sk184981 - CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero

CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero

Please read this important update from Check Point.

Security Alert:

High

Product: Security Gateways, Spark Firewall
Version: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10
Last Modified: 2026-06-11

Symptoms

Solution

Mitigations:

To do so:

  1. In the SmartConsole, open the Security Gateway object
  2. In the General Properties window, clear the IPSec VPN checkbox
  3. Click OK, then save and install the Security Policy

This will prevent malicious packets from reaching ports 500/UDP and 4500/UDP.

To do so:

  1. In the SmartConsole, go to Security Policies > Threat Prevention
  2. In Custom Policy Tools at the bottom, click IPS Protection
  3. Search for IKE Unsigned Underflow
  4. Double-click it to open
  5. Edit Action to make sure it is set to Prevent:

Solution

For Security Gateways, the fix is included in:

For Spark Firewalls, see: