# CVE-2026-48132 - VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP

Please read this important update from Check Point.

## Security Alert:

**High**

**Product:** Security Gateways, Spark Firewall  
**Version:** R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10  
**Last Modified:** 2026-06-11

## Symptoms

- The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic).
- This issue affects:
  - R82.10 with Jumbo Hotfix Take 6 or below  
  - R82 with Jumbo Hotfix Take 91 or below  
  - R81.20 with Jumbo Hotfix Take 127 or below  
  - All releases from R81.10 and below  
- This issue received the ID [CVE-2026-48132](https://www.cve.org/CVERecord?id=CVE-2026-48132).

## Solution

**Mitigations**

- If VPN services are not needed, disable the VPN feature in the Security Gateway's properties and install the policy.

To do so:

1. In the **SmartConsole**, open the **Security Gateway** object  
2. In the **General Properties** window, clear the **IPSec VPN** checkbox  
3. Click **OK**, then save and install the Security Policy

This will prevent malicious packets from reaching ports 500/UDP and 4500/UDP.

- If you want to use the VPN services, enable the IPS protection **IKE Improper Length Validation** in Protection mode.

To do so:

1. In the **SmartConsole**, go to **Security Policies** > **Threat Prevention**  
2. In **Custom Policy Tools** at the bottom, click **IPS Protection**  
3. Search for **IKE Improper Length Validation**  
4. Double-click it to open  
5. Edit **Action** to make sure it is set to **Prevent**:

**Solution**

For Security Gateways, the fix is included in:

- [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 19  
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103  
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 141  
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 187

For Spark Firewalls, see:

- R81.10.17 - **[sk183153](https://support.checkpoint.com/results/sk/sk183153)**  
- R82.00.10 - **[sk184357](https://support.checkpoint.com/results/sk/sk184357)**

## Article Properties

**Access Level:** General  
**Severity:** High  
**Status:** Approved  
**Date Created:** 2026-05-20  
**Last Modified:** 2026-06-11
