vciy

CVEs we hold for Checkpoint

Records whose assigning authority named Checkpoint as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-91843Stack overflow in login process to the Security Management and Log Serverscheckpoint Quantum Security Management
CVE-2026-85103Heap-based Buffer Overflow in VPN Certificate ASN.1 Decodingcheckpoint Quantum Security Management
CVE-2026-85102Improper Certificate Validation in Quantum Security Gatewaycheckpoint Quantum Security Gateway
CVE-2026-62145Local Privilege Escalation in Gaia Portalcheckpoint Quantum Security Management
CVE-2026-62144Management Authentication Bypass and Privilege Escalationcheckpoint Multi-Domain Security Management
CVE-2026-50752Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1checkpoint Spark Firewalls
CVE-2026-50751User Authentication Bypass in VPN Remote Access and Mobile Accesscheckpoint Spark Firewalls
CVE-2026-48136Authenticated Administrator Role-Based Access Control Bypass in Compliancecheckpoint Quantum Security Management
CVE-2026-48135HTTP service can incorrectly process malformed HTTP requestscheckpoint Quantum Security Gateway
CVE-2026-48134SQL injection issue in UserCheck Portal when DLP Software Blade is activecheckpoint Quantum Security Gateway
CVE-2026-48133Identity Awareness Captive Portal - Unauthenticated Local File Inclusioncheckpoint Quantum Security Gateway
CVE-2026-48132VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDPcheckpoint Quantum Security Gateway
CVE-2026-48131VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zerocheckpoint Quantum Security Gateway
CVE-2026-18574Authentication Bypass in Check Point Security Management Servercheckpoint Multi-Domain Security Management Server
CVE-2026-16232Authentication Bypass in the SmartConsole Login Process Using an Application Tokencheckpoint Multi-Domain Security Management
CVE-2026-10847Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OScheckpoint Identity Agent
CVE-2025-9142Local privilege escalation in Harmony SASE Windows Agentcheckpoint Hramony SASE
CVE-2025-8305Information Disclosure in Identity Agent Debug Filescheckpoint Identity Awareness
CVE-2025-8304Information Disclosure in Identity Agent Registry Keyscheckpoint Identity Agent
CVE-2025-3831Exposed SFTP servercheckpoint Check Point Harmony SASE
CVE-2025-2028Lack of TLS validationcheckpoint Check Point Management Log Server
CVE-2024-52888Stored-XSScheckpoint Check Point Mobile Access
CVE-2024-52887Self-XSScheckpoint Check Point Mobile Access
CVE-2024-52885Path Traversalcheckpoint Check Point Mobile Access
CVE-2024-24919Information disclosurecheckpoint Check Point Quantum Gateway, Spark Gateway and…
CVE-2024-24916DLL-HiJackingcheckpoint Check Point SmartConsole
CVE-2024-24915SmartConsole Sensitive Credential Exposure via Memory Dumpcheckpoint Check Point SmartConsole
CVE-2024-24914no title heldcheckpoint ClusterXL, Multi-Domain Security Management…
CVE-2024-24912Local privilege escalation in Harmony Endpoint Security Client for Windows via crafted DLL filecheckpoint Harmony Endpoint Security Client for Windows
CVE-2024-24911Out of Bounds read in the CPCA process on Check Point Management Servercheckpoint Multi-Domain Security Management, Quantum…
CVE-2024-24910LocalprivilegeescalationinCheckPointZoneAlarmExtremeSecurityNextGen,IdentityAgentforWindows,andIdentityAgentforWindowsTe…checkpoint ZoneAlarmExtremeSecurityNextGen,IdentityAgentforW…
CVE-2023-28134Local Privliege Escalation in Check Point Endpoint Security Remediation Servicecheckpoint Harmony Endpoint.
CVE-2022-23745no title heldn/a Checkpoint Harmony Capsule Workspace

33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.