Skip to content
Threat Feed

Vendor

Check Point

10 briefs RSS
high advisory

Cross-Telemetry Correlation of Endpoint and Network Security Alerts

Detection engineering logic that correlates Elastic Defend endpoint alerts with network security events from PAN-OS, FortiGate, and Suricata to identify potentially compromised hosts based on multi-source telemetry.

Elastic Defend +5 correlation multi-datasource network-security endpoint-security phishing email-security
3t
high advisory

Remote Code Execution Vulnerability in Check Point Management Products

A critical remote code execution vulnerability (CVE-2026-91843) affects multiple Check Point security management servers, allowing unauthenticated attackers to execute arbitrary code.

Log Server +5 vulnerability rce network-security
1c updated
high advisory

Critical Vulnerabilities in Check Point Security Appliances

Check Point has disclosed critical vulnerabilities, including CVE-2026-85102 and CVE-2026-85103, affecting various Security Gateway, Management Server, and Spark Firewall deployments.

Security Gateway +2 vulnerability network-security rce high-confidence-source
2t 2c
high advisory

Critical Remote Code Execution in Check Point Security Management

Check Point security management products are vulnerable to remote code execution and security policy bypass via CVE-2026-18574, affecting multiple current and legacy versions.

Multi-Domain Security Management +3
2t 1c
critical threat

Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Actively Exploited

Check Point released a critical security advisory to address CVE-2026-16232, an authentication bypass vulnerability in SmartConsole, which is actively being exploited in the wild and affects Security Management, Multi-Domain Management, Firewall, and Multi-Domain Log Server products.

exploited PoC SmartConsole +9 cve vulnerability authentication-bypass checkpoint
1t 4c 6i updated
critical threat

Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector

The Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.

www.acosol.es +46 Qilin +1 ransomware double-extortion golang agriculture food-production
2r 13t 5c 178i updated
high threat

Multiple Vulnerabilities in Check Point Security Gateway

Multiple vulnerabilities exist in Check Point Security Gateway that could be exploited by an attacker to perform a denial of service attack, disclose information, and perform a SQL injection attack.

Security Gateway vulnerability denial-of-service sql-injection information-disclosure checkpoint
2r 3t
high advisory

Multiple Vulnerabilities in Check Point Products

Multiple vulnerabilities in Check Point Security Gateways and Spark Firewalls allow for remote denial of service, data confidentiality breaches, and data integrity compromise.

Security Gateways R81.20 +4 vulnerability denial-of-service data-breach sql-injection
2r 3t 4c
high threat

VECT Ransomware Destroys Files Due to Encryption Flaw

VECT 2.0 ransomware, a RaaS offering, permanently destroys large files due to an encryption flaw, discarding decryption nonces for files above 128 KB, rendering them unrecoverable and effectively acting as a wiper; it uses raw ChaCha20-IETF with no authentication.

ESXi +3 TeamPCP ransomware wiper raas
2r 1t
high advisory

Elastic Defend and Email Alerts Correlation

This rule correlates Elastic Defend alerts with email security alerts by target username, potentially indicating a successful phishing attack and subsequent endpoint compromise.

Check Point Harmony Email & Collaboration threat-detection phishing endpoint email
2r 1t