Medium [CVE-2026-48135] Check Point HTTP-based service can incorrectly handle malformed HTTP requests
This medium-severity Check Point advisory covers CVE-2026-48135 affecting Check Point, Security Gateway, Spark Firewall (Locally Managed).
Android app · Google Play
Monitor future Check Point CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A Check Point HTTP-based service, such as Mobile Access Portal or Identity Awareness Portals (except for Captive Portal), can incorrectly handle malformed HTTP requests. Gaia Portal is not affected by this issue.
The issue is related to HTTP request parsing and validation. The attacker can exploit this vulnerability leading to Denial of Service, HTTP header injection, or heap buffer overflow.
This issue affects: R82.10 with Jumbo Hotfix Take 6 or below R82 with Jumbo Hotfix Take 91 or below R81.20 with Jumbo Hotfix Take 127 or below All releases from R81.10 and below This issue received the ID CVE-2026-48135.
Affected products named by the advisory: Security Gateway; Spark Firewall (Locally Managed).
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 2 days ago·verify at source
- R82.10 Jumbo Hotfix Accumulator Take 19 or later
- R82 Jumbo Hotfix Accumulator Take 103 or later
- R81.20 Jumbo Hotfix Accumulator Take 141 or later
- R81.10 Jumbo Hotfix Accumulator Take 187 or later
Official advisory · high-confidence parse· fetched 2 days ago·verify at source
Mitigation checklist
- Mitigation Until the fix is installed, reduce exposure to the affected HTTP service. Recommended mitigation: Limit access to Check Point web-based services (Mobile Access Portal, Identity Awareness Portals) to trusted networks only. Allow access only from administrator networks, jump servers, VPN networks, or other trusted internal networks. Block access from untrusted networks. Do not allow direct access to the affected HTTP-based service from the Internet or from networks that do not require access. Disable unused web-based services or portals. If a web-based service, portal, or feature is not required in your environment, disable it or restrict access to it according to your organization's security policy. Use an explicit Access Control rule to restrict access. Configure rules that allow only trusted source networks to reach the relevant Check Point interface or service, and drop all other access attempts. Monitor logs for unexpected HTTP access attempts. Review connections to Check Point web-based services, especially from untrusted or unexpected source addresses. Solution This problem was fixed. The fix strengthens HTTP request validation.Mobile Access Portal and Identity Awareness Portals are monitored by the Check Point WatchDog service and will be automatically restarted after you install the fix.For Security Gateways, the fix is included in: Jumbo Hotfix Accumulator for R82.10 starting from Take 19 Jumbo Hotfix Accumulator for R82 starting from Take 103 Jumbo Hotfix Accumulator for R81.20 starting from Take 141 Jumbo Hotfix Accumulator for R81.10 starting from Take 187 For Spark Firewalls, see: R81.10.17 - sk183153 R82.00.10 - sk184357
Official advisory · high-confidence parse· fetched 2 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.