<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241972#M40384</link>
    <description>&lt;P&gt;For an official response, please check with TAC.&lt;BR /&gt;Unofficially, I don't believe these CVEs to be major issues:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2025-26465" target="_self"&gt;CVE-2025-26465&lt;/A&gt; is an ssh client vulnerability that requires an option to be explicitly set in the ssh_config file that isn't set by default. The only way to exploit this is from expert mode, which should only be given to trusted users.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://ubuntu.com/security/CVE-2025-26466" target="_self"&gt;CVE-2025-26466&lt;/A&gt; appears to be related to a version of OpenSSH we currently don't use.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2025 21:57:17 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-02-21T21:57:17Z</dc:date>
    <item>
      <title>Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241903#M40371</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;According to the recent vulnerabilities disclosed by Qualys which are CVE-2025-26465/26466 curious to know if CP products are vulnerable and if any fix is released?&lt;/P&gt;
&lt;P&gt;TIA&lt;/P&gt;
&lt;P&gt;Blason R&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 07:34:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241903#M40371</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2025-02-21T07:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241917#M40374</link>
      <description>&lt;P&gt;Please raise this with TAC otherwise monitor these repositories:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/security-advisories" target="_blank"&gt;https://support.checkpoint.com/security-advisories&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk65269" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk65269&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 09:25:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241917#M40374</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-02-21T09:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241935#M40380</link>
      <description>&lt;P&gt;I agree with Chris, best to open TAC case. Ironically enough, when I check those CVEs on support site, all I get is your post lol&lt;/P&gt;
&lt;P&gt;And FWIW, see what AI Copilot says:&lt;/P&gt;
&lt;DIV class="ai-chatbot-conversation-assistant-text css-1m564fq"&gt;
&lt;P&gt;I'm sorry, but I don't have the information on that topic. For the most accurate and up-to-date information regarding vulnerabilities and their impact on Check Point products, I recommend referring to the official Check Point support site or contacting Check Point Support directly. You can visit the support site at&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/" target="_blank"&gt;Check Point Support&lt;/A&gt;.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="ai-chatbot-references css-g9n3fs"&gt;
&lt;DIV class="css-131f8vm"&gt;Learn more:&lt;/DIV&gt;
&lt;DIV class="css-zs1iv6"&gt;
&lt;OL class="css-3yupri"&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk105284" target="_blank" rel="noopener"&gt;sk105284 - Check Point response to OpenSSL Security advisory 19 March 2015&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk170918" target="_blank" rel="noopener"&gt;sk170918 - Check Point response to FireEye red team tools leak&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk42545" target="_blank" rel="noopener"&gt;sk42545 - Check Point response to Vulnerabilities in Visual Studio Active Template Library (MS09-035)&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk162212" target="_blank" rel="noopener"&gt;sk162212 - Is Check Point Endpoint Security Client vulnerable to CVE-2019-8286?&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk175589" target="_blank" rel="noopener"&gt;sk175589 - Check Point response to CVE-2021-3781 (Command Execution Vulnerability in Ghostscript)&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk147552" target="_blank" rel="noopener"&gt;sk147552 - Check Point response to CVE-2018-20346 (Magellan), CVE-2018-20505, CVE-2018-20506&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk182320" target="_blank" rel="noopener"&gt;sk182320 - Check Point response to CVE-2024-2511&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk176113" target="_blank" rel="noopener"&gt;sk176113 - Check Point response to Apache CVEs - November 2021 for httpd versions between 2.4.41 and 2.4.51&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk120493" target="_blank" rel="noopener"&gt;sk120493 - Check Point response to CVE-2017-13715&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk182336" target="_blank" rel="noopener"&gt;sk182336 - Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 21 Feb 2025 13:15:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241935#M40380</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-21T13:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241937#M40381</link>
      <description>&lt;P&gt;If we look at the SSH version in R81.x/R82, we learn that only &lt;SPAN class="lia-message-read"&gt;CVE-2025-26465 is present according to the Qualis version list.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 13:45:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241937#M40381</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-02-21T13:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241972#M40384</link>
      <description>&lt;P&gt;For an official response, please check with TAC.&lt;BR /&gt;Unofficially, I don't believe these CVEs to be major issues:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2025-26465" target="_self"&gt;CVE-2025-26465&lt;/A&gt; is an ssh client vulnerability that requires an option to be explicitly set in the ssh_config file that isn't set by default. The only way to exploit this is from expert mode, which should only be given to trusted users.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://ubuntu.com/security/CVE-2025-26466" target="_self"&gt;CVE-2025-26466&lt;/A&gt; appears to be related to a version of OpenSSH we currently don't use.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 21:57:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/241972#M40384</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-21T21:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242001#M40389</link>
      <description>&lt;P&gt;Note if this is related to what I queried, but I do have a TAC case related to OpenSSH vulnerability; currently waiting on a response from TAC.&amp;nbsp; I know when Tenable scanned the appliances it rated the OpenSSH as medium level vulnerability.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2025 14:47:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242001#M40389</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-02-22T14:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242003#M40390</link>
      <description>&lt;P&gt;Please keep us posted what they say. I had customer ask me about it yesterday, but I told him there is community post on the subject, so did not bother opening a TAC case.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2025 17:16:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242003#M40390</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-22T17:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242004#M40391</link>
      <description>&lt;P&gt;The severity of the vulnerabilities is not classified as medium or high if they are identified by any organization regulated by authorities, which must either address the issues through patching or provide justification for their existence.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2025 17:25:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242004#M40391</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2025-02-22T17:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242005#M40392</link>
      <description>&lt;P&gt;You got that 100% right&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2025 17:28:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242005#M40392</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-22T17:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242007#M40393</link>
      <description>&lt;P&gt;Will do, I'm hoping they will say that OpenSSH will be updated in the next Jumbo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2025 17:58:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242007#M40393</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-02-22T17:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242008#M40394</link>
      <description>&lt;P&gt;Latest one is 98, so lets see.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2025 18:00:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-CP-Products-with-81-x-and-82-safe-from-CVE-2025-26465-and/m-p/242008#M40394</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-22T18:00:31Z</dc:date>
    </item>
  </channel>
</rss>

