Security Policy Bypass in Forcepoint Security Engine (NGFW)
Published Sep 23, 2026
7.9
HIGHCVSS 4.0
EPSS 0.29%
Description
A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).
This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.
Affected products
-
Affected
- ≥ 7.1.0, ≤ 7.1.13
- ≥ 7.3.0, ≤ 7.3.1
- 7.3.3
- ≥ 7.4.0, ≤ 7.4.1
- 7.5.0
Unaffected
- 7.3.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Forcepoint | Forcepoint Security Engine (NGFW) | unaffected | Affected
Unaffected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
FlexEdge Secure SD-WAN Engine 7.1.14
Network Security Platform Security Engine 7.3.4
Network Security Platform Security Engine 7.4.2
Network Security Platform Security Engine 7.5.1
References (2)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data