For Site to Site VPN, disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 for the specific peer IP addresses.
Note: This mitigation option is not applicable to the locally managed Spark Firewall.
This problem was fixed.
Option 1: If you have enabled automatic installation of Check Point LivePatch, you are already protected.
| Version | Take Number | Download Package |
| R82.10 | BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE take 24 |
(TAR) |
| R82 | BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE take 24 | (TAR) |
| R81.20 | BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE take 24 | (TAR) |
To validate that LivePatch is properly installed and active, run the cpinfo -y CPupdates command on the Security Gateway / ClusterXL member in Expert mode and validate that you have BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE Take 24
Example:
[Expert@Host:0]# cpinfo -y CPupdates [CPUpdates] BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE Take: 24
For LivePatch validation, run in Expert mode:
Expected output:
cpcert:cpca* CVE-2026-85102 CVE-2026-85103 cpcert:iked* CVE-2026-85102 CVE-2026-85103 cpcert:vpn* CVE-2026-85102 CVE-2026-85103 cpcert:vpnrad* CVE-2026-85102 CVE-2026-85103 cpcert_cprid:cprid* CVE-2026-85102 CVE-2026-85103
Option 2: The fix is also included in: