Search

Find a vulnerability

Search criteria

    7 vulnerabilities found for Quantum Security Management by checkpoint

    CVE-2026-93616 (GCVE-0-2026-93616)

    Vulnerability from cvelistv5 – Published: 2026-09-22 12:59 – Updated: 2026-09-23 03:55
    VLAI
    Title
    Directory Traversal and File upload allows execution of arbitrary script on the Management Server
    Summary
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 00:00 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.20 with no Jumbo Hotfix
    Affected: R82.10 with Jumbo Hotfix Take 44 or below
    Affected: R82 with Jumbo Hotfix Take 126 or below
    Affected: R81.20 with Jumbo Hotfix Take 166 or below
    Affected: R81.10 (EOS) with Jumbo Hotfix Take 190 or below
    Affected: R81 (EOS)
    Affected: R80.40 (EOS)
    Affected: R80.30 (EOS)
    Affected: R80.20 (EOS)
    Affected: R80.10 (EOS)
    Affected: R80 (EOS)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-93616",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-22",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T03:55:59.259Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory"
                ],
                "url": "https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-09-22T00:00:00.000Z",
                "value": "CVE-2026-93616 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.20 with no Jumbo Hotfix"
                },
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 44 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 126 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 166 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10 (EOS) with Jumbo Hotfix Take 190 or below"
                },
                {
                  "status": "affected",
                  "version": "R81 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.40 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.30 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.20 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.10 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80 (EOS)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027).",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T12:59:01.057Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk1000171"
            }
          ],
          "title": "Directory Traversal and File upload allows execution of arbitrary script on the Management Server",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-93616",
        "datePublished": "2026-09-22T12:59:01.057Z",
        "dateReserved": "2026-09-18T11:08:38.818Z",
        "dateUpdated": "2026-09-23T03:55:59.259Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91843 (GCVE-0-2026-91843)

    Vulnerability from cvelistv5 – Published: 2026-09-16 13:03 – Updated: 2026-09-17 11:39
    VLAI
    Title
    Stack overflow in login process to the Security Management and Log Servers
    Summary
    A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 03:56 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 44 or below
    Affected: R82 with Jumbo Hotfix Take 126 or below
    Affected: R81.20 with Jumbo Hotfix Take 166 or below
    Affected: R81.10 (EOS) with Jumbo Hotfix Take 190 or below
    Affected: R81 (EOS)
    Affected: R80.40 (EOS)
    Affected: R80.30 (EOS)
    Affected: R80.20 (EOS)
    Affected: R80.10 (EOS)
    Affected: R80 (EOS)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91843",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T03:56:52.301574Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T11:39:25.299Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 44 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 126 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 166 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10 (EOS) with Jumbo Hotfix Take 190 or below"
                },
                {
                  "status": "affected",
                  "version": "R81 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.40 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.30 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.20 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80.10 (EOS)"
                },
                {
                  "status": "affected",
                  "version": "R80 (EOS)"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:03:40.553Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk1000155"
            }
          ],
          "title": "Stack overflow in login process to the Security Management and Log Servers",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-91843",
        "datePublished": "2026-09-16T13:03:40.553Z",
        "dateReserved": "2026-09-15T08:30:18.206Z",
        "dateUpdated": "2026-09-17T11:39:25.299Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-85103 (GCVE-0-2026-85103)

    Vulnerability from cvelistv5 – Published: 2026-09-09 13:00 – Updated: 2026-09-10 03:56
    VLAI
    Title
    Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
    Summary
    A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-09 00:00 UTC
    CWE
    • CWE-122 - Heap-based Buffer Overflow.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 43 or below
    Affected: R82 with Jumbo Hotfix Take 125 or below
    Affected: R81.20 with Jumbo Hotfix Take 165 or below
    Create a notification for this product.
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 43 or below
    Affected: R82 with Jumbo Hotfix Take 125 or below
    Affected: R81.20 with Jumbo Hotfix Take 165 or below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-85103",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-09T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-10T03:56:41.934Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 43 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 125 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 165 or below"
                }
              ]
            },
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 43 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 125 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 165 or below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122: Heap-based Buffer Overflow.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-09T13:00:42.088Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk1000118"
            }
          ],
          "title": "Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding",
          "x_generator": {
            "engine": "cvelib 1.8.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-85103",
        "datePublished": "2026-09-09T13:00:42.088Z",
        "dateReserved": "2026-09-03T06:38:15.701Z",
        "dateUpdated": "2026-09-10T03:56:41.934Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-62145 (GCVE-0-2026-62145)

    Vulnerability from cvelistv5 – Published: 2026-07-22 13:53 – Updated: 2026-07-24 03:56
    VLAI
    Title
    Local Privilege Escalation in Gaia Portal
    Summary
    A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 00:00 UTC
    CWE
    • CWE-269 - Improper Privilege Management.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Gateway Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-62145",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-24T03:56:05.075Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Gateway",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            },
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-22T13:57:12.312Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185153"
            }
          ],
          "title": "Local Privilege Escalation in Gaia Portal"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-62145",
        "datePublished": "2026-07-22T13:53:53.656Z",
        "dateReserved": "2026-07-13T10:24:07.648Z",
        "dateUpdated": "2026-07-24T03:56:05.075Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-62144 (GCVE-0-2026-62144)

