<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CVE-2026-50751-Mitigation-Scripts in Automation and APIs</title>
    <link>https://community.checkpoint.com/t5/Automation-and-APIs/CVE-2026-50751-Mitigation-Scripts/m-p/278026#M25</link>
    <description>&lt;P&gt;This is more for MDS customers than it is for SMS but I did include the one line for SMS even though you just need to click one box in the GUI. I'm a cli guy so I like it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have since updated this to do either mitigation 1 or 2 automatically. So there are scripts to turn off the legacy check box or to turn off ikev1&lt;/P&gt;
&lt;P&gt;The legacy check box is through generic object but I tested on my SMS with multiple gateways and it worked great. Use at own risk though because of generic object.&lt;/P&gt;
&lt;P&gt;MDS this will make the global change to ike v2 on all Domains for you. Quicker than open close. Please note changing to ike v2 is mitigation step 2 and you should make sure you read&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk166415" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk166415&lt;/A&gt;&amp;nbsp;before making that switch.&lt;/P&gt;
&lt;P&gt;I am working on scripts to do the per-gateway mitigation of disabling legacy clients.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/WadesWeaponShed/CVE-2026-50751-Mitigation-Scripts" target="_blank" rel="noopener"&gt;https://github.com/WadesWeaponShed/CVE-2026-50751-Mitigation-Scripts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jun 2026 16:12:58 GMT</pubDate>
    <dc:creator>Adam_Forester</dc:creator>
    <dc:date>2026-06-08T16:12:58Z</dc:date>
    <item>
      <title>CVE-2026-50751-Mitigation-Scripts</title>
      <link>https://community.checkpoint.com/t5/Automation-and-APIs/CVE-2026-50751-Mitigation-Scripts/m-p/278026#M25</link>
      <description>&lt;P&gt;This is more for MDS customers than it is for SMS but I did include the one line for SMS even though you just need to click one box in the GUI. I'm a cli guy so I like it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have since updated this to do either mitigation 1 or 2 automatically. So there are scripts to turn off the legacy check box or to turn off ikev1&lt;/P&gt;
&lt;P&gt;The legacy check box is through generic object but I tested on my SMS with multiple gateways and it worked great. Use at own risk though because of generic object.&lt;/P&gt;
&lt;P&gt;MDS this will make the global change to ike v2 on all Domains for you. Quicker than open close. Please note changing to ike v2 is mitigation step 2 and you should make sure you read&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk166415" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk166415&lt;/A&gt;&amp;nbsp;before making that switch.&lt;/P&gt;
&lt;P&gt;I am working on scripts to do the per-gateway mitigation of disabling legacy clients.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/WadesWeaponShed/CVE-2026-50751-Mitigation-Scripts" target="_blank" rel="noopener"&gt;https://github.com/WadesWeaponShed/CVE-2026-50751-Mitigation-Scripts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 16:12:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Automation-and-APIs/CVE-2026-50751-Mitigation-Scripts/m-p/278026#M25</guid>
      <dc:creator>Adam_Forester</dc:creator>
      <dc:date>2026-06-08T16:12:58Z</dc:date>
    </item>
  </channel>
</rss>

