Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4622 articles · 179960 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-10847EXPLOITEDPATCHED
check point · identity agent full

Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS

Description

A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint.

Affected Products

VendorProductVersions
check pointidentity agent fullVersions prior to 81.087.0000

References

  • https://support.checkpoint.com/results/sk/sk185052(vendor-advisory)

Related News (2 articles)

Tier B
CCCS Canada42d ago
Check Point security advisory (AV26-590)
→ No new info (linked only)
Tier C
VulDB42d ago
CVE-2026-10847 | Check Point Identity Agent prior 81.087.0000 on Windows uncontrolled search path
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://support.checkpoint.com/results/sk/sk185052
CWECWE-427, CWE-20
PublishedJun 11, 2026
Last enriched42d agov3
Trending Score0
Source articles2
Independent2
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 114
HIGHCVE-2026-48132
VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP
HIGHCVE-2026-48133EXP
Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
MEDIUMCVE-2026-48134EXP
SQL injection issue in UserCheck Portal when DLP Software Blade is active
HIGHCVE-2026-48135EXP
HTTP service can incorrectly process malformed HTTP requests

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 11, 2026
Discovered by ZDM
Jun 11, 2026
Updated: description
Jun 11, 2026
Actively Exploited
Jun 11, 2026
Exploit Available
Jun 11, 2026
Patch Available
Jun 11, 2026
Updated: exploitAvailable, activelyExploited, cweIds
Jun 11, 2026

Version History

v3
Last enriched 42d ago
v3Tier B42d ago

Updated vendor to 'Check Point', marked exploit as available, and added new CWE-20.

exploitAvailableactivelyExploitedcweIds
via CCCS Canada
v2Tier C42d ago

Updated description with new details about the uncontrolled search path and confirmed no exploit is available.

description
via VulDB
v142d ago

Initial creation