R82.10 Jumbo Hotfix Take 44

 

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 44

Released on 09 September 2026

Take 44 - New Functionality

 

PRJ-70073,
PMTR-129515

Security Management

NEW: Introducing the show-ad-content Management API, which enables the retrieval of users, groups, and machines from Active Directory.

PRJ-69930,
HEC-2296

Scalable Platforms

NEW: The Virtualization Screen is added to VS0 Insights, displaying Virtual Systems statistics, including Virtual Systems problem detection, alongside general environment metrics and the Resource Search tool.

  • Resource Search Tool: Provides a cross Virtual Systems interface search capability.
  • Problem Detection: Introduces Virtual System problem indicators in the Status and Problem Categories columns, showing problem classifications. Users can select a Virtual System row in the Virtual Systems table to re-launch Insights in the Virtual System context and investigate issues in AI Detector.

PRJ-69930,
HEC-2296

Scalable Platforms

NEW: Added support for integrating clean-install machines running a higher version into an existing ElasticXL environment.

Take 44 - Improvements and Resolved Issues

 

PRJ-71128,
ODU-4470,

PRJ-71612,

ODU-4598

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 177 and Take 178 of Web SmartConsole. Refer to sk170314.

PRJ-66288,
PRHF-43807

Automatic Updates - Smart-1 Cloud

UPDATE: After running the Get Interfaces command, updating VTI interface objects can fail on Spark Firewall clusters if VPN peer names were changed.

PRJ-71253,

ODU-4492

Automatic Updates - HCP

UPDATE: Added Take 95 of HealthCheck Point (HCP) Release Updates. Refer to sk171436.

PRJ-68592,
PMTR-127145

Automatic Updates - HCP

UPDATE: The HCP configuration sync verifier (the config_verify command) may incorrectly indicate a mismatch in the fwkern.conf file due to differences in the line order between members.

PRJ-71380,

ODU-4591

PRJ-71257,

ODU-4477

Automatic Updates - Policy Insights

UPDATE: Added Take 97 and Take 98 of Policy Insights Release Updates. Refer to sk183421.

PRJ-71315,

ODU-4456

Automatic Updates - CloudGuard Network

UPDATE: Added Take 10 of CloudGuard Controller Release Updates. Refer to sk181842.

PRJ-71262,

ODU-4484

Automatic Updates - CloudGuard Network

UPDATE: Added Take 325 of CME (Cloud Management Extension) Release Updates. Refer to sk157492.

PRJ-64532,

PRHF-42420

Security Management

UPDATE: In environments with hundreds of users and user groups, policy installation duration is significantly improved.

PRJ-69265,
PMTR-127012

Security Management

UPDATE: Added support for the match-settings parameters in the application-site Management API.

PRJ-65272,
PRHF-42905

Security Management

UPDATE: In environments with thousands of Domain objects or External User Groups, the policy installation duration has been significantly improved.

PRJ-65539,
PRHF-42643

VPN

UPDATE: When OCSP certificate validation fails, the Security Gateway now automatically falls back to CRL validation. Manual configuration via the Check Point Registry (described in Scenario 2 in sk179434) is no longer required.

PRJ-66689,
PRHF-40230

VPN

UPDATE: Added support for treating trusted CA certificates with non-compliant attributes as valid. This includes certificates with incorrect Key Usage settings or missing Basic Constraints, based on customer-defined configurations. Refer to sk183800.

PRJ-71484,

PMTR-131442

VPN

UPDATE: Resolved CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN. Refer to sk1000117.

PRJ-71550,

PMTR-131527

VPN

UPDATE: Resolved CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution. Refer to sk1000118.

PRJ-70789,
PRHF-39412

Security Management

In some scenarios, when attempting to view a revision in SmartConsole, it unexpectedly crashes after several minutes with the error message: “SmartConsole has experienced a serious problem and needs to relaunch.

PRJ-67614,
PRHF-44583

Security Management

In a Management High Availability environment, the statuses of clusters and cluster members may be displayed incorrectly on the secondary Security Management Server.

PRJ-70409,
PRHF-46322

Security Management

In an environment with multiple Multi-Domain Security Management (MDS) Servers, High Availability synchronization between MDSs may intermittently fail with the "NGM failed to import data" error message because of missing VSEC license objects in the secondary MDS database.

