| Critical |
CVE-2026-16232: Authentication Bypass in the SmartConsole Login Process Using an Application Token |
9.3 |
2026-07-22 |
2026-07-22 |
| Critical |
CVE-2026-62144: Management Authentication Bypass and Privilege Escalation |
9.3 |
2026-07-22 |
2026-07-22 |
| High |
CVE-2026-62145: Local Privilege Escalation in Gaia Portal |
7.5 |
2026-07-22 |
2026-07-22 |
| Critical |
CVE-2026-50751: User Authentication Bypass in VPN Remote Access and Mobile Access |
9.3 |
2026-06-08 |
2026-06-09 |
| High |
CVE-2026-50752: Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1 |
7.4 |
2026-06-08 |
2026-06-09 |
| Medium |
CVE-2026-48136: Authenticated Administrator Role-Based Access Control Bypass in Compliance |
4.1 |
2026-05-26 |
2026-05-26 |
| Medium |
CVE-2026-48134: SQL injection issue in UserCheck Portal when DLP Software Blade is active |
5.6 |
2026-05-26 |
2026-05-26 |
| Medium |
CVE-2026-48135: HTTP service can incorrectly process malformed HTTP requests |
5.3 |
2026-05-26 |
2026-05-26 |
| High |
CVE-2026-48133: Identity Awareness Captive Portal - Unauthenticated Local File Inclusion |
7.5 |
2026-05-26 |
2026-05-26 |
| High |
CVE-2026-48131: VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero |
8.1 |
2026-05-26 |
2026-05-26 |