Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Forcepoint

First CVE: Nov 23, 2004Active for: 22 yearsTotal CVEs: 29
32.7
VTI Score
Medium

Forcepoint develops security-focused network and endpoint protection products spanning email filtering, web gateways, cloud security, firewalls, and endpoint detection, serving organizations that rely on these defenses to control data and traffic flows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in gateway and filtering appliances where authentication bypass, access control flaws, and input-validation weaknesses can expose protected assets directly. The recurring weakness classes—cross-site scripting, authorization failures, and XML entity injection—reflect the parsing and privilege-boundary demands of products that sit between users and protected resources. Defenders should treat disclosures affecting this vendor's gateways and filtering tier as high-priority despite modest disclosure volume, as flaws in these choke-point appliances carry outsized impact on network perimeter security. Current exploitation activity, severity detail, and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Forcepoint over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2004
21 years ago
Most Recent CVE
Jun 4, 2026
50 days ago

Self-Reporting Analysis

Of all the CVEs published by Forcepoint as a CNA, 96.4% affect products that Forcepoint develops as a vendor.

96.4%
Self-reported: 27 (96.4%)
Third-party: 1 (3.6%)

Of all the CVEs published that affect products developed by Forcepoint, 93.1% are self-published by Forcepoint as a CNA.

93.1%
Self-published: 27 (93.1%)
Other CNAs: 2 (6.9%)

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-12694HIGH
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Clie
Jun 4, 20267.832NONO
CVE-2022-1700CRITICAL
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One
Sep 12, 20229.831NONO
CVE-2019-6146MEDIUM
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:
Jan 22, 20206.131NOYES
CVE-2019-6140CRITICAL
A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not complete
Apr 9, 20199.830NONO
CVE-2018-16530CRITICAL
A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process creating a denial-of-service. Whi
Apr 9, 20199.830NONO
CVE-2018-16529CRITICAL
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has
Mar 28, 20199.829NONO
CVE-2023-6452CRITICAL
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS. The Forc
Aug 22, 20249.628NONO
CVE-2019-6143CRITICAL
Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vulnerability that potentially all
Aug 20, 20199.128NONO
CVE-2025-14026HIGH
Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library. ctypes is a fore
Jan 6, 20267.827NONO
CVE-2023-2080CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway,
Jun 15, 20239.827NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
52%
21%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (24.1%)
Network21 (72.4%)
Unknown1 (3.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (93.1%)
High1 (3.4%)
Unknown1 (3.4%)
User Interaction
None18 (62.1%)
Unknown1 (3.4%)
Required10 (34.5%)
Privileges Required
Low5 (17.2%)
High3 (10.3%)
None20 (69.0%)
Unknown1 (3.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Forcepoint.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Forcepoint — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Forcepoint's Products

View all 3 CNAs →

Top CWEs