CVE-2026-48131 Details
Description
The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).
A denial-of-service vulnerability has been identified in the VPN service of Check Point Security Gateways and Spark Firewalls. This issue arises when the service improperly processes an unexpected IKE fragment value on the IKE port 500/UDP during the initial stages of a connection attempt. The mishandling can lead to an unexpected termination of the service, causing a temporary disruption in VPN functionality. However, existing IPsec tunnels remain unaffected.
To address this vulnerability, users can upgrade to the following versions: Check Point Security Gateways can upgrade to the Jumbo Hotfix Accumulator for R82.10 starting from Take 19, for R82 starting from Take 103, or for R81.20 starting from Take 141. For Spark Firewalls, the upgrade should be to R81.10.17 or R82.00.10. Additionally, users can enable the IPS protection 'IKE Unsigned Underflow' in Protection mode to mitigate the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.checkpoint.com/results/sk/sk184981 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |