24 July 2026
Reference: CVE-2026-62145
1. What is being reported?
The vulnerability lets an attacker who already has read-only access to the Check Point Gaia Portal run commands with full administrative (root) privileges. This means they can do almost anything on the system, even though they should only be able to view information.
2. What this means in plain English
If exploited, this flaw could allow a cybercriminal to take over your firewall or VPN management system, potentially exposing sensitive data or disrupting your network security. Even if you only give some users limited access, this vulnerability could let them escalate their privileges.
3. Could this affect a small business?
Small businesses using Check Point Gaia Portal for their firewall or VPN management could be at risk, especially if they allow staff or contractors to access the portal with any level of permission. Organisations not using this product are not affected.
4. What to do now
- Check if your organisation uses Check Point Gaia Portal for firewall or VPN management.
- Contact your IT provider or software supplier immediately to confirm if you are affected and to get the latest security updates or patches.
- Review who has access to the Gaia Portal and limit permissions to only those who absolutely need it.
- Monitor your systems for any unusual activity and ensure backups are up to date in case recovery is needed.
5. Ask your IT provider
Can you confirm if our Check Point Gaia Portal is affected by CVE-2026-62145 and what steps are being taken to protect us from this vulnerability?
6. Bottom line
If you use Check Point Gaia Portal, act quickly to check your exposure and apply fixes to prevent attackers from gaining full control.
Information based on CISA KEV, NVD and reputable security reporting.