Check Point Quantum Gateway / Gaia Vulnerabilities & Security Advisories
3 advisories tracked · Check Point (cve@checkpoint.com CNA) via NVD · 1 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Check Point advisory that VulniPulse classified as Quantum Gateway / Gaia, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 1 high.
Android app · Google Play
Monitor Check Point CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Check Point (cve@checkpoint.com CNA) via NVD
Check Point is its own CVE Numbering Authority. VulniPulse ingests Check Point's CVEs from the NVD CNA feed (cve@checkpoint.com), each linking to its support.checkpoint.com advisory. Covers Quantum Security Gateway / Spark, the Gaia OS, Quantum Maestro, Harmony Endpoint / Mobile, CloudGuard and the Security Management server — its Quantum VPN/gateways were mass-exploited (CVE-2024-24919), a top network-security target.
Latest Check Point Quantum Gateway / Gaia advisories
Critical [CVE-2026-62144] authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients. Affected products named by the advisory: Quantum Security Management.
Critical [CVE-2026-16232] authentication bypass vulnerability in the Check Point SmartConsole login process
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers. Affected products named by the advisory: Quantum Security Management; Multi-Domain Security Management.