Forcepoint develops security-focused network and endpoint protection products spanning email filtering, web gateways, cloud security, firewalls, and endpoint detection, serving organizations that rely on these defenses to control data and traffic flows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in gateway and filtering appliances where authentication bypass, access control flaws, and input-validation weaknesses can expose protected assets directly. The recurring weakness classes—cross-site scripting, authorization failures, and XML entity injection—reflect the parsing and privilege-boundary demands of products that sit between users and protected resources. Defenders should treat disclosures affecting this vendor's gateways and filtering tier as high-priority despite modest disclosure volume, as flaws in these choke-point appliances carry outsized impact on network perimeter security. Current exploitation activity, severity detail, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Forcepoint over time
Of all the CVEs published by Forcepoint as a CNA, 96.4% affect products that Forcepoint develops as a vendor.
Of all the CVEs published that affect products developed by Forcepoint, 93.1% are self-published by Forcepoint as a CNA.
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12694HIGH A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Clie | Jun 4, 2026 | 7.8 | 32 | NO | NO |
CVE-2022-1700CRITICAL Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One | Sep 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-6146MEDIUM It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S: | Jan 22, 2020 | 6.1 | 31 | NO | YES |
CVE-2019-6140CRITICAL A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not complete | Apr 9, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-16530CRITICAL A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process creating a denial-of-service. Whi | Apr 9, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-16529CRITICAL A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has | Mar 28, 2019 | 9.8 | 29 | NO | NO |
CVE-2023-6452CRITICAL Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS.
The
Forc | Aug 22, 2024 | 9.6 | 28 | NO | NO |
CVE-2019-6143CRITICAL Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vulnerability that potentially all | Aug 20, 2019 | 9.1 | 28 | NO | NO |
CVE-2025-14026HIGH Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library. ctypes is a fore | Jan 6, 2026 | 7.8 | 27 | NO | NO |
CVE-2023-2080CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, | Jun 15, 2023 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Forcepoint.
Media articles that mention a CVE ID that affects a product developed by Forcepoint — matched by CVE ID, not by vendor name.