CVE-2026-12974

Summary

A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).

This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.

Affected Software

VendorProductVersion RangeStatus
ForcepointForcepoint Security Engine (NGFW)7.1.0 <= 7.1.13affected
ForcepointForcepoint Security Engine (NGFW)7.3.0 <= 7.3.1affected
ForcepointForcepoint Security Engine (NGFW)7.3.3affected
ForcepointForcepoint Security Engine (NGFW)7.4.0 <= 7.4.1affected
ForcepointForcepoint Security Engine (NGFW)7.5.0affected
ForcepointForcepoint Security Engine (NGFW)7.3.2unaffected

Weaknesses

  • CWE-1284: CWE-1284 Improper validation of specified quantity in input
  • CWE-183: CWE-183 Permissive list of allowed inputs

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References