Vendor
Forcepoint vulnerabilities
28 advisories tracked, 0 exploited in the wild according to CISA, 6 published in 2026.
Data refreshed 11 Oct 2026
Patch now
Exploited in the last two years (CISA KEV), or a 10%+ chance of exploitation in the next 30 days (EPSS).
Nothing from Forcepoint meets this bar right now: no CVE in CISA's exploited list, and none with a high exploitation score.
Products covered
Select a product to see only its advisories.
All tracked advisories
Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.
| Published | CVE | Product | Issue | Severity | EPSS | Exploited |
|---|---|---|---|---|---|---|
| CVE-2026-12974 | Next Generation Firewall | Security Policy Bypass in Forcepoint Security Engine (NGFW) | HIGH 7.9 | 0.29% | – | |
| CVE-2026-11970 | Data Loss Prevention and endpoint | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension… | MEDIUM 4.8 | 0.16% | – | |
| CVE-2025-12694 | Next Generation Firewall | Local Privilege Escalation in VPN Client | HIGH 8.5 | 0.10% | – | |
| CVE-2025-2274 | Web Security and SSE | Stored Cross Site Scripting in Forcepoint Web Security | MEDIUM 4.8 | 0.16% | – | |
| CVE-2025-12690 | Next Generation Firewall | Local Privilege Escalation in NGFW Engine | HIGH 7.3 | 0.13% | – | |
| CVE-2025-14026 | Data Loss Prevention and endpoint | Vulnerable Python version used in Forcepoint One DLP Client | HIGH 7.8 | 0.21% | – | |
| CVE-2025-2272 | Data Loss Prevention and endpoint | Privilege Escalation and Arbitrary code execution in F1E Endpoint | HIGH 7.3 | 0.16% | – | |
| CVE-2024-9103 | Web Security and SSE | Persistent XSS in blocked messages | MEDIUM 6.1 | 0.23% | – | |
| CVE-2024-2166 | Web Security and SSE | Cross-site scripting in Email Security | HIGH 8.8 | 0.31% | – | |
| CVE-2023-6452 | Web Security and SSE | Cross-site scripting in Web Security | CRITICAL 9.6 | 0.42% | – | |
| CVE-2023-5451 | Next Generation Firewall | Cross-site scripting in Next Generation Firewall Security Management Center | MEDIUM 6.1 | 0.31% | – | |
| CVE-2023-1705 | Data Loss Prevention and endpoint | Missing Authorization in F|One SmartEdge Agent | HIGH 8.4 | 0.15% | – | |
| CVE-2023-26292 | Web Security and SSE | Cross-site scripting in Web Security, Cloud Security Gateway (CSG) | MEDIUM 6.1 | 0.35% | – | |
| CVE-2023-26291 | Web Security and SSE | Cross-site scripting in Web Security, Cloud Security Gateway (CSG) | MEDIUM 6.1 | 0.35% | – | |
| CVE-2023-26290 | Web Security and SSE | Cross-site scripting in Web Security, Cloud Security Gateway (CSG) | MEDIUM 6.1 | 0.35% | – | |
| CVE-2022-1700 | Web Security and SSE | XXE in Cloud Security Gateway, Data Loss Prevention (DLP) and others | HIGH 7.5 | 0.81% | – | |
| CVE-2021-41530 | Next Generation Firewall | Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP ref… | – | 0.93% | – | |
| CVE-2020-6590 | Web Security and SSE | Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to in… | – | 1.0% | – | |
| CVE-2019-6146 | Web Security and SSE | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, v… | – | 3.0% | – | |
| CVE-2019-6147 | Next Generation Firewall | Forcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 have a rare issue that… | – | 0.70% | – | |
| CVE-2019-6142 | Web Security and SSE | It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3. | – | 0.64% | – | |
| CVE-2019-6144 | Data Loss Prevention and endpoint | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04… | – | 0.97% | – | |
| CVE-2019-6145 | Next Generation Firewall | Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path in Forcepoint VPN Client for Windows | – | 0.66% | – | |
| CVE-2019-6143 | Next Generation Firewall | Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x bef… | – | 1.1% | – | |
| CVE-2019-6140 | Web Security and SSE | A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left… | – | 1.4% | – | |
| CVE-2018-16530 | Web Security and SSE | A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft maliciou… | – | 3.4% | – | |
| CVE-2019-6139 | Next Generation Firewall | Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload in Forcepoint User ID (FUID) server | – | 2.4% | – | |
| CVE-2018-16529 | Web Security and SSE | Password reset in Forcepoint Email Security | – | 1.6% | – |
Sources: Forcepoint security advisories, CISA KEV and FIRST EPSS. Severity is the vendor's own rating.