Check Point Software Technologies
checkpoint-support · A · candidate
https://support.checkpoint.com/results/sk/sk185222
Added 2026-08-05 as the ONE candidate source of this run. Check Point's own support/PSIRT advisory pages (sk articles) — the vendor primary for the Security Management / SmartConsole management-plane CVE stream this pipeline has covered four times in three weeks (CVE-2026-16232, CVE-2026-62144/-62145, CVE-2026-18574). Until now every Check Point entry had to lean on CERT-FR/BSI restatements because the vendor page was unreadable. FETCH → https://support.checkpoint.com/results/sk/<skid> is a Next.js SPA returning only a <title> to a direct GET. The full advisory body (symptoms, affected versions, conditions, mitigation, solution, dateCreated/lastModified) is served as JSON at https://support.checkpoint.com/_next/data/<buildId>/results/sk/<skid>.json — read <buildId> from the /_next/static/<buildId>/_buildManifest.js reference in the shell HTML (2026-08-05: qfIT1FE0sMobyOnl2MXEb; it rotates on every site deploy, so re-read it, never hardcode it). CITE the human /results/sk/<skid> URL; read the body from the data route. Candidate — promote to active after 3 contributing runs.
Cited in 3 entries
Citation cadence
Citation days per ISO week (9 weeks of coverage span, total 3).
- CVE-2026-18574 — Check Point Security Management: unauthenticated bypass of management authentication to arbitrary command execution, with no fix for seven end-of-support trains2026-08-05
- Check Point Security Management: two more CVEs in the actively-exploited SmartConsole bundle — unauth management RCE (CVE-2026-62144) and Gaia Portal root escalation (CVE-2026-62145)2026-07-25
- Check Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)2026-06-09