CVE-2026-12974
7.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:A
Summary
A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).
This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Forcepoint | Forcepoint Security Engine (NGFW) | 7.1.0 <= 7.1.13 | affected |
| Forcepoint | Forcepoint Security Engine (NGFW) | 7.3.0 <= 7.3.1 | affected |
| Forcepoint | Forcepoint Security Engine (NGFW) | 7.3.3 | affected |
| Forcepoint | Forcepoint Security Engine (NGFW) | 7.4.0 <= 7.4.1 | affected |
| Forcepoint | Forcepoint Security Engine (NGFW) | 7.5.0 | affected |
| Forcepoint | Forcepoint Security Engine (NGFW) | 7.3.2 | unaffected |
Weaknesses
- CWE-1284: CWE-1284 Improper validation of specified quantity in input
- CWE-183: CWE-183 Permissive list of allowed inputs
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.