# CVE-2026-50752 - VPN site to site certificate bypass vulnerability in deprecated IKEv1 key exchange

Please read this important update from Check Point.

**Security Alert:**

**High**

**Product:** Security Gateways, Spark Firewall  
**Version:** R80.20.X (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10  
**OS:** Gaia, Gaia Embedded  
**Last Modified:** 2026-06-25

## Symptoms

- A vulnerability in the certificate validation logic of the [deprecated IKEv1 key exchange method](https://www.ietf.org/archive/id/draft-ietf-ipsecme-ikev1-algo-to-historic-07.html) may lead to a man-in-the-middle attack on the VPN site-to-site configuration.  
This vulnerability was discovered by Check Point security research team. There are no reported exploits of this vulnerability

- **Vulnerable Configurations**

Versions:

- Security Gateways:
    - R82.10 Jumbo Hotfix Take 19 or below
    - R82 Jumbo Hotfix Take 103 or below
    - R81.20 Jumbo Hotfix Take 141 or below
    - R81.10 (EOS)
    - R81 (EOS)
    - R80.40 (EOS)
  - Spark Firewalls: R80.20.X (EOS), R81.10.X, R82.00.X

The vulnerability applies only when all of the following conditions are met:

- VPN site-to-site is enabled.
  - The VPN community uses IKEv1.
  - Gateways participating in the VPN community use certificate-based authentication (pre-shared key authentication is not affected).
  - Gateways are not Dynamic IP (DAIP) gateways.
  - The community is not a Large Scale VPN (LSV) community.

- This issue received the ID [CVE-2026-50752](https://www.cve.org/CVERecord?id=CVE-2026-50752).

## Solution

**Table of Contents:**

- Mitigation
- Recommended step - Install Jumbo Hotfix Accumulator
- Hotfix
- Revision History

### Mitigation

Configure all VPN communities to use IKEv2 only:

**For Security Gateways**

1. In **SmartConsole**, open the **VPN community**.
2. Set the encryption settings to use **IKEv2** only:
   
3. Install the policy on all Security Gateways in the community.

**For Locally Managed Spark Firewall**

1. In **Spark WebUI**, go to **VPN** > **VPN Sites**
2. For each VPN Site, go to **Advanced** tab
3. From the drop-down menu, change the **Encryption Method** to **IKEv2**
   
4. Click **Save**

**For Spark Management**

1. In **Check Point Portal**, go to **Spark Management** service
2. Go to **COMMUNITY**
3. In **Community** > **VPN Settings**, change the **Encryption Method** to **IKEv2**
   
4. Click **Save**

### Recommended step - Install Jumbo Hotfix Accumulator

The fix is included in these Jumbo Hotfix Accumulators:

|     |     |
| --- | --- |
| Version | Take # |
| **R82.10 Jumbo Hotfix Accumulator** | [Take 24](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) |
| **R82 Jumbo Hotfix Accumulator** | [Take 107](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) |
| **R81.20 Jumbo Hotfix Accumulator** | [Take 146](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) |
| **R81.10 Jumbo Hotfix Accumulator** | [Take 187](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) |

### Hotfix R81.20, R82, and R82.10

Check Point can supply a Hotfix for R81.20, R82, and R82.10. Download the Hotfix relevant to your version:

**For Security Gateway / Security Group Member**

|     |     |     |
| --- | --- | --- |
| **Hotfix on top** | **Take #** | **Download link** |
| **R82.10** Jumbo Hotfix Accumulator Take **19** | 3 |  (TAR)<br> (TAR for 3900 appliances) |
| **R82.10** Jumbo Hotfix Accumulator Take **6** | 2 |  (TAR)<br> (TAR for 3900 appliances) |
| **R82** Jumbo Hotfix Accumulator Take **103** | 2 |  (TAR) |
| **R82** Jumbo Hotfix Accumulator Take **91** | 2 |  (TAR) |
| **R82** Jumbo Hotfix Accumulator Take **60** | 3 |  (TAR) |
| **R82** Jumbo Hotfix Accumulator Take **44** | 1 |  (TAR) |
| **R81.20** Jumbo Hotfix Accumulator Take **141** | 2 |  (TAR) |
| **R81.20** Jumbo Hotfix Accumulator Take **127** | 2 |  (TAR) |
| **R81.20** Jumbo Hotfix Accumulator Take **120** | 2 |  (TAR) |
| **R81.20** Jumbo Hotfix Accumulator Take **118** | 1 |  (TAR) |
| **R81.20** Jumbo Hotfix Accumulator Take **113** | 2 |  (TAR) |
| **R81.20** Jumbo Hotfix Accumulator Take **105** | 1 |  (TAR) |
| **R81.20** Jumbo Hotfix Accumulator Take **92** | 1 |  (TAR) |

**For Check Point Spark Firewalls**

|     |     |     |     |     |     |
| --- | --- | --- | --- | --- | --- |
| **Download Package** | **15X5/1575R Appliances** | **1595R**<br>**Appliances** | **1600/1800/**<br>**1900/2000**<br>**Appliances** | **2530/2550**<br>**Appliances** | **2560/2570/**<br>**2580/2590**<br>**Appliances** |
| **R82.00.10 Build 998002216**<br>**for Local Installation** |  (IMG) |  (IMG) |  (IMG) |  (IMG) |  (IMG) |
| **R82.00.10 Build 998002216**<br>**for Central Deployment**<br>**in SmartConsole** |  (TAR) |  (TAR) |  (TAR) |  (TAR) |  (TAR) |
| **R82.00.10 Build 998002216**<br>**for SmartUpdate** |  (TGZ) |  (TGZ) |  (TGZ) |  (TGZ) |  (TGZ) |

|     |     |     |     |
| --- | --- | --- | --- |
| **Download Package** | **1500 Appliances** | **1595R**<br>**Appliances** | **1600/1800/**<br>**1900/2000**<br>**Appliances** |
| **R81.10.17 Build 996004901**<br>**for Local Installation** |  (IMG) |  (IMG) |  (IMG) |
| **R81.10.17 Build 996004901**<br>**for Central Deployment**<br>**in SmartConsole** |  (TAR) |  (TAR) |  (TAR) |
| **R81.10.17 Build 996004901**<br>**for SmartUpdate** |  (TGZ) |  (TGZ) |  (TGZ) |

**Important:** For Centrally Managed Appliances, before installing these Builds, make sure your Security Management is updated with solution for [Certificate and CRL validation](https://support.checkpoint.com/results/sk/sk184766).

### Revision History

|     |     |
| --- | --- |
| Date | Description |
| 15 Jun 2026 | Added Recommended step<br>- R82.10 Jumbo Hotfix Accumulator Take 24<br>- R82 Jumbo Hotfix Accumulator Take 107<br>- R81.20 Jumbo Hotfix Accumulator Take 146 |
| 14 Jun 2026 | Added Hotfixes for<br>- R82 Jumbo Hotfix Accumulator Take 60<br>- R82 Jumbo Hotfix Accumulator Take 44 |
| 11 Jun 2026 | Added Recommended step - R81.10 Jumbo Hotfix Accumulator Take 187.
