CVE-2026-12974
Awaiting Analysis
Awaiting Analysis - Queue
Security Policy Bypass in Forcepoint Security Engine NGFW
Vulnerability report for CVE-2026-12974, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-23
Last updated on: 2026-09-23
Assigner: Forcepoint
Description
Description
A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).
This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| forcepoint | security_engine | From 7.1.0 (inc) to 7.1.13 (inc) |
| forcepoint | security_engine | From 7.3.0 (inc) to 7.3.1 (inc) |
| forcepoint | security_engine | 7.3.3 |
| forcepoint | security_engine | From 7.4.0 (inc) to 7.4.1 (inc) |
| forcepoint | security_engine | 7.5.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1284 | The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties. |
| CWE-183 | The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses. |