Check Point Software Technologies製品の脆弱性対策について(CVE-2026-50751)

Imported from official source

Announcement

Check Point Software Technologies社より、UTM製品に関する脆弱性が公表されました。

不適切な認証の脆弱性(CVE-2026-50751)が確認されています。
本脆弱性を悪用された場合、遠隔の第三者によって、当該製品における認証を回避される可能性があります。

製品開発者は、本脆弱性を悪用する攻撃を確認していると公表しています。
今後被害が拡大するおそれがあるため、製品開発者が公表している手順に従い、ホットフィックスの適用を実施してください。

また、攻撃に関連する IP アドレスや調査用クエリについても公表されています。
製品開発者が公開している手順に従い、悪用が生じていないかどうか、ログを確認してください。

  • Security Gateways R82.10 Jumbo Hotfix Take 19以下
  • Security Gateways R82 Jumbo Hotfix Take 103以下
  • Security Gateways R81.20 Jumbo Hotfix Take 141以下
  • VPN Remote Access または Mobile Access が有効であること
  • 開発者が提供する情報をもとに、ホットフィックスの適用をしてください。開発者は、本脆弱性を修正した次のホットフィックスをリリースしています。

  • Security Gateways R82.10 Jumbo Hotfix Accumulator Take 19
  • Security Gateways R82.10 Jumbo Hotfix Accumulator Take 6
  • Security Gateways R82 Jumbo Hotfix Accumulator Take 103
  • Security Gateways R82 Jumbo Hotfix Accumulator Take 91
  • Security Gateways R81.20 Jumbo Hotfix Accumulator Take 141
  • Security Gateways R81.20 Jumbo Hotfix Accumulator Take 127
  • Security Gateways R81.20 Jumbo Hotfix Accumulator Take 120
  • Security Gateways R81.20 Jumbo Hotfix Accumulator Take 113
  • Spark Firewalls R82.00.10 Build 998002216
  • Spark Firewalls R81.10.17 Build 996004901
  • 影響を受けるシステムにはサポート終了(EOS)の状態のものが含まれます。EOS 製品のついては、ライフサイクルポリシーなどの製品開発者からの情報などを踏まえ、移行等の対応を検討してください。

    https://www.checkpoint.com/jp/support-services/support-life-cycle-policy/

    This is an extract. The publication continues at the source.

    Read the original at the source: https://www.ipa.go.jp/security/security-alert/2026/alert20260610.html

    Officially imported this from Information-technology Promotion Agency (IPA)’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Information-technology Promotion Agency (IPA) — imported from official source
    Official source
    https://www.ipa.go.jp/security/alert-rss.rdf RSS
    Imported
    October 03, 2026 20:39
    Versions
    1 recorded
    Identity
    https://www.ipa.go.jp/security/security-alert/2026/alert20260610.html

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.