Check Point Security Advisories & CVEs
48 advisories tracked · Check Point (cve@checkpoint.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Check Point CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Check Point device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Check Point's recent advisories.
Official source
Check Point (cve@checkpoint.com CNA) via NVD
Check Point is its own CVE Numbering Authority. VulniPulse ingests Check Point's CVEs from the NVD CNA feed (cve@checkpoint.com), each linking to its support.checkpoint.com advisory. Covers Quantum Security Gateway / Spark, the Gaia OS, Quantum Maestro, Harmony Endpoint / Mobile, CloudGuard and the Security Management server — its Quantum VPN/gateways were mass-exploited (CVE-2024-24919), a top network-security target.
Latest Check Point advisories
Critical [CVE-2026-18574] authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.
Critical [CVE-2026-62144] authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients. Affected products named by the advisory: Quantum Security Management.
Critical [CVE-2026-16232] authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers. Affected products named by the advisory: Quantum Security Management; Multi-Domain Security Management.
High [CVE-2026-62145] vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. Affected products named by the advisory: Quantum Security Gateway; Quantum Security Management.
High [CVE-2026-10847] local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS
A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint.
Critical [CVE-2026-50751] User Authentication Bypass in VPN Remote Access and Mobile Access
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Affected products named by the advisory: Quantum Security Gateway; Spark Firewalls.
High [CVE-2026-50752] Check Point: weakness in the certificate validation logic of the deprecated IKEv1 key exchange may
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel. Affected product named by the advisory: Check Point.
High [CVE-2026-48133] Check Point: When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user
When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. Affected product named by the advisory: Check Point.
High [CVE-2026-48132] Check Point: The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP).
The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic). Affected product named by the advisory: Check Point.
High [CVE-2026-48131] Check Point: The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a…
The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality). Affected product named by the advisory: Check Point.
Medium [CVE-2026-48136] When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC)
When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).
Medium [CVE-2026-48135] Check Point HTTP-based service can incorrectly handle malformed HTTP requests
A Check Point HTTP-based service, such as Mobile Access Portal or Identity Awareness Portals (except for Captive Portal), can incorrectly handle malformed HTTP requests. Gaia Portal is not affected by this issue. The issue is related to HTTP request parsing and validation. The attacker can exploit this vulnerability leading to Denial of Service, HTTP header injection, or heap buffer overflow. This issue affects: R82.10 with Jumbo Hotfix Take 6 or below R82 with Jumbo Hotfix Take 91 or below R81.20 with Jumbo Hotfix Take 127 or below All releases from R81.10 and below This issue received the ID CVE-2026-48135. Affected products named by the advisory: Security Gateway; Spark Firewall (Locally Managed).
Medium [CVE-2026-48134] Check Point: When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow.
When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks. Affected product named by the advisory: Check Point.
High [CVE-2025-9142] local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory
A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory.
Medium [CVE-2025-8305] authenticated local user can obtain information that allows claiming security policy rules of another user
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files.
Medium [CVE-2025-8304] authenticated local user can obtain information that allows claiming security policy rules of another user
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows Registry keys for Check Point Identity Agent running on a Terminal Server.
High [CVE-2025-3831] Harmony: Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
Medium [CVE-2025-2028] Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country…
Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs
Medium [CVE-2024-52885] The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated…
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.
Medium [CVE-2024-24915] SmartConsole: Credentials are not cleared from memory after being used.
Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.