# Multiple vulnerabilities in Check Point Security Gateways and Spark Firewalls enable…

Published: 2026-05-27 · Severity: high
Canonical: https://vorant.io/reports/ba0a1b33-be4b-4e3a-8a41-e5ce311520f5/multiple-vulnerabilities-in-check-point-security-gateways-and-spark-firewalls

> Multiple vulnerabilities in Check Point Security Gateways and Spark Firewalls enable remote denial of service, data confidentiality breaches, and integrity compromise.

CERT-FR has published an advisory detailing multiple vulnerabilities affecting Check Point Security Gateways and Spark Firewalls. The flaws impact Security Gateways running R81.20 (without patch 141), R82 (without patch 103), and R82.10 (without patch 19), as well as Spark Firewalls versions R81 prior to R81.10.17 and R82 prior to R82.00.10. Six CVEs have been assigned to these issues (CVE-2026-48131 through CVE-2026-48136).

The vulnerabilities enable various attack vectors including remote denial of service, SQL injection, security policy bypass, and compromise of data confidentiality and integrity. Check Point has released patches for all affected versions, documented across six separate security bulletins published on May 26, 2026.

Organizations running affected Check Point firewall products should prioritize applying the vendor-supplied patches. Given that these are perimeter security devices and the range of potential impacts includes policy bypass and remote exploitation, prompt remediation is essential to maintain network security posture.

## Mentioned in this report

- Vulnerabilities: CVE-2026-48131, CVE-2026-48132, CVE-2026-48133, CVE-2026-48134, CVE-2026-48135, CVE-2026-48136

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0650

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ba0a1b33-be4b-4e3a-8a41-e5ce311520f5/multiple-vulnerabilities-in-check-point-security-gateways-and-spark-firewalls.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
