Skip to finding
important · Edge devices

Unauthenticated requests to Check Point's management web service can execute scripts or load Java classes.

Affects

Check Point Security Management, Log Server and Multi-Domain management products that administer enterprise security gateways.

Today's scope update pins the path to the management service on TCP port 19009: a pre-authentication traversal reaches attacker-directed script execution and arbitrary Java class loading. Check Point has published a fix.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026