PRJ-67854,
PRHF-45034

Security Management

In rare scenarios, login to SmartConsole may fail due to a timeout.

PRJ-65797,
PMTR-120362

Security Management

Changes made to .def and .conf files are not applied during an accelerated policy installation if a previous policy installation failed after the files were updated.

PRJ-70495,
PRHF-43991

Security Management

Policy installation may fail with error code 0-2-2000078 when a policy rule references a track object that cannot be resolved.

PRJ-69443,
PRHF-45656

Security Management

Accelerated policy installation may be skipped if Compliance generates a high number of audit log entries between sessions.

PRJ-70230,
PRHF-45998

Security Management

In some scenarios, when a Multi-Domain Security Management Server is connected to the Check Point Portal, a connectivity failure warning for the Global SmartEvent server may appear, even though Global SmartEvent servers are not supported in the Check Point Portal.

PRJ-67813,
PMTR-126383

Security Management

Disk space on the Security Management Server may become depleted due to the excessive growth of internal PostgreSQL database tables.

PRJ-70415,
PRHF-40980

Security Management

On a Multi-Domain Security Management Server, the "api stats-group-by-domain" command may report all requests as "unknown domain" instead of categorizing them per domain. Refer to sk183892.

PRJ-68349,
PRHF-45145

Security Management

In some scenarios, running the show access-rulebase Management API command with a non-existent object identifier could return an HTTP 500 error with a "Null Pointer Exception" error message.

PRJ-69188,
PRHF-45542

Security Management

When generating a Show Changes PDF report for a workflow or session, the report could include internal system changes, such as IPS protection changes, that were not performed by the user.

PRJ-70414,
PRHF-41422

Security Management

The "mds_restore" command may not restore audit logs at the MDS level.

PRJ-70384,
PMTR-129271

Security Management

SmartConsole may display a "No communication" error message caused by a file descriptor leak in the FWMHA process after prolonged uptime.

PRJ-66787,
PRHF-43884

Security Management

In SmartConsole, a network object that is no longer referenced by any policy may fail to be deleted with an "object is being used" error message.

PRJ-67611,
PRHF-44814

Security Management

In unpublished sessions, the Change report may not display the names of newly created objects when these objects are added as members of another object.

PRJ-64481,
PRHF-42459

Security Management

In some scenarios, desktop policy installation fails with a "Could not find type of Network Object 'ReferenceObject'. Desktop policies will not be installed on Policy Servers" error message.

PRJ-70233,
PRHF-46050

Security Management

After deleting a Security Management Server object, attempting to create a new management host object with the same IP address may fail with an "IPv4 address is already in use" validation error.

PRJ-67756,
PRHF-44852

Security Management

Policy installation may fail when custom authentication .ttm files are not included during policy package preparation, resulting in a "No such file or directory" error message.

PRJ-67761,
PRHF-44799

Security Management

Improved debug logging in the cpm.elg file during upgrades of a Multi-Domain Security Management Server.

PRJ-67777,
PMTR-126316

Security Management

Snort IPS protections are not downloaded to the local domain during Global Policy Assignment.

PRJ-69865,
PRHF-45625

Security Management

When one administrator installs a policy, other logged-in administrators may see an "Error retrieving results" message in the Tasks window instead of the policy installation progress.

PRJ-70500,
PMTR-129992

Security Management

New licenses may not be synced to the Check Point Portal if the license expiration date includes a single-digit day.

PRJ-69862,
PRHF-46038

Security Management

Administrators logging into SmartConsole with certificate authentication at the MDS level using the "\MDS" format may unexpectedly receive read-only permissions instead of the expected read-write access.

PRJ-67764,
PRHF-44772

Security Management

In rare scenarios, deleting a Secondary Security Management Server fails because it references objects that no longer exist.

PRJ-67496,
PRHF-44700

Security Management

In rare scenarios, the accumulation of large API request-status files could cause Security Management Server slowness.

PRJ-68288,
PRHF-44951

Security Management

Policy objects may fail to open in Web SmartConsole with a "Something went wrong" error message.

PRJ-69393,
PRHF-45724

Security Management

Security Gateways created using the Management API or SmartConsole might be assigned duplicate Dynamically Assigned IP (DAIP) addresses. Refer to sk185077.

