
Critical9.3Check Point Exploited CISA KEV

Critical [CVE-2026-16232] authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers. Affected products named by the advisory: Quantum Security Management; Multi-Domain Security Management.

CVE-2026-16232
Quantum Gateway / GaiaSecurity Management
Jul 22, 2026
High7.5Check Point

High [CVE-2026-62145] vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. Affected products named by the advisory: Quantum Security Gateway; Quantum Security Management.

CVE-2026-62145
Quantum Gateway / GaiaSecurity Management
Jul 22, 2026
High7.8Check Point

High [CVE-2026-10847] local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS

A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint.

CVE-2026-10847
Unclassified
Jun 11, 2026
Critical9.3Check Point Exploited CISA KEV

Critical [CVE-2026-50751] User Authentication Bypass in VPN Remote Access and Mobile Access

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Affected products named by the advisory: Quantum Security Gateway; Spark Firewalls.

CVE-2026-50751
Quantum Gateway / Gaia
Jun 8, 2026
High7.4Check Point

High [CVE-2026-50752] Check Point: weakness in the certificate validation logic of the deprecated IKEv1 key exchange may

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel. Affected product named by the advisory: Check Point.

CVE-2026-50752
Unclassified
Jun 8, 2026
High7.5Check Point

High [CVE-2026-48133] Check Point: When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. Affected product named by the advisory: Check Point.

CVE-2026-48133
Quantum Gateway / Gaia
May 26, 2026
High8.1Check Point

High [CVE-2026-48132] Check Point: The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP).

The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic). Affected product named by the advisory: Check Point.

CVE-2026-48132
Quantum Gateway / Gaia
May 26, 2026
High8.1Check Point

High [CVE-2026-48131] Check Point: The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a…

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality). Affected product named by the advisory: Check Point.

CVE-2026-48131
Unclassified
May 26, 2026
High7.5Check Point

High [CVE-2025-9142] local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory

A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory.

CVE-2025-9142
Harmony (Endpoint/Mobile)
Jan 14, 2026
High8.1Check Point

High [CVE-2025-3831] Harmony: Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

CVE-2025-3831
Harmony (Endpoint/Mobile)
Aug 12, 2025
High8.0Check Point

High [CVE-2024-24914] Gaia: Authenticated Gaia users can inject code or commands by global variables through special HTTP requests.

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

CVE-2024-24914
Quantum Gateway / Gaia
Nov 7, 2024
High8.6Check Point Exploited CISA KEV

High [CVE-2024-24919] Information disclosure

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. Affected product named by the advisory: Check Point Quantum Gateway, Spark Gateway and CloudGuard Network.

CVE-2024-24919
Quantum Gateway / GaiaCloudGuard
May 28, 2024
High7.3Check Point

High [CVE-2024-24910] local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows…

A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.

CVE-2024-24910
Unclassified
Apr 18, 2024
High7.8Check Point

High [CVE-2023-28134] Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security

Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVE-2023-28134
Harmony (Endpoint/Mobile)
Nov 12, 2023
High7.2Check Point

High [CVE-2023-28130] Gaia: Local user may lead to privilege escalation using Gaia Portal hostnames page.

Local user may lead to privilege escalation using Gaia Portal hostnames page.

CVE-2023-28130
Quantum Gateway / Gaia
Jul 26, 2023
High7.8Check Point

High [CVE-2023-28133] Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file

Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file

CVE-2023-28133
Unclassified
Jul 23, 2023
Critical9.6Check Point

Critical [CVE-2023-28131] vulnerability in the expo.io framework

A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).

CVE-2023-28131
Unclassified
Apr 24, 2023
High7.5Check Point

High [CVE-2022-23746] The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX).

The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.

CVE-2022-23746
Unclassified
Nov 30, 2022