Vendor
Check Point vulnerabilities
43 advisories tracked, 5 exploited in the wild according to CISA, 18 published in 2026.
Data refreshed 10 Oct 2026
Patch now
Exploited in the last two years (CISA KEV), or a 10%+ chance of exploitation in the next 30 days (EPSS).
CVE-2026-93616Security Management and SmartConsole
Directory Traversal and File upload allows execution of arbitrary script on the Management ServerCVE-2026-85102Quantum Security Gateway
Improper Certificate Validation in Quantum Security GatewayCVE-2026-16232Security Management and SmartConsole
Authentication Bypass in the SmartConsole Login Process Using an Application TokenCVE-2026-50751Quantum Security Gateway
User Authentication Bypass in VPN Remote Access and Mobile AccessCVE-2023-28130Quantum Security Gateway
Local user may lead to privilege escalation using Gaia Portal hostnames page.CVE-2022-23745Harmony Endpoint and VPN clients
A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).
Products covered
Select a product to see only its advisories.
- Quantum Security GatewayFirewalls, Gaia OS, Remote Access and Mobile Access VPN18 tracked
- Security Management and SmartConsoleManagement server, Multi-Domain and SmartConsole13 tracked
- Harmony Endpoint and VPN clientsEndpoint security, Remote Access VPN client and ZoneAlarm12 tracked
- Harmony SASE, Email and other productsHarmony SASE, Email & Collaboration, Browse, Mobile, CloudGuard4 tracked
All tracked advisories
Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.
| Published | CVE | Product | Issue | Severity | EPSS | Exploited |
|---|---|---|---|---|---|---|
| CVE-2026-93616Full analysis | Security Management and SmartConsole | Directory Traversal and File upload allows execution of arbitrary script on the Management Server | CRITICAL 9.8 | 20% | Yes | |
| CVE-2026-91843 | Security Management and SmartConsole | Stack overflow in login process to the Security Management and Log Servers | CRITICAL 9.8 | 0.52% | – | |
| CVE-2026-85103 | Quantum Security Gateway | Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding | CRITICAL 9.8 | 3.7% | – | |
| CVE-2026-85102Full analysis | Quantum Security Gateway | Improper Certificate Validation in Quantum Security Gateway | CRITICAL 9.8 | 7.5% | Yes | |
| CVE-2026-18574 | Security Management and SmartConsole | Authentication Bypass in Check Point Security Management Server | CRITICAL 9.3 | 0.89% | – | |
| CVE-2026-62145 | Quantum Security Gateway | Local Privilege Escalation in Gaia Portal | HIGH 7.5 | 0.39% | – | |
| CVE-2026-62144 | Security Management and SmartConsole | Management Authentication Bypass and Privilege Escalation | CRITICAL 9.1 | 1.0% | – | |
| CVE-2026-16232 | Security Management and SmartConsole | Authentication Bypass in the SmartConsole Login Process Using an Application Token | CRITICAL 9.3 | 78% | Yes | |
| CVE-2026-10847 | Harmony Endpoint and VPN clients | Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS | HIGH 7.8 | 0.12% | – | |
| CVE-2026-50751Full analysis | Quantum Security Gateway | User Authentication Bypass in VPN Remote Access and Mobile Access | CRITICAL 9.3 | 85% | Yes · ransomware | |
| CVE-2026-50752 | Quantum Security Gateway | Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1 | HIGH 7.4 | 0.26% | – | |
| CVE-2026-48136 | Security Management and SmartConsole | Authenticated Administrator Role-Based Access Control Bypass in Compliance | MEDIUM 4.1 | 0.26% | – | |
| CVE-2026-48135 | Quantum Security Gateway | HTTP service can incorrectly process malformed HTTP requests | MEDIUM 5.3 | 0.40% | – | |
| CVE-2026-48134 | Quantum Security Gateway | SQL injection issue in UserCheck Portal when DLP Software Blade is active | MEDIUM 5.6 | 0.25% | – | |
| CVE-2026-48133 | Quantum Security Gateway | Identity Awareness Captive Portal - Unauthenticated Local File Inclusion | HIGH 7.5 | 0.50% | – | |