    Vulnerability from cvelistv5 – Published: 2026-07-22 13:53 – Updated: 2026-07-24 03:56
    VLAI
    Title
    Management Authentication Bypass and Privilege Escalation
    Summary
    An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 00:00 UTC
    CWE
    • CWE-287 - Improper Authentication.
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    checkpoint Multi-Domain Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 9.1,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-62144",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-24T03:56:14.016Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            },
            {
              "product": "Multi-Domain Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients."
            }
          ],
          "metrics": [
            {
              "format": "CVSS",
              "other": {
                "content": {
                  "attackComplexity": "LOW",
                  "attackRequirements": "NONE",
                  "attackVector": "NETWORK",
                  "baseScore": 9.3,
                  "baseSeverity": "CRITICAL",
                  "privilegesRequired": "NONE",
                  "subAvailabilityImpact": "NONE",
                  "subConfidentialityImpact": "NONE",
                  "subIntegrityImpact": "NONE",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                  "version": "4.0",
                  "vulnAvailabilityImpact": "HIGH",
                  "vulnConfidentialityImpact": "HIGH",
                  "vulnIntegrityImpact": "HIGH"
                },
                "type": "CVSSv4.0"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-22T13:57:08.986Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185152"
            }
          ],
          "title": "Management Authentication Bypass and Privilege Escalation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-62144",
        "datePublished": "2026-07-22T13:53:35.969Z",
        "dateReserved": "2026-07-13T10:24:07.648Z",
        "dateUpdated": "2026-07-24T03:56:14.016Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-16232 (GCVE-0-2026-16232)

    Vulnerability from cvelistv5 – Published: 2026-07-22 13:53 – Updated: 2026-08-10 18:34
    VLAI
    Title
    Authentication Bypass in the SmartConsole Login Process Using an Application Token
    Summary
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 03:55 UTC
    CWE
    • CWE-287 - Improper Authentication.
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    checkpoint Multi-Domain Security Management Affected: R82.10 with Jumbo Hotfix Take 36 or below
    Affected: R82 with Jumbo Hotfix Take 118 or below
    Affected: R81.20 with Jumbo Hotfix Take 158 or below
    Affected: R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-16232",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T03:55:51.690584Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-07-22",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-10T18:34:01.548Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            },
            {
              "product": "Multi-Domain Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 36 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 118 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 158 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication.",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-02T07:06:06.363Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk185169"
            }
          ],
          "title": "Authentication Bypass in the SmartConsole Login Process Using an Application Token",
          "x_generator": {
            "engine": "cveClient/1.0.25"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-16232",
        "datePublished": "2026-07-22T13:53:09.830Z",
        "dateReserved": "2026-07-19T12:14:17.233Z",
        "dateUpdated": "2026-08-10T18:34:01.548Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-48136 (GCVE-0-2026-48136)

    Vulnerability from cvelistv5 – Published: 2026-05-26 12:57 – Updated: 2026-06-02 14:17
    VLAI
    Title
    Authenticated Administrator Role-Based Access Control Bypass in Compliance
    Summary
    When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-26 18:41 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    References
    Impacted products
    Vendor Product Version
    checkpoint Quantum Security Management Affected: R82.10 with Jumbo Hotfix Take 6 or below
    Affected: R82 with Jumbo Hotfix Take 91 or below
    Affected: R81.20 with Jumbo Hotfix Take 127 or below
    Affected: All releases from R81.10 and below
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-48136",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-26T18:41:27.298316Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-02T14:17:00.827Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Quantum Security Management",
              "vendor": "checkpoint",
              "versions": [
                {
                  "status": "affected",
                  "version": "R82.10 with Jumbo Hotfix Take 6 or below"
                },
                {
                  "status": "affected",
                  "version": "R82 with Jumbo Hotfix Take 91 or below"
                },
                {
                  "status": "affected",
                  "version": "R81.20 with Jumbo Hotfix Take 127 or below"
                },
                {
                  "status": "affected",
                  "version": "All releases from R81.10 and below"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-26T14:16:34.470Z",
            "orgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
            "shortName": "checkpoint"
          },
          "references": [
            {
              "url": "https://support.checkpoint.com/results/sk/sk184992"
            }
          ],
          "title": "Authenticated Administrator Role-Based Access Control Bypass in Compliance"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "897c38be-0345-43cd-b6cf-fe179e0c4f45",
        "assignerShortName": "checkpoint",
        "cveId": "CVE-2026-48136",
        "datePublished": "2026-05-26T12:57:29.298Z",
        "dateReserved": "2026-05-20T19:29:00.635Z",
        "dateUpdated": "2026-06-02T14:17:00.827Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }