Vendor

Forcepoint vulnerabilities

28 advisories tracked, 0 exploited in the wild according to CISA, 6 published in 2026.

Data refreshed 11 Oct 2026

Patch now

Exploited in the last two years (CISA KEV), or a 10%+ chance of exploitation in the next 30 days (EPSS).

Nothing from Forcepoint meets this bar right now: no CVE in CISA's exploited list, and none with a high exploitation score.

Products covered

Select a product to see only its advisories.

All tracked advisories

Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.

PublishedCVEProductIssueSeverityEPSSExploited
CVE-2026-12974Next Generation FirewallSecurity Policy Bypass in Forcepoint Security Engine (NGFW)HIGH 7.90.29%–
CVE-2026-11970Data Loss Prevention and endpointThis vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension…MEDIUM 4.80.16%–
CVE-2025-12694Next Generation FirewallLocal Privilege Escalation in VPN ClientHIGH 8.50.10%–
CVE-2025-2274Web Security and SSEStored Cross Site Scripting in Forcepoint Web SecurityMEDIUM 4.80.16%–
CVE-2025-12690Next Generation FirewallLocal Privilege Escalation in NGFW EngineHIGH 7.30.13%–
CVE-2025-14026Data Loss Prevention and endpointVulnerable Python version used in Forcepoint One DLP ClientHIGH 7.80.21%–
CVE-2025-2272Data Loss Prevention and endpointPrivilege Escalation and Arbitrary code execution in F1E EndpointHIGH 7.30.16%–
CVE-2024-9103Web Security and SSEPersistent XSS in blocked messagesMEDIUM 6.10.23%–
CVE-2024-2166Web Security and SSECross-site scripting in Email SecurityHIGH 8.80.31%–
CVE-2023-6452Web Security and SSECross-site scripting in Web SecurityCRITICAL 9.60.42%–
CVE-2023-5451Next Generation FirewallCross-site scripting in Next Generation Firewall Security Management CenterMEDIUM 6.10.31%–
CVE-2023-1705Data Loss Prevention and endpointMissing Authorization in F|One SmartEdge AgentHIGH 8.40.15%–
CVE-2023-26292Web Security and SSECross-site scripting in Web Security, Cloud Security Gateway (CSG)MEDIUM 6.10.35%–
CVE-2023-26291Web Security and SSECross-site scripting in Web Security, Cloud Security Gateway (CSG)MEDIUM 6.10.35%–
CVE-2023-26290Web Security and SSECross-site scripting in Web Security, Cloud Security Gateway (CSG)MEDIUM 6.10.35%–
CVE-2022-1700Web Security and SSEXXE in Cloud Security Gateway, Data Loss Prevention (DLP) and othersHIGH 7.50.81%–
CVE-2021-41530Next Generation FirewallForcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP ref…–0.93%–
CVE-2020-6590Web Security and SSEForcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to in…–1.0%–
CVE-2019-6146Web Security and SSEIt has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, v…–3.0%–
CVE-2019-6147Next Generation FirewallForcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 have a rare issue that…–0.70%–
CVE-2019-6142Web Security and SSEIt has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3.–0.64%–
CVE-2019-6144Data Loss Prevention and endpointThis vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04…–0.97%–
CVE-2019-6145Next Generation FirewallForcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path in Forcepoint VPN Client for Windows–0.66%–
CVE-2019-6143Next Generation FirewallForcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x bef…–1.1%–
CVE-2019-6140Web Security and SSEA configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left…–1.4%–
CVE-2018-16530Web Security and SSEA stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft maliciou…–3.4%–
CVE-2019-6139Next Generation FirewallForcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload in Forcepoint User ID (FUID) server–2.4%–
CVE-2018-16529Web Security and SSEPassword reset in Forcepoint Email Security–1.6%–

Sources: Forcepoint security advisories, CISA KEV and FIRST EPSS. Severity is the vendor's own rating.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.