Vendor

Check Point vulnerabilities

43 advisories tracked, 5 exploited in the wild according to CISA, 18 published in 2026.

Data refreshed 10 Oct 2026

Patch now

Exploited in the last two years (CISA KEV), or a 10%+ chance of exploitation in the next 30 days (EPSS).

Products covered

Select a product to see only its advisories.

All tracked advisories

Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.

PublishedCVEProductIssueSeverityEPSSExploited
CVE-2026-93616Full analysisSecurity Management and SmartConsoleDirectory Traversal and File upload allows execution of arbitrary script on the Management ServerCRITICAL 9.820%Yes
CVE-2026-91843Security Management and SmartConsoleStack overflow in login process to the Security Management and Log ServersCRITICAL 9.80.52%–
CVE-2026-85103Quantum Security GatewayHeap-based Buffer Overflow in VPN Certificate ASN.1 DecodingCRITICAL 9.83.7%–
CVE-2026-85102Full analysisQuantum Security GatewayImproper Certificate Validation in Quantum Security GatewayCRITICAL 9.87.5%Yes
CVE-2026-18574Security Management and SmartConsoleAuthentication Bypass in Check Point Security Management ServerCRITICAL 9.30.89%–
CVE-2026-62145Quantum Security GatewayLocal Privilege Escalation in Gaia PortalHIGH 7.50.39%–
CVE-2026-62144Security Management and SmartConsoleManagement Authentication Bypass and Privilege EscalationCRITICAL 9.11.0%–
CVE-2026-16232Security Management and SmartConsoleAuthentication Bypass in the SmartConsole Login Process Using an Application TokenCRITICAL 9.378%Yes
CVE-2026-10847Harmony Endpoint and VPN clientsLocal Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OSHIGH 7.80.12%–
CVE-2026-50751Full analysisQuantum Security GatewayUser Authentication Bypass in VPN Remote Access and Mobile AccessCRITICAL 9.385%Yes · ransomware
CVE-2026-50752Quantum Security GatewayCertificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1HIGH 7.40.26%–
CVE-2026-48136Security Management and SmartConsoleAuthenticated Administrator Role-Based Access Control Bypass in ComplianceMEDIUM 4.10.26%–
CVE-2026-48135Quantum Security GatewayHTTP service can incorrectly process malformed HTTP requestsMEDIUM 5.30.40%–
CVE-2026-48134Quantum Security GatewaySQL injection issue in UserCheck Portal when DLP Software Blade is activeMEDIUM 5.60.25%–
CVE-2026-48133Quantum Security GatewayIdentity Awareness Captive Portal - Unauthenticated Local File InclusionHIGH 7.50.50%–
CVE-2026-48132Quantum Security GatewayVPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDPHIGH 8.10.40%–
CVE-2026-48131Quantum Security GatewayVPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number ZeroHIGH 8.10.40%–
CVE-2025-9142Harmony SASE, Email and other productsLocal privilege escalation in Harmony SASE Windows AgentHIGH 7.50.08%–
CVE-2025-8305Harmony SASE, Email and other productsInformation Disclosure in Identity Agent Debug FilesMEDIUM 6.50.12%–
CVE-2025-8304Harmony Endpoint and VPN clientsInformation Disclosure in Identity Agent Registry KeysMEDIUM 6.50.12%–
CVE-2025-3831Harmony SASE, Email and other productsExposed SFTP serverHIGH 8.10.40%–
CVE-2024-52885Quantum Security GatewayPath TraversalMEDIUM 50.46%–
CVE-2025-2028Security Management and SmartConsoleLack of TLS validationMEDIUM 6.50.21%–
CVE-2024-24915Security Management and SmartConsoleSmartConsole Sensitive Credential Exposure via Memory DumpMEDIUM 6.10.21%–
CVE-2024-24916Security Management and SmartConsoleDLL-HiJackingMEDIUM 6.52.7%–
CVE-2024-52888Quantum Security GatewayStored-XSSMEDIUM 5.40.23%–
CVE-2024-52887Quantum Security GatewaySelf-XSSLOW 3.50.22%–
CVE-2024-24911Security Management and SmartConsoleOut of Bounds read in the CPCA process on Check Point Management ServerMEDIUM 5.30.40%–
CVE-2024-24914Quantum Security GatewayAuthenticated Gaia users can inject code or commands by global variables through special HTTP requests.HIGH 80.41%–
CVE-2024-6233Harmony Endpoint and VPN clientsCheck Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation VulnerabilityHIGH 7.80.40%–
CVE-2024-24919Quantum Security GatewayQuantum Security Gateways Information DisclosureHIGH 8.6100%Yes · ransomware
CVE-2024-24912Harmony Endpoint and VPN clientsLocal privilege escalation in Harmony Endpoint Security Client for Windows via crafted DLL fileMEDIUM 6.70.16%–
CVE-2024-24910Harmony Endpoint and VPN clientsLocalprivilegeescalationinCheckPointZoneAlarmExtremeSecurityNextGen,IdentityAgentforWindows,andIdentityAgentforWindowsTerminalServerviacraftedDLLfileHIGH 7.30.15%–
CVE-2023-28134Harmony Endpoint and VPN clientsLocal Privliege Escalation in Check Point Endpoint Security Remediation ServiceHIGH 7.80.24%–
CVE-2023-28130Quantum Security GatewayLocal user may lead to privilege escalation using Gaia Portal hostnames page.HIGH 7.221%–
CVE-2023-28133Harmony Endpoint and VPN clientsLocal privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL con…–5.7%–
CVE-2022-23746Quantum Security GatewayThe IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX).HIGH 7.50.63%–
CVE-2022-23745Harmony Endpoint and VPN clientsA potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).–17%–
CVE-2022-23744Harmony Endpoint and VPN clientsCheck Point Endpoint before version E86.50 failed to protect against specific registry change which allowed…–4.6%–
CVE-2022-23742Harmony Endpoint and VPN clientsCheck Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics repo…HIGH 7.84.2%–
CVE-2021-30361Quantum Security GatewayThe Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI…–4.5%–
CVE-2022-23743Harmony Endpoint and VPN clientsCheck Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the…–0.42%–
CVE-2021-30360Harmony Endpoint and VPN clientsUsers have access to the directory where the installation repair occurs.–0.57%–

Sources: Check Point security advisories, CISA KEV and FIRST EPSS. Severity is the vendor's own rating.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.