CVE-2026-93616
- EPSS 2.42%
- Veröffentlicht 22.09.2026 12:59:01
- Zuletzt bearbeitet 23.09.2026 16:38:38
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
CVE-2026-91843
- EPSS 0.5%
- Veröffentlicht 16.09.2026 13:03:40
- Zuletzt bearbeitet 18.09.2026 19:34:36
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
CVE-2026-85103
- EPSS 0.36%
- Veröffentlicht 09.09.2026 13:00:42
- Zuletzt bearbeitet 10.09.2026 04:18:18
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
CVE-2026-62145
- EPSS 0.39%
- Veröffentlicht 22.07.2026 13:53:53
- Zuletzt bearbeitet 24.07.2026 05:16:45
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
CVE-2026-62144
- EPSS 1.01%
- Veröffentlicht 22.07.2026 13:53:35
- Zuletzt bearbeitet 24.07.2026 05:16:45
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also all...
CVE-2026-16232
- EPSS 73.3%
- Veröffentlicht 22.07.2026 13:53:09
- Zuletzt bearbeitet 10.08.2026 19:59:12
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitatio...
CVE-2026-48136
- EPSS 4.1%
- Veröffentlicht 26.05.2026 12:57:29
- Zuletzt bearbeitet 20.07.2026 20:10:00
When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain,...
CVE-2024-24911
- EPSS 0.39%
- Veröffentlicht 06.02.2025 14:15:29
- Zuletzt bearbeitet 15.10.2025 16:33:11
In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in t...
- EPSS 0.41%
- Veröffentlicht 07.11.2024 12:15:24
- Zuletzt bearbeitet 26.08.2025 16:40:18
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.