Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Check Point Software

Check Point Software Vendor Cyber Rating & Cyber Score

checkpoint.com

Check Point Software Technologies Ltd. is a leading protector of digital trust, utilizing AI-powered cyber security solutions to safeguard over 100,000 organizations globally. Through its Infinity Platform and an open garden ecosystem, Check Point’s prevention-first approach delivers industry-leading security efficacy while reducing risk. Employing a hybrid mesh network architecture with SASE at its core, the Infinity Platform unifies the management of on-premises, cloud, and workspace environments to offer flexibility, simplicity and scale for enterprises and service providers.


CPS A.I CyberSecurity Scoring

CPS
Company Information
Website:http://www.checkpoint.com
Employees number:8,356
Number of followers:420,046
NAICS:541514
Industry Type:Computer and Network Security
Homepage:checkpoint.com
CPS Risk Score (AI oriented)
Between 550 and 599
logo
CPSComputer and Network Security
Updated:
08/06/2026
597/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CPS Global Score (TPRM)
xxxx
logo
CPSComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CPS
CPSVery Poor
Current Score
597Ca (VERY POOR)
01000
7 incidents
-18.2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
597Before Incident
MAY 2026
612Before Incident
Cyber Attack
21 May 2026CPS
Check Point: Revealed: Top five most vulnerable countries to an impending cyberattack

Global Cyberattack Vulnerability Report Highlights Indonesia as Top Target for AI-Powered Threats

595After Incident
LOW-17
CHE1779395576
Global Cyberattack Vulnerability Report Highlights Indonesia as Top Target for AI-Powered Threats A 2026 study by cybersecurity firm Check Point reveals Indonesia as the most vulnerable country to AI-driven cyberattacks, with nearly half of its internet-connected devices targeted by hackers. The research analyzed five major attack types botnets, infostealers, banking trojans, ransomware, and mobile malware ranking nations based on device exposure, economic impact, and cybersecurity defenses. Key Findings: - Indonesia leads the list, with 47% of devices under attack. Weak defenses (47.5/100) and high AI-driven automation in attacks contribute to its vulnerability. Infostealers compromise 16% of devices, while botnets affect 21%. - Mongolia ranks second, with 30% of devices targeted. Low cybersecurity scores (50/100) and widespread internet use (85% penetration) make it a prime target, despite modest average incomes ($7K/year). - Mexico follows in third, with 29% of devices at risk. Botnets (10.6%) and ransomware (8.4%) dominate attacks, fueled by high internet usage (81%) and weak defenses (38/100). Average incomes ($14K/year) make it a lucrative target. - Saudi Arabia, despite stronger defenses (78.33/100), faces attacks on 28.5% of devices. High average incomes ($35K/year) and AI adoption (26%) create high-value targets, amplifying financial losses from breaches. - Georgia rounds out the top five, with 28% of devices targeted. Banking trojans alone affect 8% of accounts, while rapid AI adoption (18%) outpaces security measures. The study underscores how AI-powered attacks exploit weak defenses, high internet penetration, and economic disparities to maximize damage, with emerging economies bearing the brunt of automated threats.
INCIDENT DETAILS -
TYPE
botnetsinfostealersbanking trojansransomwaremobile malware
MOTIVATION
Financial gainData exfiltration
IMPACT
Systems Affected: Internet-connected devices
MAY 2026
614Before Incident
Vulnerability
07 May 2026CPS
Check Point, Nissan and Court Services Victoria: Check Point links VPN zero-day attacks to Qilin ransomware gang

Check Point Patches Critical Zero-Day Exploited in VPN Attacks Linked to Qilin Ransomware

611After Incident
CRITICAL-3
NISCHEHAR1780929039
Check Point Patches Critical Zero-Day Exploited in VPN Attacks Linked to Qilin Ransomware Israeli cybersecurity firm Check Point has released urgent security updates to address a critical authentication bypass vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access deployments. The flaw, actively exploited in zero-day attacks since May 7, allows unauthenticated remote attackers to bypass authentication on vulnerable systems, including Mobile Access/SSL VPNs, Remote Access VPNs, and Spark firewalls. The vulnerability affects only deployments using the deprecated IKEv1 key exchange protocol, specifically those configured to accept legacy Remote Access clients without requiring machine certificate authentication. Exploitation surged in early June, impacting a few dozen organizations globally, with at least one confirmed case tied to the Qilin ransomware operation. Check Point’s investigation also uncovered a second flaw (CVE-2026-50752), which enables man-in-the-middle attacks on site-to-site VPN connections due to improper certificate validation in IKEv1. While no active exploitation of CVE-2026-50752 has been observed, the company urges immediate patching to prevent potential exposure. For organizations unable to patch immediately, Check Point recommends disabling IKEv1 support, enforcing IKEv2-only authentication, mandating machine certificate authentication, and enabling IPS with updated signatures. Qilin, a Ransomware-as-a-Service (RaaS) group active since August 2022, has claimed nearly 400 victims via its dark web leak site, targeting high-profile entities such as Nissan, Asahi, Lee Enterprises, Synnovis, and Australia’s Court Services Victoria. The group’s involvement in the Check Point VPN attacks underscores the growing threat of ransomware actors exploiting critical infrastructure vulnerabilities.
INCIDENT DETAILS -
TYPE
Zero-Day Exploitation
MOTIVATION
Ransomware, Data Exfiltration
IMPACT
Systems Affected: Remote Access VPN, Mobile Access/SSL VPN, Spark firewalls
APRIL 2026
615Before Incident
MARCH 2026
615Before Incident
FEBRUARY 2026
614Before Incident
JANUARY 2026
612Before Incident
Vulnerability
14 Jan 2026CPS
Check Point: Critical Vulnerability In Check Point Harmony SASE Allows Local Privilege Escalation On Windows

