# CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero

Please read this important update from Check Point.

Security Alert:

**High**

**Product**: Security Gateways, Spark Firewall  
**Version**: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10  
**Last Modified**: 2026-06-11

## Symptoms

- The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).
- The VPN service is monitored by a Check Point WatchDog service and is automatically restarted.
- Existing IPsec tunnels continue to function.
- This issue affects:

- R82.10 with Jumbo Hotfix Take 6 or below
  - R82 with Jumbo Hotfix Take 91 or below
  - R81.20 with Jumbo Hotfix Take 127 or below
  - All releases from R81.10 and below
- This issue received the ID [CVE-2026-48131](https://www.cve.org/CVERecord?id=CVE-2026-48131).

## Solution

**Mitigations**:

- If VPN services are not needed, disable the VPN feature in the Security Gateway's properties and install the policy.

To do so:

1. In the **SmartConsole**, open the **Security Gateway** object  
2. In the **General Properties** window, clear the **IPSec VPN** checkbox  
3. Click **OK**, then save and install the Security Policy

This will prevent malicious packets from reaching ports 500/UDP and 4500/UDP.

- If you want to use the VPN services, enable the IPS protection **IKE Unsigned Underflow** in Protection mode.

To do so:

1. In the **SmartConsole**, go to **Security Policies** > **Threat Prevention**  
2. In **Custom Policy Tools** at the bottom, click **IPS Protection**  
3. Search for **IKE Unsigned Underflow**  
4. Double-click it to open  
5. Edit **Action** to make sure it is set to **Prevent**:

**Solution**

For Security Gateways, the fix is included in:

- [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 19  
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103  
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 141  
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 187

For Spark Firewalls, see:

- R81.10.17 - **[sk183153](https://support.checkpoint.com/results/sk/sk183153)**  
- R82.00.10 - **[sk184357](https://support.checkpoint.com/results/sk/sk184357)**
