Check Point Software Technologies
checkpoint-support · A · active
https://support.checkpoint.com/results/sk/sk185222
Added 2026-08-05 as the ONE candidate source of this run. Check Point's own support/PSIRT advisory pages (sk articles), the vendor primary for the Security Management / SmartConsole management-plane CVE stream this pipeline has covered four times in three weeks (CVE-2026-16232, CVE-2026-62144/-62145, CVE-2026-18574). Until now every Check Point entry had to lean on CERT-FR/BSI restatements because the vendor page was unreadable. FETCH → https://support.checkpoint.com/results/sk/<skid> is a Next.js SPA returning only a <title> to a direct GET. The full advisory body (symptoms, affected versions, conditions, mitigation, solution, dateCreated/lastModified) is served as JSON at https://support.checkpoint.com/_next/data/<buildId>/results/sk/<skid>.json, read <buildId> from the /_next/static/<buildId>/_buildManifest.js reference in the shell HTML (2026-08-05: qfIT1FE0sMobyOnl2MXEb; it rotates on every site deploy, so re-read it, never hardcode it). CITE the human /results/sk/<skid> URL; read the body from the data route. Candidate; promote to active after 3 contributing runs. | 2026-09-11: promoted candidate -> active per state-digest sources.promotion_due (3 contributing runs, most recent 2026-09-10T0410Z-intel), per Phase 0 allocation rule 4.
Cited in 5 entries
Citation cadence
Citation days per ISO week (15 weeks of coverage span, total 5).
- CVE-2026-91843, Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8)2026-09-18
- Check Point Quantum Security Gateway / Management Server / Spark Firewall: two unauthenticated CVSS 9.8 pre-auth RCE flaws in VPN certificate processing (CVE-2026-85103 heap overflow, CVE-2026-85102 improper cert validation)2026-09-10
- CVE-2026-18574, Check Point Security Management: unauthenticated bypass of management authentication to arbitrary command execution, with no fix for seven end-of-support trains2026-08-05
- CVE-2026-16232, Check Point SmartConsole: authentication bypass to full admin, exploited in the wild (CVSS 9.1)2026-07-23
- Check Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)2026-06-09