Check Point Harmony SASE Windows Client Flaw Grants SYSTEM Privileges via JWT Manipulation

608After Incident
CRITICAL-4
CHE1769604337
Check Point Harmony SASE Windows Client Flaw Grants SYSTEM Privileges via JWT Manipulation A critical vulnerability in Check Point’s Harmony SASE Windows client (CVE-2025-9142) allows local attackers to escalate privileges to SYSTEM by exploiting poor validation in certificate processing. The flaw affects versions below 12.2, with the last update issued on January 14, 2026. The issue stems from the Perimeter81 service component, which runs with elevated privileges. Attackers can manipulate the tenant name in a JWT token, passed via IPC or URI handlers, to trigger directory traversal. This enables the service to write or delete files outside its intended directory for example, crafting paths like `../../../../../../../../../sleep` to target `C:\sleep`. The vulnerability arises from inadequate JWT signature verification in the `SaferVPN.Core.Sdp.SdpCertificates` class, which uses a user-supplied `WorkingDirectory` from the JWT’s `tenantId` field without proper validation. Functions like `CleanCertFolder()` and `GenerateAndLoadCertificates()` executed as SYSTEM can then delete or write files in arbitrary locations. Exploitation requires local access and follows a precise sequence: 1. Pre-create a target directory (e.g., `C:\sleep`). 2. Invoke the URI handler (`perimeter81://`) with a tampered JWT, delaying a rogue server’s CSR response. 3. Swap the directory with a symlink (via RPC Control) to redirect writes e.g., replacing `client.crt` with a path like `C:\Windows\System32\newfile.dll`. 4. Serve malicious certificate content, which the SYSTEM service writes, potentially enabling DLL hijacking on restart. A proof-of-concept (PoC) demonstrates achieving a SYSTEM shell via automated named pipes, local web servers, and symlink timing. While Microsoft patches (e.g., CVE-2024-38014) mitigate older OpLock tricks, symlink-based attacks remain viable. Impacted versions include Harmony SASE 11.5.0.2501 and all releases below 12.2. The client supports 40+ allowed domains (e.g., `perimeter81.com`, `sase.checkpoint.com`), but attackers bypass these controls by forging unverified JWTs. Notably, QA environments (e.g., `splinter.saseqa.checkpoint.com`) are also vulnerable. Check Point has released version 12.2 to address the flaw, urging users to upgrade via sk182466. The accompanying SK article (sk184557) details symptoms, root causes, and remediation steps. The researcher behind the discovery returned the domain `p81-falcon.com` to aid patching, and updated TLS certificates now block rogue server setups. The flaw underscores risks in SASE clients processing web-derived inputs without strict validation, highlighting the need for privileged service hardening even in local attack scenarios.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Systems Affected: Windows systems running Check Point Harmony SASE client versions below 12.2Operational Impact: Potential SYSTEM-level compromise, enabling arbitrary file writes/deletions and DLL hijackingBrand Reputation Impact: Moderate (Check Point’s SASE client security flaw)
DECEMBER 2025
611Before Incident
NOVEMBER 2025
618Before Incident
OCTOBER 2025
663Before Incident
Breach
16 Oct 2025CPS
Check Point (as referenced in the article, representing a generalized case of affected organizations)

Undetected Cloud Security Breaches and Delayed Response Trends (2025)