PRJ-71005,

PRHF-46361

Security Management

In some scenarios, logging into SmartConsole may fail or time out.

PRJ-71301,

PRHF-46484

Security Management

When a Data Center object is imported into SmartConsole and the session is discarded, the object may not be removed and might remain visible in SmartConsole.

PRJ-70783,

PRHF-46219

Security Management

In SmartConsole, selecting a value in a filter category within the Gateways & Servers view may cause other options in that category to disappear, preventing the selection of multiple filter values simultaneously.

PRJ-71562,

PRHF-47729

Security Management

In some scenarios within Multi-Domain Security Management environments, AI Assist may display the following error message: "There was an internal error processing the query".

PRJ-70588,
PRHF-46795

Multi-Domain Management

The mds_backup command does not include the configuration of MDS-level log exporters in the backup.

PRJ-68527,
PRHF-45066

SmartProvisioning

When running the LSMcli AddROBO command with the -S (SubstitutedNamePart) parameter, the cluster profile name suffix may not be substituted correctly.

PRJ-67346,
PRHF-44310

Logging

In rare scenarios, the LOG_INDEXER process may crash unexpectedly due to improper memory handling.

PRJ-69042,
PRHF-36102

Logging

When viewing Forensics Reports in SmartView through the Check Point Portal, non-ASCII characters may appear distorted.

PRJ-69247,
PRHF-45525

Logging

When right-clicking the "*_interface" field in the SmartView Logs web view and selecting Add as Filter, the query may fail, resulting in no logs being displayed.

PRJ-68885,
PRHF-45417

Logging

Exporting logs that contain "&" in their fields to a CSV file via SmartView web application may fail with a “Failed to export” error message.

PRJ-65855,
PRHF-41245

Logging

In some scenarios, the Service field may not appear in logs for certain connections, primarily for dropped traffic, even when destination port information is available in the raw log.

PRJ-67638,
PMTR-125374

Logging

In some scenarios, the LOG_INDEXER process may crash repeatedly, causing core dumps on the Security Management server.

PRJ-69437,
PMTR-126941

Logging

The LOG_INDEXER process on the Security Management Server may generate a core dump due to a memory handling issue.

PRJ-69987,
PRHF-46185

Logging

When viewing logs in the Check Point Portal, a "Query failed" error message may intermittently appear for several minutes.

PRJ-70649,
PRHF-46562

Logging

In Smart-1 Cloud, the status of a Dynamically Assigned IP (DAIP) Gateway may be incorrectly displayed as "Connection Lost", even when the Gateway is successfully connected and policies are installed.

PRJ-69457,

PMTR-126981

Logging

In some scenarios, the LOG_INDEXER process may unexpectedly exit and generate a core dump while processing log files.

PRJ-66300,
PRHF-43833

Security Gateway

The FWK process may unexpectedly restart because of an incorrect integration with CPView.

PRJ-70037,
PRHF-46215

Security Gateway

In some scenarios, incorrect memory size allocation identified in the c_icap open-source code may cause a crash in the ICAP Server.

PRJ-68603,
PRHF-45088

Security Gateway

Threat Prevention inspection of Server Message Block (SMB) traffic during CREATE+WRITE operations may cause a memory leak during file write processes.

PRJ-65315,
PRHF-38547

Security Gateway

In a rare scenario, the Security Gateway may crash during email inspection.

PRJ-70363,
PRHF-46526

Security Gateway

In some scenarios, a memory leak in the FWK process occurs when two HTTP/2 upgrade requests are sent over the same connection.

PRJ-69103,
PRHF-45611

Security Gateway

The RAD daemon may unexpectedly exit on VSX Gateways.

PRJ-66071,
SWSCFG-654

Security Gateway

The PDPD daemon may encounter high CPU utilization when Nested Groups query method 5 (query by SIDs) is in use. Refer to sk183748.

PRJ-66836,
PRHF-43754

Security Gateway

In some scenarios, CPView may display an incorrect value for CPU user time. Refer to sk184722

PRJ-66082,
PRHF-43723

Security Gateway

Policy installation on Centrally Managed Spark Firewall fails with the error "Dynamic object in the translated source column cannot be resolved" . Refer to sk184599.

