{"record":"Check Point evidence record","url":"https://nexalign.io/vendors/check-point","vendor":{"slug":"check-point","name":"Check Point","domain":"checkpoint.com","category":"network","categoryLabel":"Network security"},"lastChecked":"2026-07-17T22:22:39.290Z","coverage":{"earliest":"2022-07-18T08:01:13.204Z","latest":"2026-07-17T22:22:39.290Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":137,"kindsOfSource":5,"attributedAdvisories":12,"knownExploited":1,"registerEntriesNotAttributable":104,"practitionerThreads":1,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":102,"latest":"2026-07-17T16:59:06.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":10,"latest":"2026-06-12T08:15:53.947Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":4,"latest":"2025-08-25T00:00:00.000Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":16,"latest":"2026-07-09T13:29:52.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":5,"latest":"2026-07-17T22:22:39.290Z"}],"advisories":{"shown":6,"total":12,"truncated":true,"fullList":"https://nexalign.io/vendors/check-point/advisories","items":[{"id":"CVE-2024-24919","description":"Check Point Quantum Security Gateways Information Disclosure Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2024-05-30T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2024-24919"]},{"id":"WID-SEC-2026-1818","description":"Affected products: Check Point Security Gateway, Check Point Remote Access VPN, Check Point Mobile Access, Check Point Spark Firewall","severity":"high","cvss":9.1,"knownExploited":false,"date":"2026-06-12T08:15:53.947Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1818"]},{"id":"WID-SEC-2026-1746","description":"Affected products: Check Point Security Gateway","severity":"medium","cvss":5.3,"knownExploited":false,"date":"2026-06-01T09:32:23.234Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1746"]},{"id":"WID-SEC-2026-1726","description":"Affected products: Check Point Security Gateway","severity":"high","cvss":8.1,"knownExploited":false,"date":"2026-05-29T08:35:32.954Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1726"]},{"id":"CVE-2026-48136","description":"When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated…","severity":"medium","cvss":4.1,"knownExploited":false,"date":"2026-05-26T12:57:29.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31823"]},{"id":"WID-SEC-2024-1743","description":"Affected products: Check Point Zone Alarm","severity":"medium","cvss":7.8,"knownExploited":false,"date":"2024-12-02T11:33:56.774Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1743"]}]},"practitionerThreads":{"shown":1,"total":1,"truncated":false,"items":[{"title":"Free CVE-2024-24919 Scanner – Check Point VPN Vulnerability","context":"Hacker News","url":"https://news.ycombinator.com/item?id=40632848","date":"2024-06-10T12:29:01.000Z"}]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Check Point Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/network-firewalls/vendor/check-point-software-tech","date":null},{"title":"What is your primary use case for Check Point NGFW?","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-check-point-ngfw","date":null},{"title":"Check Point - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Check_Point","date":null},{"title":"What is your primary use case for Check Point Antivirus?","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-check-point-antivirus","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 104 register entries mention Check Point without naming a product of Check Point as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}