Vulnerabilities

Summary — last 7 days

New vulnerabilities3,335▲ 417 vs. last week
Critical / high1,494▲ 172 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)579▲ 105 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisCritical (9.8)3.7%—Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI9/9/20269/10/2026
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
AnalyzedHigh (8.6)100%⚠ Active exploitationCheckpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security5/28/20248/5/2026
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
ModifiedMedium (5.9)64%—OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+1023/25/20216/17/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…