Check Point Software Ltd. develops widely deployed security infrastructure spanning firewalls, endpoint protection, and VPN solutions that occupy critical positions in network perimeters and access control worldwide. The vendor's vulnerability disclosures are moderate in volume but include a prominent tendency toward public exploit availability, reflecting the high visibility and attacker interest in security appliances. The recurring exposure concentrates in flagship products such as Firewall-1 and VPN-1, with a notable pattern of weaknesses in resource-permission assignment, process control, and symlink/path-traversal issues characteristic of systems that require elevated privileges and manage sensitive access pathways. Defenders should prioritize Check Point advisories for internet-facing and critical-path deployments; current exploitation activity and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Check Point Software Ltd. over time
Of all the CVEs published by Check Point Software Ltd. as a CNA, 43.2% affect products that Check Point Software Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Check Point Software Ltd., 36.1% are self-published by Check Point Software Ltd. as a CNA.
Signals from CVEs in this vendor scope (133 CVEs).
133 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2026-50751CRITICAL A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentica | Jun 8, 2026 | 9.3 | 98 | YES | YES |
CVE-2024-24919HIGH Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Sof | May 28, 2024 | 8.6 | 98 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2026-16232CRITICAL An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to au | Jul 22, 2026 | 9.1 | 82 | YES | NO |
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
CVE-2002-1623MEDIUM The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negot | Dec 31, 2002 | 5.0 | 41 | NO | NO |
CVE-2009-1227HIGH NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote attackers to cause a denial of ser | Apr 2, 2009 | 10.0 | 39 | NO | YES |
CVE-2021-30358HIGH Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal | Oct 19, 2021 | 7.2 | 35 | NO | NO |
CVE-2019-8452HIGH A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will g | Apr 22, 2019 | 7.8 | 35 | NO | YES |
Signals from CVEs in this vendor scope (133 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Check Point Software Ltd..
Media articles that mention a CVE ID that affects a product developed by Check Point Software Ltd. — matched by CVE ID, not by vendor name.