Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4622 articles · 179960 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-48133EXPLOITED
check point · security

Identity Awareness Captive Portal - Unauthenticated Local File Inclusion

Description

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

Affected Products

VendorProductVersions
check pointsecurityR82.10 with Jumbo Hotfix Take 6 or below, R82 with Jumbo Hotfix Take 91 or below, R81.20 with Jumbo Hotfix Take 127 or below, All releases from R81.10 and below

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointsecuritycert_advisory90%

References

  • https://support.checkpoint.com/results/sk/sk184993

Related News (4 articles)

Tier D
Heise Security52d ago
IT-Sicherheitslösung Check Point Security Gateway ist verwundbar
→ No new info (linked only)
Tier B
BSI Advisories55d ago
[NEU] [hoch] Check Point Security Gateway: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR58d ago
Multiples vulnérabilités dans les produits Check Point (27 mai 2026)
→ No new info (linked only)
Tier C
VulDB58d ago
CVE-2026-48133 | Check Point Quantum Security Gateway Browser-based Authentication filename control
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-98
PublishedMay 26, 2026
Last enriched58d agov2
Trending Score0
Source articles4
Independent4
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 114
HIGHCVE-2026-10847EXP
Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS
HIGHCVE-2026-48132
VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP
MEDIUMCVE-2026-48134EXP
SQL injection issue in UserCheck Portal when DLP Software Blade is active
HIGHCVE-2026-48135EXP
HTTP service can incorrectly process malformed HTTP requests

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 26, 2026
Discovered by ZDM
May 26, 2026
Updated: description, activelyExploited, cweIds
May 26, 2026
Actively Exploited
Jun 2, 2026

Version History

v2
Last enriched 58d ago
v2Tier C58d ago

Updated description with technical details, marked as actively exploited, and added CWE-20.

descriptionactivelyExploitedcweIds
via VulDB
v158d ago

Initial creation