PRJ-65549,
PRHF-42950

Security Gateway

Optimized DNS handling to align with the DNS additional configuration formats.

PRJ-67540,
PRHF-44757

Security Gateway

In some scenarios, multicast traffic and a race condition during route lookup may lead to a crash in the Security Gateway.

PRJ-69501,
PRHF-40443

Security Gateway

In some cases, an ICAP server closing the connection to an ICAP client with an RST may cause an FWK process crash.

PRJ-70302,
PRHF-46417

Security Gateway

In some scenarios, servers sent compressed data with Content-Encoding: deflate but included an additional zlib header (starting with 78 01), while the Security Gateway expected raw deflate data without any header.

PRJ-70522,
PRHF-46706

Security Gateway

Some valid HTTP requests may be incorrectly identified as malformed and blocked.

PRJ-67915,
PRHF-41891

Security Gateway

In some scenarios, the Security Gateway may not close connections properly when a device stops responding during an active download, leading to a gradual memory leak over time.

PRJ-70545,
PRHF-46784

Security Gateway

An issue in the parsing function may cause the FWK process to crash when handling an MCP connection.

PRJ-69871,
PRHF-46057

Security Gateway

The ROUTED process may restart unexpectedly when using the DHCPv6 relay code.

PRJ-70424,
PMTR-129903

Security Gateway

In a Smart-1 Cloud cluster environment, users may not see the cluster member status in Netscout if ICMP traffic is blocked.

PRJ-67418,
PMTR-124725

Security Gateway

In some scenarios, the ICAP Server may crash because of memory issues.

PRJ-66557,
PRHF-43835

Security Gateway

In rare scenarios, a Security Gateway may crash when LSP (Link State Propagation) is enabled.

PRJ-64698,
PRHF-41674

Security Gateway

In a Maestro VSX environment, Layer 2 MAC address table in Bridge Mode (Bridge Forwarding Database) entries may be incorrectly deleted, causing connectivity issues.

PRJ-70134,
PMTR-129198

Security Gateway

When using ISP Redundancy in a VSNext environment, failover between ISPs may not occur if the WRP interface is configured as one of the ISPs.

PRJ-67802,
PRHF-45012

Security Gateway

When a user configures NAT to convert a connection's destination IP address from unicast to multicast, the Security Gateway may transmit packets with an incorrect MAC address when SecureXL is enabled.

PRJ-66844,
PRHF-26696

Security Gateway

In some cases, the Captive Portal fails to authenticate users when SAML authentication is enabled.

PRJ-66266,
PRHF-43044

Security Gateway

The FWK process may restart unexpectedly due to improper handling of a connection.

PRJ-69206,
PRHF-45101

Security Gateway

In some scenarios, Spike Detective file descriptors may remain undeleted.

PRJ-64887,

PRHF-40560

Security Gateway

Enhanced stability when manual edits to the fwkern.conf file result in a malformed configuration. To manage the file, it is recommended to use the -f option of the fw ctl set command, as detailed in sk26202. Refer to sk184081.

PRJ-70508,
PMTR-130005

Threat Prevention

In certain scenarios, the Security Gateway may fail to apply a new GeoIP database update.

PRJ-69949,

PRHF-46128

Threat Prevention

The Anti-Virus may fail to load external IOC feeds that contain URL-type observables.

PRJ-69350

Threat Extraction

In some scenarios, malicious emails processed by MTA Security Gateways may fail to include the configured custom text in the email body.

PRJ-65681,
PRHF-43309

Threat Emulation

Files without extensions were receiving a Scan Pass verdict from the ICAP server. As a result, malicious files without extensions were also assigned a Scan Pass verdict, which ultimately led to a Benign classification.

PRJ-67051,
PRHF-34201

Identity Awareness

In some scenarios, errors in rule number calculation prevented packet tagging from working.

PRJ-69217,
PRHF-39546

Identity Awareness

Improved handling of duplicate Identity Collector events on the PDP Security Gateway.

PRJ-69105,
PRHF-45589

Identity Awareness

In rare scenarios, the FWK process may exit unexpectedly on the PEP side when Identity Sharing is configured to receive identities from remote PDPs.

