{"id":"CVE-2026-12974","title":"A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).\n\n\nThis issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.","summary":"A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).\n\n\nThis issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.","severity":"high","cvss":7.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:A","cwe":["CWE-183","CWE-1284"],"vendor":"Forcepoint","product":"Forcepoint Security Engine (NGFW)","affected":["security_engine_ngfw >= 7.1.0 <= 7.1.13","security_engine_ngfw >= 7.3.0 <= 7.3.1","security_engine_ngfw 7.3.3","security_engine_ngfw >= 7.4.0 <= 7.4.1","security_engine_ngfw 7.5.0"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T17:58:26.570","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12974","references":[{"url":"https://support.forcepoint.com/s/article/Security-Advisory-Security-Policy-Bypass-in-Forcepoint-Security-Engine-NGFW-CVE-2026-12974","label":"psirt@forcepoint.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-23T15:23:42.713648Z"},"cvssSource":"cna","ingestedAt":"2026-09-23T14:25:29.799Z","slug":"CVE-2026-12974","body":"## Overview\n\nA Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).\n\n\nThis issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":43.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}