Security Policy Bypass in Forcepoint Security Engine Products
CVE-2026-12974

7.9HIGH

Key Information:

Vendor

Forcepoint

Vendor
CVE Published:
23 September 2026

What is CVE-2026-12974?

A significant security policy bypass vulnerability exists within the Forcepoint Security Engine, potentially allowing unauthorized access to sensitive functionalities and data. The flaw affects several versions, including those from 7.1.0 through 7.1.13, as well as versions from 7.3.x and 7.4.x up to 7.4.1. This vulnerability emphasizes the need for immediate attention to security patches and updates to maintain the integrity of the firewall protections.

Affected Version(s)

Forcepoint Security Engine (NGFW) 7.1.0 <= 7.1.13

Forcepoint Security Engine (NGFW) 7.3.0 <= 7.3.1

Forcepoint Security Engine (NGFW) 7.3.3

References

CVSS V4

Score:
7.9
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tuukka Vainio from the University of Turku
.