Skip to content
VulniPulse

Check Point Security Advisories & CVEs

14 advisories tracked · Check Point (cve@checkpoint.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Check Point CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Check Point device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Check Point's recent advisories.

Official source

Check Point (cve@checkpoint.com CNA) via NVD

Check Point is its own CVE Numbering Authority. VulniPulse ingests Check Point's CVEs from the NVD CNA feed (cve@checkpoint.com), each linking to its support.checkpoint.com advisory. Covers Quantum Security Gateway / Spark, the Gaia OS, Quantum Maestro, Harmony Endpoint / Mobile, CloudGuard and the Security Management server — its Quantum VPN/gateways were mass-exploited (CVE-2024-24919), a top network-security target.

Latest Check Point advisories

Medium4.1Check Point

Medium [CVE-2026-48136] When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC)

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).

CVE-2026-48136
Unclassified
May 26, 2026
Medium5.3Check Point

Medium [CVE-2026-48135] Check Point HTTP-based service can incorrectly handle malformed HTTP requests

A Check Point HTTP-based service, such as Mobile Access Portal or Identity Awareness Portals (except for Captive Portal), can incorrectly handle malformed HTTP requests. Gaia Portal is not affected by this issue. The issue is related to HTTP request parsing and validation. The attacker can exploit this vulnerability leading to Denial of Service, HTTP header injection, or heap buffer overflow. This issue affects: R82.10 with Jumbo Hotfix Take 6 or below R82 with Jumbo Hotfix Take 91 or below R81.20 with Jumbo Hotfix Take 127 or below All releases from R81.10 and below This issue received the ID CVE-2026-48135. Affected products named by the advisory: Security Gateway; Spark Firewall (Locally Managed).

CVE-2026-48135
Quantum Gateway / Gaia
May 26, 2026
Medium5.6Check Point

Medium [CVE-2026-48134] Check Point: When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow.

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks. Affected product named by the advisory: Check Point.

CVE-2026-48134
Quantum Gateway / Gaia
May 26, 2026
Medium6.5Check Point

Medium [CVE-2025-8305] authenticated local user can obtain information that allows claiming security policy rules of another user

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files.

CVE-2025-8305
Unclassified
Dec 22, 2025
Medium6.5Check Point

Medium [CVE-2025-8304] authenticated local user can obtain information that allows claiming security policy rules of another user

An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows Registry keys for Check Point Identity Agent running on a Terminal Server.

CVE-2025-8304
Unclassified
Dec 22, 2025
Medium6.5Check Point

Medium [CVE-2025-2028] Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country…

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

CVE-2025-2028
Unclassified
Aug 6, 2025
Medium5.0Check Point

Medium [CVE-2024-52885] The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated…

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.

CVE-2024-52885
Unclassified
Aug 6, 2025
Medium6.1Check Point

Medium [CVE-2024-24915] SmartConsole: Credentials are not cleared from memory after being used.

Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

CVE-2024-24915
Security Management
Jun 29, 2025
Medium6.5Check Point

Medium [CVE-2024-24916] Untrusted DLLs in the installer's directory

Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).

CVE-2024-24916
Unclassified
Jun 19, 2025
Medium5.4Check Point

Medium [CVE-2024-52888] For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties

For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.

CVE-2024-52888
Unclassified
Apr 27, 2025
Medium5.3Check Point

Medium [CVE-2024-24911] In rare scenarios, the cpca process on the Security Management Server / Domain Management Server

In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache.

CVE-2024-24911
Quantum Gateway / GaiaSecurity Management
Feb 6, 2025
Medium6.7Check Point

Medium [CVE-2024-24912] local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10…

A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.

CVE-2024-24912
Harmony (Endpoint/Mobile)
May 1, 2024
Medium6.7Check Point

Medium [CVE-2021-30361] The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to…

The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.

CVE-2021-30361
Quantum Gateway / Gaia
May 11, 2022
Medium5.3Check Point

Medium [CVE-2021-30357] SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied

SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.

CVE-2021-30357
Unclassified
Jun 8, 2021

← All vendors