Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Blason_R
MVP Gold
MVP Gold

Are CP Products with 81.x and 82 safe from CVE-2025-26465 and CVE-2025-26466

Hi Team,

According to the recent vulnerabilities disclosed by Qualys which are CVE-2025-26465/26466 curious to know if CP products are vulnerable and if any fix is released?

TIA

Blason R

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
10 Replies
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Please raise this with TAC otherwise monitor these repositories:

https://support.checkpoint.com/security-advisories

https://support.checkpoint.com/results/sk/sk65269 

CCSM R77/R80/ELITE
0 Kudos
the_rock
MVP Gold
MVP Gold

0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

If we look at the SSH version in R81.x/R82, we learn that only CVE-2025-26465 is present according to the Qualis version list.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
PhoneBoy
Admin
Admin

For an official response, please check with TAC.
Unofficially, I don't believe these CVEs to be major issues:

  • CVE-2025-26465 is an ssh client vulnerability that requires an option to be explicitly set in the ssh_config file that isn't set by default. The only way to exploit this is from expert mode, which should only be given to trusted users.
  • CVE-2025-26466 appears to be related to a version of OpenSSH we currently don't use.

 

genisis__
MVP Silver
MVP Silver

Note if this is related to what I queried, but I do have a TAC case related to OpenSSH vulnerability; currently waiting on a response from TAC.  I know when Tenable scanned the appliances it rated the OpenSSH as medium level vulnerability. 

the_rock
MVP Gold
MVP Gold

Please keep us posted what they say. I had customer ask me about it yesterday, but I told him there is community post on the subject, so did not bother opening a TAC case.

Andy

Best,
Andy
0 Kudos
genisis__
MVP Silver
MVP Silver

Will do, I'm hoping they will say that OpenSSH will be updated in the next Jumbo.

 

the_rock
MVP Gold
MVP Gold

Latest one is 98, so lets see.

Andy

Best,
Andy
0 Kudos
Blason_R
MVP Gold
MVP Gold

The severity of the vulnerabilities is not classified as medium or high if they are identified by any organization regulated by authorities, which must either address the issues through patching or provide justification for their existence.

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
(1)
the_rock
MVP Gold
MVP Gold

You got that 100% right @Blason_R 

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events