Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

checkpoint — Vulnerabilities & Security Advisories 33

Browse all 33 CVE security advisories affecting checkpoint. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Checkpoint develops network security solutions including firewalls and threat prevention systems. Historically, Checkpoint products have been vulnerable to remote code execution, cross-site scripting, privilege escalation, and authentication bypass flaws. The vendor maintains 16 CVE records, with some vulnerabilities allowing unauthenticated attackers to execute arbitrary code or bypass security controls. While no major public security incidents have been widely reported, Checkpoint's complex architectures have occasionally introduced misconfiguration risks. The company regularly addresses security issues through patches, though some historical vulnerabilities remained exploitable for extended periods before fixes were deployed.

CVE ID Title CVSS Severity Published
CVE-2026-93616 Directory Traversal and File upload allows execution of arbitrary script on the Management Server — Quantum Security Management CWE-22 9.8 Critical 2026-09-22
CVE-2026-91843 Stack overflow in login process to the Security Management and Log Servers — Quantum Security Management CWE-121 9.8 Critical 2026-09-16
CVE-2026-85103 Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding — Quantum Security Gateway CWE-122 9.8 Critical 2026-09-09
CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway — Quantum Security Gateway CWE-295 9.8 Critical 2026-09-09
CVE-2026-18574 Authentication Bypass in Check Point Security Management Server — Security Management Server CWE-288 9.3 Critical 2026-08-03
CVE-2026-62145 Local Privilege Escalation in Gaia Portal — Quantum Security Gateway CWE-269 7.5 High 2026-07-22
CVE-2026-62144 Management Authentication Bypass and Privilege Escalation — Quantum Security Management CWE-287 - - 2026-07-22
CVE-2026-16232 Authentication Bypass in the SmartConsole Login Process Using an Application Token — Quantum Security Management CWE-287 9.3 Critical 2026-07-22
CVE-2026-10847 Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS — Identity Agent CWE-427 7.8 High 2026-06-11
CVE-2026-50751 User Authentication Bypass in VPN Remote Access and Mobile Access — Quantum Security Gateway CWE-287 - - 2026-06-08
CVE-2026-50752 Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1 — Quantum Security Gateway CWE-295 7.4 High 2026-06-08
CVE-2026-48136 Authenticated Administrator Role-Based Access Control Bypass in Compliance — Quantum Security Management CWE-89 4.1 Medium 2026-05-26
CVE-2026-48135 HTTP service can incorrectly process malformed HTTP requests — Quantum Security Gateway CWE-122 5.3 Medium 2026-05-26
CVE-2026-48134 SQL injection issue in UserCheck Portal when DLP Software Blade is active — Quantum Security Gateway CWE-89 5.6 Medium 2026-05-26
CVE-2026-48133 Identity Awareness Captive Portal - Unauthenticated Local File Inclusion — Quantum Security Gateway CWE-98 7.5 High 2026-05-26
CVE-2026-48132 VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP — Quantum Security Gateway CWE-125 8.1 High 2026-05-26
CVE-2026-48131 VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero — Quantum Security Gateway CWE-122 8.1 High 2026-05-26
CVE-2025-9142 Local privilege escalation in Harmony SASE Windows Agent — Hramony SASE CWE-22 7.5 High 2026-01-14
CVE-2025-8305 Information Disclosure in Identity Agent Debug Files — Identity Awareness CWE-200 6.5 Medium 2025-12-22
CVE-2025-8304 Information Disclosure in Identity Agent Registry Keys — Identity Agent CWE-200 6.5 Medium 2025-12-22
CVE-2025-3831 Exposed SFTP server — Check Point Harmony SASE CWE-200 8.1 High 2025-08-12
CVE-2024-52885 Path Traversal — Check Point Mobile Access CWE-35 5.0 Medium 2025-08-06
CVE-2025-2028 Lack of TLS validation — Check Point Management Log Server CWE-295 6.5 Medium 2025-08-06
CVE-2024-24915 SmartConsole Sensitive Credential Exposure via Memory Dump — Check Point SmartConsole CWE-316 6.1 Medium 2025-06-29
CVE-2024-24916 DLL-HiJacking — Check Point SmartConsole CWE-427 6.5 Medium 2025-06-19
CVE-2024-52888 Stored-XSS — Check Point Mobile Access CWE-79 5.4 Medium 2025-04-27
CVE-2024-52887 Self-XSS — Check Point Mobile Access CWE-79 3.5 Low 2025-04-27
CVE-2024-24911 Out of Bounds read in the CPCA process on Check Point Management Server — Multi-Domain Security Management, Quantum Security Management CWE-125 5.3 Medium 2025-02-06
CVE-2024-24914 Check Point Gaia Portal 安全漏洞 — ClusterXL, Multi-Domain Security Management, Quantum Appliances, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, Quantum Security Management CWE-914 8.0 High 2024-11-07
CVE-2024-24919 Information disclosure — Check Point Quantum Gateway, Spark Gateway and CloudGuard Network CWE-200 8.6 High 2024-05-28

This page lists every published CVE security advisory associated with checkpoint. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.