Gaia OS
6 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for Gaia OS, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Gaia OS CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High1
- Medium3
Latest CVEs
The 6 most recently published vulnerabilities affecting Gaia OS.
- CVE-2026-85102Improper Certificate Validation in Quantum Security Gateway9.8
- CVE-2026-50751User Authentication Bypass in VPN Remote Access and Mobile Access9.3
- CVE-2024-24911Out of Bounds read in the CPCA process on Check Point Management Server5.3
- CVE-2024-24914Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.8.0
- CVE-2021-30361The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.6.7
- CVE-2013-7311The OSPF implementation in Check Point Gaia OS R75.X and R76 and IPSO OS 6.2 R75.X and R76 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) pack...5.4
Product grouping is registry-driven, with AI assist and human review. How it works