CVE-2026-12974: Security Policy Bypass in Forcepoint Security Engine (NGFW)
Published Sep 23, 2026
·Updated
A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW).
This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.
Affected Software
1 affected component
Forcepoint Security Engine (NGFW)>=7.1.0<=7.1.13, >=7.3.0<=7.3.1, =7.3.3, >=7.4.0<=7.4.1, =7.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Forcepoint FlexEdge Secure SD-WAN Engineto a version that resolves this vulnerability.Fixed in 7.1.14 - Upgrade
Upgrade
Forcepoint Network Security Platform Security Engineto a version that resolves this vulnerability.Fixed in 7.3.4 - Upgrade
Upgrade
Forcepoint Network Security Platform Security Engineto a version that resolves this vulnerability.Fixed in 7.4.2 - Upgrade
Upgrade
Forcepoint Network Security Platform Security Engineto a version that resolves this vulnerability.Fixed in 7.5.1
Event History
Sep 23, 2026
CVE Published
via MITRE·01:27 PM
Data Sourced
via MITRE·01:27 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness