Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4585 articles · 179966 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2026-48131EXPLOITED
checkpoint · quantum security gateway

VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero

Description

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).

Affected Products

VendorProductVersions
checkpointquantum security gatewayR82.10 with Jumbo Hotfix Take 6 or below, R82 with Jumbo Hotfix Take 91 or below, R81.20 with Jumbo Hotfix Take 127 or below, All releases from R81.10 and below

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointsecuritycert_advisory90%

References

  • https://support.checkpoint.com/results/sk/sk184981

Related News (4 articles)

Tier D
Heise Security52d ago
IT-Sicherheitslösung Check Point Security Gateway ist verwundbar
→ No new info (linked only)
Tier B
BSI Advisories55d ago
[NEU] [hoch] Check Point Security Gateway: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR58d ago
Multiples vulnérabilités dans les produits Check Point (27 mai 2026)
→ No new info (linked only)
Tier C
VulDB58d ago
CVE-2026-48131 | Check Point Quantum Security Gateway VPN Service heap-based overflow
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-122
PublishedMay 26, 2026
Last enriched58d agov2
Trending Score0
Source articles4
Independent4
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-50751EXPKEV
User Authentication Bypass in VPN Remote Access and Mobile Access
Trending: 157
CRITICALCVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 112
CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 57
HIGHCVE-2026-62145
Local Privilege Escalation in Gaia Portal
Trending: 45
HIGHCVE-2026-50752
Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 26, 2026
Discovered by ZDM
May 26, 2026
Updated: description, severity, activelyExploited
May 26, 2026
Actively Exploited
May 26, 2026

Version History

v2
Last enriched 58d ago
v2Tier C58d ago

Updated severity to CRITICAL, marked as actively exploited, and provided a more detailed description of the vulnerability.

descriptionseverityactivelyExploited
via VulDB
v158d ago

Initial creation