Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Check Point

High [CVE-2026-62145] vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. Affected products named by the advisory: Quantum Security Gateway; Quantum Security Management.

CVE-2026-62145
Quantum Gateway / GaiaSecurity Management
Jul 22, 2026
High7.8Check Point

High [CVE-2026-10847] local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS

A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint.

CVE-2026-10847
Unclassified
Jun 11, 2026
Critical9.3Check Point Exploited CISA KEV

Critical [CVE-2026-50751] User Authentication Bypass in VPN Remote Access and Mobile Access

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Affected products named by the advisory: Quantum Security Gateway; Spark Firewalls.

CVE-2026-50751
Quantum Gateway / Gaia
Jun 8, 2026
High7.4Check Point

High [CVE-2026-50752] Check Point: weakness in the certificate validation logic of the deprecated IKEv1 key exchange may

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel. Affected product named by the advisory: Check Point.

CVE-2026-50752
Unclassified
Jun 8, 2026
High7.5Check Point

High [CVE-2026-48133] Check Point: When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. Affected product named by the advisory: Check Point.

CVE-2026-48133
Quantum Gateway / Gaia
May 26, 2026
High8.1Check Point

High [CVE-2026-48132] Check Point: The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP).

The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic). Affected product named by the advisory: Check Point.

CVE-2026-48132
Quantum Gateway / Gaia
May 26, 2026
High8.1Check Point

High [CVE-2026-48131] Check Point: The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a…

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality). Affected product named by the advisory: Check Point.

CVE-2026-48131
Unclassified
May 26, 2026
Medium4.1Check Point

Medium [CVE-2026-48136] When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC)

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).

CVE-2026-48136
Unclassified
May 26, 2026
Medium5.6Check Point

Medium [CVE-2026-48134] Check Point: When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow.

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks. Affected product named by the advisory: Check Point.

CVE-2026-48134
Quantum Gateway / Gaia
May 26, 2026
High7.5Check Point

High [CVE-2025-9142] local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory

A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory.

CVE-2025-9142
Harmony (Endpoint/Mobile)
Jan 14, 2026
Medium6.5Check Point

Medium [CVE-2025-8305] authenticated local user can obtain information that allows claiming security policy rules of another user

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files.

CVE-2025-8305
Unclassified
Dec 22, 2025
Medium6.5Check Point

Medium [CVE-2025-8304] authenticated local user can obtain information that allows claiming security policy rules of another user

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows Registry keys for Check Point Identity Agent running on a Terminal Server.

CVE-2025-8304
Unclassified
Dec 22, 2025
High8.1Check Point

High [CVE-2025-3831] Harmony: Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

CVE-2025-3831
Harmony (Endpoint/Mobile)
Aug 12, 2025
Medium6.5Check Point

Medium [CVE-2025-2028] Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country…

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

CVE-2025-2028
Unclassified
Aug 6, 2025
Medium5.0Check Point

Medium [CVE-2024-52885] The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated…

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.

CVE-2024-52885
Unclassified
Aug 6, 2025
Medium6.1Check Point

Medium [CVE-2024-24915] SmartConsole: Credentials are not cleared from memory after being used.

Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

CVE-2024-24915
Security Management
Jun 29, 2025
Medium6.5Check Point

Medium [CVE-2024-24916] Untrusted DLLs in the installer's directory

Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).

CVE-2024-24916
Unclassified
Jun 19, 2025
Medium5.4Check Point

Medium [CVE-2024-52888] For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties

For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.

CVE-2024-52888
Unclassified
Apr 27, 2025
Low3.5Check Point

Low [CVE-2024-52887] Authenticated end-user may set a specially crafted SNX bookmark

Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.

CVE-2024-52887
Unclassified
Apr 27, 2025
Medium5.3Check Point

Medium [CVE-2024-24911] In rare scenarios, the cpca process on the Security Management Server / Domain Management Server

In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache.

CVE-2024-24911
Quantum Gateway / GaiaSecurity Management
Feb 6, 2025