Next Generation Firewall
CVE-2026-12974: Security Policy Bypass in Forcepoint Security Engine (NGFW)
A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).
Published
ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityHIGHCVSS 4.0 7.9
EPSS0.29%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Forcepoint Security Engine (NGFW) 7.1.0 to 7.1.13 | Upgrade past 7.1.13; see the advisory |
| Forcepoint Security Engine (NGFW) 7.3.0 to 7.3.1 | Upgrade past 7.3.1; see the advisory |
| Forcepoint Security Engine (NGFW) 7.3 | See the advisory |
| Forcepoint Security Engine (NGFW) 7.4.0 to 7.4.1 | Upgrade past 7.4.1; see the advisory |
| Forcepoint Security Engine (NGFW) 7.5 | See the advisory |
| Forcepoint Security Engine (NGFW) 7.3 | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).
This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.