Description
A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).


This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.
Published: 2026-09-23
Score: 7.9 High
EPSS: n/a
KEV: No
Impact: Security Policy Bypass
Action: Apply Patch
AI Analysis

Impact

A security policy bypass flaw allows an attacker to circumvent configured firewall rules, potentially granting unauthorized network access. The vulnerability falls under CWE‑1284 and may also involve CWE‑183 mechanisms, indicating that manipulated inputs could lead to configuration or command processing errors.

Affected Systems

Forcepoint Security Engine (NGFW) machines running versions 7.1.0 through 7.1.13, 7.3.0 through 7.3.1, 7.3.3, 7.4.0 through 7.4.1, and 7.5.0 are vulnerable. The vendor recommends upgrading to the latest supported firmware such as FlexEdge Secure SD‑WAN Engine 7.1.14 or Network Security Platform Security Engine 7.3.4, 7.4.2, or 7.5.1.

Risk and Exploitability

The CVSS score of 7.9 denotes a high impact on confidentiality, integrity, and availability, enabling attackers to bypass network security controls. No EPSS data is available, so the exploitation probability remains undetermined, and the vulnerability is not listed in CISA's KEV catalog. Although the official description does not detail the attack vector, it is inferred that the flaw can be triggered remotely via crafted traffic sent to the NGFW.

Generated by OpenCVE AI on September 23, 2026 at 14:58 UTC.

Remediation

Vendor Solution

FlexEdge Secure SD-WAN Engine 7.1.14


OpenCVE Recommended Actions

  • Upgrade Forcepoint Security Engine to firmware version 7.1.14, 7.3.4, 7.4.2, or 7.5.1 as applicable.
  • Restart the device after the firmware update to ensure the new policies are applied.
  • Verify that all security policies are enabled and correctly configured after the upgrade.

Generated by OpenCVE AI on September 23, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.
Title Security Policy Bypass in Forcepoint Security Engine (NGFW)
First Time appeared Forcepoint
Forcepoint forcepoint Security Engine Ngfw
Weaknesses CWE-1284
CWE-183
CPEs cpe:2.3:a:forcepoint:forcepoint_security_engine_ngfw_:*:*:*:*:*:*:*:*
cpe:2.3:a:forcepoint:forcepoint_security_engine_ngfw_:7.3.2:*:*:*:*:*:*:*
cpe:2.3:a:forcepoint:forcepoint_security_engine_ngfw_:7.3.3:*:*:*:*:*:*:*
cpe:2.3:a:forcepoint:forcepoint_security_engine_ngfw_:7.5.0:*:*:*:*:*:*:*
Vendors & Products Forcepoint
Forcepoint forcepoint Security Engine Ngfw
References
Metrics cvssV4_0

{'score': 7.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:A'}


Subscriptions

Forcepoint Forcepoint Security Engine Ngfw
cve-icon MITRE

Status: PUBLISHED

Assigner: forcepoint

Published:

Updated: 2026-09-23T15:23:50.227Z

Reserved: 2026-06-23T10:14:07.181Z

Link: CVE-2026-12974

cve-icon Vulnrichment

Updated: 2026-09-23T15:23:46.012Z

cve-icon NVD

Status : Received

Published: 2026-09-23T14:17:06.547

Modified: 2026-09-23T16:16:40.190

Link: CVE-2026-12974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:00:06Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-183

    Permissive List of Allowed Inputs