CVE-2026-33920Cross-site request forgery in the Guardian/CMC login before 26.3.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 09/08/2026 Severity Medium CVE-2026-33391Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 09/08/2026 Severity Medium CVE-2026-33389Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 09/08/2026 Severity Medium CVE-2026-33388Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 09/08/2026 Severity Medium CVE-2026-33387Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 09/08/2026 Severity Medium CVE-2026-33922Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0 Exploitation status Not known exploited Fix YesAffected product A Arc Published 08/11/2026 Severity Medium CVE-2026-33921Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0 Exploitation status Not known exploited Fix YesAffected product A Arc Published 08/11/2026 Severity Medium CVE-2026-33390Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 07/09/2026 Severity High CVE-2026-31985Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0 Exploitation status Not known exploited Fix YesAffected product R Remote Collector Published 07/09/2026 Severity High CVE-2026-31984DoS through oversized audit log entries in Guardian/CMC before 26.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 07/09/2026 Severity High CVE-2026-31983Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 07/09/2026 Severity Medium CVE-2026-31982Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 07/09/2026 Severity Medium CVE-2026-31981HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 07/09/2026 Severity Medium CVE-2025-40904HTML injection in Smart Polling in Guardian/CMC before 26.1.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 05/19/2026 Severity Medium CVE-2025-40903HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 05/19/2026 Severity Medium CVE-2025-40902HTML injection in Users in Guardian/CMC before 26.1.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 05/19/2026 Severity Medium CVE-2025-40901HTML injection in Credentials Manager in Guardian/CMC before 26.1.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 05/19/2026 Severity Medium CVE-2025-40900Angular template injection in Reports in Guardian/CMC before 26.1.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 05/19/2026 Severity Medium CVE-2025-40899Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 04/15/2026 Severity High CVE-2025-40897Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 04/15/2026 Severity High CVE-2025-40896Lack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.0 Exploitation status Not known exploited Fix YesAffected product A Arc Published 03/04/2026 Severity Medium CVE-2025-40895HTML injection in Sensor Map in CMC before 25.6.0 Exploitation status Not known exploited Fix YesAffected product C CMC Published 03/04/2026 Severity Low CVE-2025-40894HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 03/04/2026 Severity Low CVE-2025-40898Path traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 12/18/2025 Severity High CVE-2025-40893HTML injection in Asset List in Guardian/CMC before 25.5.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 12/18/2025 Severity Medium CVE-2025-40892Stored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 12/18/2025 Severity High CVE-2025-40891HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 12/18/2025 Severity Low CVE-2025-40890Stored Cross-Site Scripting (XSS) in Dashboards in Guardian/CMC before 25.4.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 11/25/2025 Severity Medium CVE-2025-40888Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 10/07/2025 Severity Medium CVE-2025-40889Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 10/07/2025 Severity High CVE-2025-40887Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 10/07/2025 Severity Medium CVE-2025-40886Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 10/07/2025 Severity High CVE-2025-40885Authenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 10/07/2025 Severity Medium CVE-2025-3719Incorrect authorization for CLI in Guardian/CMC before 25.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 10/07/2025 Severity High CVE-2025-3718Client-side path traversal in Guardian/CMC before 25.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 10/07/2025 Severity Medium CVE-2025-1501Incorrect authorization for traces request/download in CMC before 25.1.0 Exploitation status Not known exploited Fix YesAffected product C CMC Published 08/26/2025 Severity Medium CVE-2024-13090Privilege escalation in Guardian/CMC before 24.6.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 06/10/2025 Severity High CVE-2024-13089Authenticated RCE in update functionality in Guardian/CMC before 24.6.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 06/10/2025 Severity High CVE-2024-4465Incorrect authorization for Reports configuration in Guardian/CMC before 24.2.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 09/11/2024 Severity Medium CVE-2023-5938Path traversal via 'zip slip' in Arc before v1.6.0 Exploitation status Not known exploited Fix YesAffected product A Arc Published 05/15/2024 Severity High CVE-2023-5937Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0 Exploitation status Not known exploited Fix YesAffected product A Arc Published 05/15/2024 Severity Medium CVE-2023-5936Unsafe temporary data privileges on Unix systems in Arc before v1.6.0 Exploitation status Not known exploited Fix YesAffected product A Arc Published 05/15/2024 Severity High CVE-2023-5935Missing authentication for local web interface in Arc before v1.6.0 Exploitation status Not known exploited Fix YesAffected product A Arc Published 05/15/2024 Severity High CVE-2024-0218DoS on IDS parsing of malformed Radius packets in Guardian before 23.4.1 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 04/10/2024 Severity High CVE-2023-6916Information disclosure via audit records for OpenAPI requests in Guardian/CMC before 23.4.1 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 04/10/2024 Severity High CVE-2023-5253Check Point IoT integration: WebSocket returns assets data without authentication in Guardian/CMC before 23.3.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 01/15/2024 Severity Medium CVE-2023-32649DoS on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 09/19/2023 Severity High CVE-2023-29245SQL Injection on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 09/19/2023 Severity Critical CVE-2023-2567Authenticated SQL Injection on Query functionality in Guardian/CMC before 22.6.3 and 23.1.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 09/19/2023 Severity High CVE-2023-23903DoS via SAML configuration in Guardian/CMC before 22.6.2 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 08/09/2023 Severity Medium CVE-2023-24015Partial DoS on Reports section due to null report name in Guardian/CMC before 22.6.2 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 08/09/2023 Severity Medium CVE-2023-24471Information disclosure via the debug function in assertions in Guardian/CMC before 22.6.2 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 08/09/2023 Severity High CVE-2023-22843Stored Cross-Site Scripting (XSS) in Threat Intelligence rules in Guardian/CMC before 22.6.2 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 08/09/2023 Severity High CVE-2023-23574Authenticated Blind SQL Injection on alerts count in Guardian/CMC before 22.6.2 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 08/09/2023 Severity High CVE-2023-22378Authenticated Blind SQL Injection on sorting in Guardian/CMC before 22.6.2 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 08/09/2023 Severity High CVE-2023-24477Session Fixation in Guardian/CMC before 22.6.2 Exploitation status Not confirmed Fix YesAffected product G Guardian Published 08/09/2023 Severity Medium CVE-2022-4259Authenticated SQL Injection on Alerts in Guardian/CMC before 22.5.2 Exploitation status Not known exploited Fix YesAffected product C CMC Published 05/04/2023 Severity High CVE-2022-0551Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 03/24/2022 Severity High CVE-2022-0550Authenticated RCE on logo report upload in Guardian/CMC before 22.0.0 Exploitation status Not confirmed Fix YesAffected product G Guardian Published 03/24/2022 Severity High CVE-2021-26724Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4 Exploitation status Not confirmed Fix YesAffected product G Guardian Published 02/22/2021 Severity High CVE-2021-26725Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4 Exploitation status Not known exploited Fix YesAffected product G Guardian Published 02/22/2021 Severity High