PRJ-70210,
PRJ-70209

IPS

In some scenarios, the Packet Capture option is missing from IPS logs in SmartConsole.

PRJ-67475,
PRHF-44623

SSL Inspection

In some scenarios, a memory leak may occur in the WSTLSD process when it fails to decode a certificate.

PRJ-67478,
PRHF-44630

SSL Inspection

Certificate validation may fail for certificates containing an ASN.1 NumericString in the X.509 Subject attribute.

PRJ-65973,
PRHF-43606

SSL Inspection

In rare cases, NAT may have been incorrectly identified in specific probing scenarios during HTTPS inbound inspection.

PRJ-64265,
PRHF-41806

ClusterXL

In scenarios involving asymmetric traffic, where the same connection tuple is reused frequently, connections may be dropped and flagged as "out of state". Refer to sk184181.

PRJ-64366,
PRHF-33964

SecureXL

In some scenarios, the Security Gateway may not properly remove closed TCP connections, processed through Active Streaming, from its accelerated connections table if a new security policy was installed beforehand.

PRJ-66074,
PRHF-43570

SecureXL

In rare scenarios, a performance issue may occur when a policy is installed on multiple Virtual Systems simultaneously. Refer to sk184585.

PRJ-67270,
PMTR-125173

SecureXL

In some scenarios, the Security Gateway may restart unexpectedly when passing traffic through LightSpeed hardware acceleration interfaces with SecureXL User Mode enabled.

PRJ-66862,
PMTR-124252

SecureXL

In some scenarios, the VSX Gateway may unexpectedly restart when passing traffic through a Virtual Switch with SecureXL User Mode enabled.

PRJ-67118,
PMTR-120253

SecureXL

In some scenarios, the VSX Gateway may experience significant latency when passing traffic between Virtual Systems through a Virtual Router.

PRJ-70355,
PMTR-127257

SecureXL

In some scenarios, the VSX Gateway may not properly assign CPUs to a Firewall instance or SND after booting up when SecureXL User Mode is enabled.

PRJ-67773,
PMTR-119674

SecureXL

In some scenarios, the VSX Gateway may experience poor performance when passing traffic between Virtual Systems through a Virtual Switch with SecureXL User Mode enabled.

PRJ-70925,
PRHF-46835

SecureXL

In certain scenarios, the VSX Gateway may transmit packets with incorrect MAC addresses for cleartext connections when SecureXL is enabled, specifically when these packets are sent through a Virtual Router or Virtual Switch.

PRJ-70345,
PMTR-129663

Routing

In some cases, the ROUTED daemon incorrectly identified itself as a slave on both cluster members after boot, causing ROUTED PNOTEs to remain permanently set.

PRJ-69979,
PRHF-45943

Routing

In some scenarios where the SPT cannot be set on an entry with the Decap bit enabled, the Decap bit is now reset to ensure that incoming Register packets can be processed.

PRJ-70631,
PMTR-126125

Routing

When receiving an equal-cost LSA from two different ASBRs, only one next hop was previously installed for the route. Now, all relevant next hops are installed.

PRJ-69853,
PMTR-128972

VSNext

A connectivity issue may occur in DNS per-virtual-system after an upgrade because of a missing configuration file.

PRJ-70467,
PMTR-129616

VSNext

VLAN filtering was incorrectly enabled on VSNext bridges, causing traffic to be tagged with VLAN 1 or dropped.

PRJ-69973,
PMTR-129426

VSNext

In Maestro in VSNext mode, using a Virtual Switch with a data interface as the management interface may cause traffic flapping due to incorrect MAC address assignments between the members.

PRJ-70715,
PMTR-130236

VSNext

Creating a new Virtual System with an automatically assigned ID could fail after a failover, displaying an error that the Virtual System ID already exists.

PRJ-70128,
PMTR-129435

VSNext

MTU changes made to a WRP interface are now automatically propagated to the corresponding WRPJ interface.

PRJ-68695,
PRHF-45292

Traditional VSX

In rare scenarios, a crash may occur in Traditional VSX during a call to kmem_cache_alloc.

PRJ-69461,

PMTR-128480

Traditional VSX

In a Traditional VSX environment, the active slave in an HA bond may become misaligned between cluster members if a primary interface is not explicitly set, potentially causing traffic disruptions.

