Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4609 articles · 179960 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-48135EXPLOITED
check point · check point http-based

HTTP service can incorrectly process malformed HTTP requests

Description

A remote, anonymous attacker can exploit a vulnerability in Check Point Security Gateway to conduct a Denial of Service attack.

Affected Products

VendorProductVersions
check pointcheck point http-basedR82.10 with Jumbo Hotfix Take 6 or below, R82 with Jumbo Hotfix Take 91 or below, R81.20 with Jumbo Hotfix Take 127 or below, All releases from R81.10 and below

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointsecuritycert_advisory90%

References

  • https://support.checkpoint.com/results/sk/sk184991

Related News (3 articles)

Tier B
BSI Advisories52d ago
[NEU] [mittel] Check Point Security Gateway: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
Tier B
CERT-FR58d ago
Multiples vulnérabilités dans les produits Check Point (27 mai 2026)
→ No new info (linked only)
Tier C
VulDB58d ago
CVE-2026-48135 | Check Point Quantum Security Gateway HTTP-based Service heap-based overflow
→ No new info (linked only)
CVSS 3.15.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-122
PublishedMay 26, 2026
Last enriched52d agov3
Tags
Denial of Service
Trending Score0
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 114
HIGHCVE-2026-10847EXP
Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS
HIGHCVE-2026-48132
VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP
HIGHCVE-2026-48133EXP
Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
MEDIUMCVE-2026-48134EXP
SQL injection issue in UserCheck Portal when DLP Software Blade is active

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 26, 2026
Discovered by ZDM
May 26, 2026
Updated: description, severity, activelyExploited
May 26, 2026
Actively Exploited
May 27, 2026
Exploit Available
May 27, 2026
Updated: description, severity, exploitAvailable, tags
Jun 1, 2026

Version History

v3
Last enriched 52d ago
v3Tier B52d ago

Updated description with details about the Denial of Service attack and changed severity to HIGH.

descriptionseverityexploitAvailabletags
via BSI Advisories
v2Tier C58d ago

Updated severity to CRITICAL, added new description detailing heap-based buffer overflow, and marked the vulnerability as actively exploited.

descriptionseverityactivelyExploited
via VulDB
v158d ago

Initial creation