612After Incident
CRITICAL-51
CHE2532625101625
The article highlights a systemic issue across 66% of organizations that experienced cloud security breaches in the past year, with 91% of incidents remaining undetected for over an hour and 62% taking more than 24 hours to remediate. Prolonged exposure allowed attackers to escalate privileges, exfiltrate data, or deploy ransomware, leading to reputational damage, regulatory fines (e.g., GDPR penalties), and operational disruptions. Causes included misconfigured cloud storage, overly permissive access controls, disabled logging (e.g., AWS CloudTrail), and alert fatigue—exacerbated by fragmented hybrid environments. The delayed response enabled adversaries to maintain persistence, perform account takeovers, and exploit cloud resources for malicious purposes, compounding financial and legal risks. While no single company is named, the pattern reflects widespread vulnerabilities in cloud security postures, with breaches often escalating from initial access to data theft or system compromise before mitigation.
INCIDENT DETAILS -
TYPE
Cloud Security BreachData TheftUnauthorized AccessMisconfiguration ExploitationRegulatory Non-Compliance (GDPR)
MOTIVATION
Data TheftFinancial Gain (e.g., Ransomware)EspionageDisruption of Services
IMPACT
Project DelaysService DisruptionsResource Exploitation for Malicious Purposes (e.g., Ransomware)GDPR Fines (UK/EU)Regulatory Penalties for Personal Data Breaches
DATA BREACH
Customer DataPersonal Data (PII)Sensitive Business InformationSensitivity Of Data: High (Potential GDPR Violation)
SEPTEMBER 2025
662Before Incident
AUGUST 2025
672Before Incident
Cyber Attack
01 Aug 2025CPS
Check Point Research (Education Sector - India)

Surge in Cyberattacks Targeting Indian Organizations in August 2025

656After Incident
CRITICAL-16
CHE0532105091725
In August 2025, the education sector in India—highlighted by Check Point Research—faced an average of 4,178 cyberattacks per organization weekly, marking a 13% year-on-year increase. The sector’s rapid digitization, coupled with chronic underfunding in cybersecurity, expanded its attack surface, making it a prime target for threat actors. While the report did not specify the exact nature of each attack, the scale and frequency suggest data breaches, ransomware, or disruptive cyberattacks aimed at exploiting vulnerable systems. Given the sector’s role in handling student records, financial aid data, and research intellectual property, compromises could lead to financial fraud, reputational damage, or operational disruptions (e.g., halting online classes or exam systems).The attacks align with broader trends where education globally remains the most targeted sector, with India’s volume surpassing the worldwide average (1,994 attacks/week). Though no specific incident was detailed, the pattern implies high-severity threats, potentially involving phishing, malware, or ransomware campaigns designed to extract sensitive data or cripple institutional infrastructure. The lack of robust defenses exacerbates risks, increasing the likelihood of prolonged outages, data leaks, or financial losses—directly impacting students, faculty, and administrative operations.
INCIDENT DETAILS -
TYPE
Cyberattacks (General)Targeted Sector AttacksRansomware (US-specific)
MOTIVATION
Financial GainData TheftDisruption
IMPACT
Operational Impact: High (sector-wide disruptions, especially in education and government)Brand Reputation Impact: Moderate to High (sectoral trust erosion, especially in education)
JULY 2025
672Before Incident
APRIL 2025
713Before Incident
Breach
01 Apr 2025CPS
Check Point

Check Point Data Breach

662After Incident
CRITICAL-51
CHE417040125
A hacker using the alias CoreInjection claims to have obtained sensitive data from Check Point, including user credentials, employee contract details, and internal network maps. Check Point downplays the incident, asserting it relates to a limited and previously addressed breach. The breach supposedly involved just one account with restricted portal access and did not extend to customers' systems, production, or security architecture. Despite the company's stance, security experts like Hudson Rock CTO Alon Gal suggest Check Point may have had an administrator account compromised, indicating a serious breach with potential internal company data leaks.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
user credentialsemployee contract detailsinternal network maps
DATA BREACH
user credentialsemployee contract detailsinternal network mapsSensitivity Of Data: High
JANUARY 2025
794Before Incident
Ransomware
01 Jan 2025CPS
Check Point Research (hypothetical victim: an unnamed US educational institution)

Global Surge in Cyberattacks on Educational Institutions (2025)

708After Incident
CRITICAL-86
CHE0802408090925
An unnamed educational institution in the US fell victim to a ransomware attack amid a 41% global surge in cyberactivity targeting schools (Jan–Jul 2025). The attack, part of a broader trend where US institutions saw a 67% year-on-year increase, encrypted critical systems including student records, financial aid databases, and research data. The breach disrupted operations for weeks, forcing cancellations of online classes and delaying admissions processing. While no direct evidence of data exfiltration was confirmed, the attackers demanded a multi-million-dollar ransom, threatening to leak sensitive student and faculty information if unpaid. The institution faced reputational damage as local media covered the incident, and parents raised concerns over data privacy. Recovery costs—including system restoration, legal fees, and cybersecurity upgrades—exceeded $5 million, straining the institution’s budget. The attack underscored the education sector’s vulnerability, now the most targeted globally, with ransomware groups exploiting underfunded IT defenses.
INCIDENT DETAILS -
TYPE
cyberattackransomwaretargeted campaign
MOTIVATION
financial gaindisruptiondata theft
IMPACT
Operational Impact: high (sector-wide disruption)Brand Reputation Impact: severe (education sector reputation at risk)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CPS ?
?
What was CPS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CPS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in August 2025 ?
?
What was CPS's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on CPS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CPS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CPS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?