Security Issue - Check Point Software
Security Advisory - July 2026 Frontier AI Security and Hardening Update
Check Point is committed to the security of its products. The security response team in Check Point is dedicated to respond to potential security problems and to make sure reports on such issues are handled properly.
Check Point provides multiple ways to communicate with the security response team:
- Contact the security response team via the security-alert@checkpoint.com mailing list. Please make sure to include as many details as possible to allow us to handle the report as efficiently as possible. You can use the Check Point PGP key to encrypt the communication.
- Fill in the below form with the report details. Pressing “Submit” will send the report to our security response team.
- Contact technical services and mention you need to report a security issue. There is no need for support contract in order to submit such report. Our technical services personnel will make sure the report is escalated to our security response team.
Submit Vulnerability Report
Program highlights
- Gold Standard Safe Harbor Adheres to Gold Standard Safe Harbor. Learn more about Gold Standard Safe Harbor
- Platform Standards Fully compliant with Platform Standards. Learn more about Platform Standards
- Top Response Efficiency This program's response efficiency is above 90%. Learn more about Top Response Efficiency
You’re about to submit a vulnerability disclosure report to Check Point. Please provide as much information as possible about the potential security issue you discovered. Detailed and accurate information will help our security team review and validate the report more efficiently. If you haven't yet, please remember to review our Security Page.
- Asset
Select the attack surface of this issue.
- A None Product Report
- Critical: https://ca.portal.checkpoint.com/
- Critical: Eligible for bounty - https://cloudinfra-gw.ca.portal.checkpoint.com/api/v2/*
- Critical: - https://cloudinfra-gw.portal.checkpoint.com/api/v1/*
- https://cloudinfra-gw.portal.checkpoint.com/api/v2/*
- https://cloudinfra-gw.portal.checkpoint.com/app/*
- https://portal.checkpoint.com
Currently selected: None
Weakness Select the type of the potential issue you have discovered. Currently selected: None
Severity (optional) Estimate the severity of this issue. Submit report without severity Submit report with severity
Severity calculation method
CVSS 4.0
The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities. Learn more about CVSS 4.0
- Score: None
- Attack Vector (AV): Network
Expand attack vector (AV) description
This metric reflects the context by which vulnerability exploitation is possible.
- Network (N): The vulnerable system is bound to the network stack and the set of possible attackers extends beyond the other options listed below.
- Adjacent (A): The vulnerable system is bound to a protocol stack, but the attack is limited at the protocol level to a logically adjacent topology.
- Local (L): The attacker exploits the vulnerability by accessing the target system locally.
- Physical (P): The attack requires the attacker to physically touch or manipulate the vulnerable system.
Attack Complexity (AC)
Low / High
Expand attack complexity (AC) description
This metric captures measurable actions that must be taken by the attacker to actively evade or circumvent existing built-in security-enhancing conditions in order to obtain a working exploit.
- Low (L): The attacker must take no measurable action to exploit the vulnerability.
- High (H): The successful attack depends on the evasion or circumvention of security-enhancing techniques in place.
Attack Requirements (AT)
None / Present
Expand attack requirements (AT) description
- None (N): The successful attack does not depend on the deployment and execution conditions of the vulnerable system.
- Present (P): The successful attack depends on the presence of specific deployment and execution conditions of the vulnerable system that enable the attack.
Privileges Required (PR)
None / Low / High
Expand privileges required (PR) description
This metric describes the level of privileges an attacker must possess prior to successfully exploiting the vulnerability.
- None (N): The attacker is unauthenticated prior to the attack.
- Low (L): The attacker requires privileges that provide basic capabilities typically limited to settings owned by a single user.
- High (H): The attacker requires administrative control over the vulnerable system.
User Interaction (UI)
None / Passive / Active
Expand user interaction (UI) description
This metric captures the requirement for a human user, other than the attacker, to participate in the successful compromise of the vulnerable system.
- None (N): The vulnerable system can be exploited without interaction from any human user.
- Passive (P): Successful exploitation requires limited interaction by the targeted user.
- Active (A): Successful exploitation requires a targeted user to perform specific interactions.
Vulnerable System Confidentiality Impact (VC)
High / Low / None
Expand vulnerable system confidentiality impact (VC) description
- High (H): Total loss of confidentiality, resulting in all information within the Vulnerable System being divulged.
- Low (L): Some loss of confidentiality; restricted information is obtained.
- None (N): No loss of confidentiality.
Vulnerable System Integrity Impact (VI)
High / Low / None
Expand vulnerable system integrity impact (VI) description
- High (H): Total loss of integrity; attacker can modify any/all files.
- Low (L): Modification possible but with limited consequences.
- None (N): No loss of integrity.
Vulnerable System Availability Impact (VA)
High / Low / None
Expand vulnerable system availability impact (VA) description
- High (H): Total loss of availability; attacker can deny access to resources.
- Low (L): Reduced performance or interruptions in resource availability.
- None (N): No impact to availability.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N
Proof of Concept
The proof of concept is the most important part of your report submission. Clear, reproducible steps will help us validate this issue as quickly as possible.
- Title*: A clear and concise title includes the type of vulnerability and the impacted asset.
- Description*: What is the vulnerability? In clear steps, how do you reproduce it?
- Impact*: What security impact can an attacker achieve?
Email Enter your email to receive updates on the status of your submission. If you want to stay anonymous, you may leave this field blank.
Submit your report
By clicking 'Submit Report', you agree to HackerOne's Terms and Conditions and acknowledge that you have read HackerOne's Code of Conduct, Privacy Policy and Disclosure Guidelines.