Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4602 articles · 179966 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-62145
checkpoint · quantum security gateway

Local Privilege Escalation in Gaia Portal

Description

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

Affected Products

VendorProductVersions
checkpointquantum security gatewayR82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30, R82.10 with Jumbo Hotfix Take 36 or below, R82 with Jumbo Hotfix Take 118 or below, R81.20 with Jumbo Hotfix Take 158 or below, R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30

References

  • https://support.checkpoint.com/results/sk/sk185153

Related News (3 articles)

Tier C
Rapid7 Blog14h ago
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
→ No new info (linked only)
Tier B
CERT-FR1d ago
Multiples vulnérabilités dans les produits Check Point (23 juillet 2026)
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-62145 | Check Point Quantum Security Gateway up to R81.10 Gaia Portal privileges management
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-269
PublishedJul 22, 2026
Last enriched1d agov2
Trending Score45
Source articles3
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-50751EXPKEV
User Authentication Bypass in VPN Remote Access and Mobile Access
Trending: 159
CRITICALCVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 113
CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 57
HIGHCVE-2026-50752
Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1
Trending: 1
HIGHCVE-2026-48131EXP
VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: severity, cvssEstimate
Jul 22, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Severity upgraded from HIGH to CRITICAL based on article's assessment; CVSS estimate adjusted from 7.5 to 9.0 to reflect 'very critical' designation.

severitycvssEstimate
via VulDB
v11d ago

Initial creation