Check Point Security Advisories & CVEs
26 advisories tracked · Check Point (cve@checkpoint.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Check Point CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Check Point device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Check Point's recent advisories.
Official source
Check Point (cve@checkpoint.com CNA) via NVD
Check Point is its own CVE Numbering Authority. VulniPulse ingests Check Point's CVEs from the NVD CNA feed (cve@checkpoint.com), each linking to its support.checkpoint.com advisory. Covers Quantum Security Gateway / Spark, the Gaia OS, Quantum Maestro, Harmony Endpoint / Mobile, CloudGuard and the Security Management server — its Quantum VPN/gateways were mass-exploited (CVE-2024-24919), a top network-security target.
Latest Check Point advisories
High [CVE-2026-62145] vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. Affected products named by the advisory: Quantum Security Gateway; Quantum Security Management.
High [CVE-2026-10847] local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS
A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint.
High [CVE-2026-50752] Check Point: weakness in the certificate validation logic of the deprecated IKEv1 key exchange may
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel. Affected product named by the advisory: Check Point.
High [CVE-2026-48133] Check Point: When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user
When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. Affected product named by the advisory: Check Point.
High [CVE-2026-48132] Check Point: The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP).
The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic). Affected product named by the advisory: Check Point.
High [CVE-2026-48131] Check Point: The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a…
The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality). Affected product named by the advisory: Check Point.
High [CVE-2025-9142] local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory
A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory.
High [CVE-2025-3831] Harmony: Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
High [CVE-2024-24914] Gaia: Authenticated Gaia users can inject code or commands by global variables through special HTTP requests.
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.
High [CVE-2024-24919] Information disclosure
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. Affected product named by the advisory: Check Point Quantum Gateway, Spark Gateway and CloudGuard Network.
High [CVE-2024-24910] local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows…
A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.
High [CVE-2023-28134] Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security
Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
High [CVE-2023-28130] Gaia: Local user may lead to privilege escalation using Gaia Portal hostnames page.
Local user may lead to privilege escalation using Gaia Portal hostnames page.
High [CVE-2023-28133] Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
High [CVE-2022-23746] The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX).
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.
High [CVE-2022-23748] mDNSResponder.exe is vulnerable to DLL Sideloading attack.
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.
High [CVE-2022-23745] potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).
A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could result in application crashing but could not be used to gather any sensitive information.
High [CVE-2020-0896 +1] Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory…
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.
High [CVE-2022-23743] Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process
Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory allow a local attacker the ability to execute an arbitrary file write, leading to execution of code as local system, in ZoneAlarm versions before v15.8.211.192119
High [CVE-2021-30360] Users have access to the directory where the installation repair occurs.
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote Access Client privileges.