VDB

GCVE-110-NCSC-2026-387

GCVE-110-NCSC-2026-387
Advisory PublishedCVSS 9.8/10
Vulnetix · Advisory published September 23, 2026
Unauthenticated attackers can exploit directory traversal and file upload vulnerabilities in multiple Check Point servers, including Management and Log Servers, to upload and execute arbitrary scripts.

Weaknesses (CWE)

CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Risk Scores

CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Check Pointvers:unknown/*

References

advisory
exploit
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›