CVE-2025-12690: Local Privilege Escalation in NGFW Engine
Published Mar 11, 2026
·Updated
Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, through 7.1.10.
Affected Software
5 affected components
Forcepoint NGFW Engine<=6.10.19, <=7.3.0, <=7.2.4, <=7.1.10
Forcepoint Next Generation Firewall<6.10.20
Forcepoint Next Generation Firewall>=7.1.0<7.1.11
Forcepoint Next Generation Firewall>=7.2.0<7.2.5
Forcepoint Next Generation Firewall=7.3.0
Remediation
Information
Upgrade to versions 6.10.20, 7.1.11, 7.2.5 and 7.3.1.
Event History
Mar 11, 2026
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12690?
CVE-2025-12690 is classified as a high-severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2025-12690?
To mitigate CVE-2025-12690, update your Forcepoint NGFW Engine to the latest version that addresses this vulnerability.
3
What versions of Forcepoint NGFW Engine are affected by CVE-2025-12690?
CVE-2025-12690 affects Forcepoint NGFW Engine versions up to and including 6.10.19, 7.3.0, 7.2.4, and 7.1.10.
4
Is CVE-2025-12690 exploitable remotely?
CVE-2025-12690 requires local access to the system, making it unsuitable for remote exploitation.
5
What impact does CVE-2025-12690 have on security?
Exploitation of CVE-2025-12690 may allow an attacker to gain elevated privileges on the system, compromising security.