| CVE-2026-48132 | Quantum Security Gateway | VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP | HIGH 8.1 | 0.40% | – | |
| CVE-2026-48131 | Quantum Security Gateway | VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero | HIGH 8.1 | 0.40% | – | |
| CVE-2025-9142 | Harmony SASE, Email and other products | Local privilege escalation in Harmony SASE Windows Agent | HIGH 7.5 | 0.08% | – | |
| CVE-2025-8305 | Harmony SASE, Email and other products | Information Disclosure in Identity Agent Debug Files | MEDIUM 6.5 | 0.12% | – | |
| CVE-2025-8304 | Harmony Endpoint and VPN clients | Information Disclosure in Identity Agent Registry Keys | MEDIUM 6.5 | 0.12% | – | |
| CVE-2025-3831 | Harmony SASE, Email and other products | Exposed SFTP server | HIGH 8.1 | 0.40% | – | |
| CVE-2024-52885 | Quantum Security Gateway | Path Traversal | MEDIUM 5 | 0.46% | – | |
| CVE-2025-2028 | Security Management and SmartConsole | Lack of TLS validation | MEDIUM 6.5 | 0.21% | – | |
| CVE-2024-24915 | Security Management and SmartConsole | SmartConsole Sensitive Credential Exposure via Memory Dump | MEDIUM 6.1 | 0.21% | – | |
| CVE-2024-24916 | Security Management and SmartConsole | DLL-HiJacking | MEDIUM 6.5 | 2.7% | – | |
| CVE-2024-52888 | Quantum Security Gateway | Stored-XSS | MEDIUM 5.4 | 0.23% | – | |
| CVE-2024-52887 | Quantum Security Gateway | Self-XSS | LOW 3.5 | 0.22% | – | |
| CVE-2024-24911 | Security Management and SmartConsole | Out of Bounds read in the CPCA process on Check Point Management Server | MEDIUM 5.3 | 0.40% | – | |
| CVE-2024-24914 | Quantum Security Gateway | Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. | HIGH 8 | 0.41% | – | |
| CVE-2024-6233 | Harmony Endpoint and VPN clients | Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability | HIGH 7.8 | 0.40% | – | |
| CVE-2024-24919 | Quantum Security Gateway | Quantum Security Gateways Information Disclosure | HIGH 8.6 | 100% | Yes · ransomware | |
| CVE-2024-24912 | Harmony Endpoint and VPN clients | Local privilege escalation in Harmony Endpoint Security Client for Windows via crafted DLL file | MEDIUM 6.7 | 0.16% | – | |
| CVE-2024-24910 | Harmony Endpoint and VPN clients | LocalprivilegeescalationinCheckPointZoneAlarmExtremeSecurityNextGen,IdentityAgentforWindows,andIdentityAgentforWindowsTerminalServerviacraftedDLLfile | HIGH 7.3 | 0.15% | – | |
| CVE-2023-28134 | Harmony Endpoint and VPN clients | Local Privliege Escalation in Check Point Endpoint Security Remediation Service | HIGH 7.8 | 0.24% | – | |
| CVE-2023-28130 | Quantum Security Gateway | Local user may lead to privilege escalation using Gaia Portal hostnames page. | HIGH 7.2 | 21% | – | |
| CVE-2023-28133 | Harmony Endpoint and VPN clients | Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL con… | – | 5.7% | – | |
| CVE-2022-23746 | Quantum Security Gateway | The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). | HIGH 7.5 | 0.63% | – | |
| CVE-2022-23745 | Harmony Endpoint and VPN clients | A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). | – | 17% | – | |
| CVE-2022-23744 | Harmony Endpoint and VPN clients | Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed… | – | 4.6% | – | |
| CVE-2022-23742 | Harmony Endpoint and VPN clients | Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics repo… | HIGH 7.8 | 4.2% | – | |
| CVE-2021-30361 | Quantum Security Gateway | The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI… | – | 4.5% | – | |
| CVE-2022-23743 | Harmony Endpoint and VPN clients | Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the… | – | 0.42% | – | |
| CVE-2021-30360 | Harmony Endpoint and VPN clients | Users have access to the directory where the installation repair occurs. | – | 0.57% | – |
Sources: Check Point security advisories, CISA KEV and FIRST EPSS. Severity is the vendor's own rating.