<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2026-50751 - Help with some questions. in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278287#M13997</link>
    <description>&lt;P&gt;Did you notice if it still disconnected when disable_ikev2 = 0 reg key was set but firewall was on IKEv1?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2026 22:02:03 GMT</pubDate>
    <dc:creator>sx8n20394</dc:creator>
    <dc:date>2026-06-10T22:02:03Z</dc:date>
    <item>
      <title>CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278078#M13973</link>
      <description>&lt;P&gt;I have contacted Checkpoint support about these questions but the low level guys have no answers for me.&lt;/P&gt;&lt;P&gt;Are there SHA1 or SHA256 hashes for the malicious files that were found? Our EDR doesn't allow MD5, only SHA1 and SHA256.&lt;/P&gt;&lt;P&gt;Is there anyway of using IKEv2 on R81.10.17 Build 4901 (Newest with Patch)? We just get the error&amp;nbsp;no response from gateway for 1st packet. We updated clients to the latest version and enabled ikev2 in the registry and still get the error. Only r82 gateways work with clients using IKEv2.&lt;/P&gt;&lt;P&gt;We suspect 2 clients were exploited. We see no additional activity after exploitation. It looks like they successfully logged into the VPN and then the connection terminates exactly an hour later. No further activity. Are there any additional remediation steps we need to take other than patching the appliances such as rotating internal certificates, etc?&lt;/P&gt;&lt;P&gt;Is there anyway to tell if either of these are enabled or not configured on our locally managed spark gateways:&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-06-08 223331.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34430i5DD5B725E89026C5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2026-06-08 223331.png" alt="Screenshot 2026-06-08 223331.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-06-08 223438.png" style="width: 677px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34431i3A49E74A98C3CE8D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2026-06-08 223438.png" alt="Screenshot 2026-06-08 223438.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Is there any data showing how long between exploitation and malicious activities started on internal networks?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 12:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278078#M13973</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2026-06-09T12:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278146#M13978</link>
      <description>&lt;P&gt;In the SK for&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182336" target="_blank"&gt;CVE-2024-24919&lt;/A&gt;, which disclosed sensitive information stored on the gateway that could be used for lateral movement and compromise of internal networks, we provide a number of recommended steps.&lt;BR /&gt;In the case of&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk185033" target="_blank"&gt;CVE-2026-50751&lt;/A&gt;, the only thing "disclosed" is your encryption domain, DNS server, and possibly your DHCP server (if you're using that to assign Office Mode IPs).&lt;/P&gt;
&lt;P&gt;As for applying mitigations, the CVE is only relevant when&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;all&lt;/EM&gt;&lt;/STRONG&gt; of the following are true:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;VPN Remote Access or Mobile Access is enabled&lt;/LI&gt;
&lt;LI&gt;IKEv1 is enabled for remote access&lt;/LI&gt;
&lt;LI&gt;Gateways accept legacy Remote Access clients&lt;/LI&gt;
&lt;LI&gt;Gateways do not demand a machine certificate for connections&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Provided you have disabled IKEv1 per&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk185033" target="_blank"&gt;sk185033&lt;/A&gt;, then you have successfully mitigated the issue (i.e. the other options aren't needed).&lt;BR /&gt;In any case, the other mitigation options are not available on locally managed SMB appliances.&lt;/P&gt;
&lt;P&gt;Once you remediate, you should follow your Incident Response plan to ensure no other resources were accessed or compromised.&lt;BR /&gt;Check Point does offer Incident Response services that can assist with this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 16:49:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278146#M13978</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-09T16:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278179#M13981</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;HI &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;Have I understood correctly that we do not need to install the hotfix if one of the three mitigation options has been implemented?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;We have already implemented Option 1 and will implement Option 3 shortly. Option 2 is not applicable in our environment because we are using R81.20 with Standalone Clients. As far as I understand, IKEv2 is only supported starting with R82.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;In addition, we installed the hotfix for Take 141. Since then, we have been experiencing issues: VPN connections are disconnected after approximately one hour, and users are then unable to establish a new connection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When we uninstall the hotfix, everything works normally again without any issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Roman&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 20:54:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278179#M13981</guid>
      <dc:creator>Romaryo</dc:creator>
      <dc:date>2026-06-09T20:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278181#M13983</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;We are having the same issue Quantum Spark R82.00.10 Latest Build&amp;nbsp;&lt;STRONG&gt;2216.&amp;nbsp;&lt;/STRONG&gt;This needs to be investigated by R&amp;amp;D and hopefully fixed quick.&lt;/P&gt;&lt;P&gt;Edit: What we are seeing is clients who use Entra SSO for remote access will be asked to login again. The browser will randomly pop open and prompt for M365 login. This is normal behavior on initial connect but we have never had this happen during an active session.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 00:50:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278181#M13983</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2026-06-10T00:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278251#M13990</link>
      <description>&lt;P&gt;Same issue with 1 hour disconnects after applying Hotfix firmware to locally managed 2570 and using RemoteAccess VPN E89.11, E89.20.&amp;nbsp;We attempted to eliminate use of IKEv1 per&amp;nbsp;sk166415, on device changed&amp;nbsp;'prefer IKEv2 but allow IKEv1', on clients applied registry change&amp;nbsp;disable_ikev2=0 - that leads to failure to renegotiate after 1 hour and errors such as '&lt;SPAN&gt;Informational exchange: Sending notification to peer: Invalid IKE SPI.(+) IKE SPIs', 'decryption failure:="Unknown SPI: 0x77e8be85 for UDP encapsulated IPsec packet'....&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 14:25:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278251#M13990</guid>
      <dc:creator>VytasM</dc:creator>
      <dc:date>2026-06-10T14:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278283#M13994</link>
      <description>&lt;P&gt;Open a TAC case. We have one open but the more opened, the faster they will probably be on this issue. Did IKEv1 drop for you though? We haven't had a chance to test with IKEv1 to see if it drops.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 21:45:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278283#M13994</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2026-06-10T21:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278286#M13996</link>
      <description>&lt;P&gt;IKEv1 has no issues, VPN connection from clients left at default registry keys are stable as with prior&amp;nbsp;R82.00.10 Build 998002203. It's not critical for us to stop using&amp;nbsp;IKEv1 ASAP. Figured Checkpoint team is quite busy as it is and this issue will be noticed and corrected in next build. We did not test IKEv2 with prior firmware version.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 21:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278286#M13996</guid>
      <dc:creator>VytasM</dc:creator>
      <dc:date>2026-06-10T21:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278287#M13997</link>
      <description>&lt;P&gt;Did you notice if it still disconnected when disable_ikev2 = 0 reg key was set but firewall was on IKEv1?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 22:02:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278287#M13997</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2026-06-10T22:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278288#M13998</link>
      <description>&lt;P&gt;In terms of mitigating the CVE, implementing one of the three options is sufficient.&lt;BR /&gt;We still officially recommended installing the JHF due to other security hardening that was done.&lt;BR /&gt;Having said that, if it's causing an issue, I understand uninstallng it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 22:26:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278288#M13998</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-10T22:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278326#M14002</link>
      <description>&lt;P&gt;I have a question on the conditions listed:&lt;/P&gt;
&lt;P&gt;As for applying mitigations, the CVE is only relevant when&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;all&lt;/EM&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of the following are true:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;VPN Remote Access or Mobile Access is enabled&lt;/LI&gt;
&lt;LI&gt;IKEv1 is enabled for remote access&lt;/LI&gt;
&lt;LI&gt;Gateways accept legacy Remote Access clients&lt;/LI&gt;
&lt;LI&gt;Gateways do not demand a machine certificate for connections&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;My scenario:&lt;/P&gt;
&lt;P&gt;None of our gateways have Mobile Access blade enabled.&lt;/P&gt;
&lt;P&gt;Some of our gateways have IPSecVPN blade enabled - this is only used for S2S VPN. None of our gateways are a member of the "RemoteAccess" VPN community.&lt;/P&gt;
&lt;P&gt;Am I in the clear for CVE-2026-50751? (I understand CVE-2026-50572 is another issue, we are not impacted by this vulnerability).&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 13:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278326#M14002</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2026-06-11T13:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278339#M14006</link>
      <description>&lt;P&gt;We have performed the test - yes VPN is stable (no disconnects) with Firewall set to IKEv1 and VPN client set at&amp;nbsp;&lt;SPAN&gt;disable_ikev2 = 0,(PC rebooted after registry change).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 17:42:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278339#M14006</guid>
      <dc:creator>VytasM</dc:creator>
      <dc:date>2026-06-11T17:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278343#M14007</link>
      <description>&lt;P&gt;Thanks. I was able to test this last night and was successful no matter the auth method.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 18:44:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278343#M14007</guid>
      <dc:creator>sx8n20394</dc:creator>
      <dc:date>2026-06-11T18:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278350#M14010</link>
      <description>&lt;P&gt;The CVE is specific to Remote Access functionality, which can either use VPN blade or Mobile Access.&lt;BR /&gt;If you're using neither (i.e. just Site-to-Site), this CVE is not relevant.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 19:12:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278350#M14010</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-11T19:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2026-50751 - Help with some questions.</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278354#M14011</link>
      <description>&lt;P&gt;That makes sense - even though I have IPSec VPN Blade enabled (which I assume is what you are calling "VPN blade") because I don't have any gateway in Remote Access VPN community and not VPN Clients allowed, etc. we are not vulnerable. There's just a little lack of clarity on what is required for "VPN Remote Access" to be considered as enabled.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2026 20:12:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CVE-2026-50751-Help-with-some-questions/m-p/278354#M14011</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2026-06-11T20:12:38Z</dc:date>
    </item>
  </channel>
</rss>