PRJ-70019,
PMTR-129289

Gaia OS

In a rare scenario, the CPU time may be displayed incorrectly.

PRJ-66703,
PRHF-43888

Gaia OS

Duplicate interface configuration entries appear in the show configuration command output. Refer to sk184759.

PRJ-64572,
PRHF-42478

Gaia OS

After backup and restore, Gaia Portal enforces 2FA, but Clish allows password-only login and does not prompt fora 2FA code. Refer to sk184285.

PRJ-68824,
PRHF-45237

Gaia OS

Gaia backup operations may fail when using the EXT file system.

PRJ-70120,
PRHF-45729

Gaia OS

When syslog messages are forwarded to the Security Management Server using the set syslog cplogs on command, they may be misclassified under an incorrect blade instead of Syslog. This misclassification can make it challenging to filter, correlate, and analyze the logs effectively.

PRJ-69097,
PRHF-45473

Gaia OS

Clish may crash when running the show virtual-system all command under specific conditions.

PRJ-69618,
PRHF-45826

Gaia OS

The show arp dynamic all Clish command displays (null) MAC address for 15-character IP addresses. Refer to sk185044.

PRJ-69255,
PMTR-126101

Gaia OS

In some scenarios, the Security Gateway may fail to access interface data correctly when SecureXL User Mode is enabled.

PRJ-68606,
PRHF-44741

Gaia OS

In rare scenarios, the Security Gateway may unexpectedly crash due to timer corruption.

PRJ-65075,
PRHF-41841

Gaia OS

When the backup file size is large, export to Microsoft Azure may fail. Refer to sk184010.

PRJ-69553,
PRHF-45732

Gaia OS

Performance improvements have been made to the VSX interface configuration process.

PRJ-70691,
PRHF-46741

Gaia OS

Added the ability for remote TACACS+ superusers to switch between Virtual Systems in the Gaia Portal.

PRJ-67683,
PRHF-44353

Gaia OS

On Check Point Firewall 3600/3600T/3800 appliances, the fan Speed was incorrectly reported as higher than the maximum threshold value (roughly double the actual value). This was a cosmetic reporting issue, the fan operates normally. Refer to sk185065.

PRJ-66896,
PRHF-44101

Gaia OS

In some scenarios, duplicate interface entries appear in the output of the "show configuration" Clish command.

PRJ-70352,
PRHF-46504

Gaia OS

Adjusted the file permissions for systemd service files.

PRJ-69601,
PRHF-44863

Gaia OS

A change in shared memory (shmem) behavior may potentially cause a freeze on Management appliances.

PRJ-67668,
PMTR-125850

Gaia OS

Aligned Gaia Portal behavior with Gaia Clish, allowing usernames to begin with a number in the Gaia Portal.

PRJ-69901,
PRJ-70325

Gaia OS

NTP synchronization failure when using IPv6.

PRJ-69469,
PRHF-45709

Gaia OS

Updated Neighbor Advertisement logic to set the Router (R) flag to 1 for cluster-generated IPv6 NAs, ensuring RFC 4861 compliance and maintaining stable IPv6 connectivity by preventing hosts from removing the cluster IPv6 Gateway from their Default Router List. Refer to sk185119.

PRJ-67300,
PRHF-44576

Mobile Access

The Mobile Access Blade portal may not function properly with web applications that set HTTP cookies containing the pipe ('|') character in their values.

PRJ-71455, PRHF-47521

Mobile Access

In some scenarios, users can connect to Mobile Access/SSL Network Extender, but do not have access to internal resources after upgrading. Refer to sk185259.

PRJ-70686,
PRHF-46758

VPN

Capsule Connect / VPN users are unable to log in and receive the error message "Client's configuration is not verified". Refer to sk185144.

PRJ-70578,
PRHF-46735

VPN

In rare scenarios, the VPND process may crash during Capsule VPN connections that use Mobile Device Management (MDM) compliance and certificate-based authentication.

PRJ-69752,
PMTR-128892

VPN

Enhanced stability and reliability in IKEv2 certificate handling.

PRJ-67112,
PRHF-44004

VPN

VPND and IKED processes keep restarting after upgrading in environments with multiple VTI interfaces. Refer to sk184895.

PRJ-69692,
PMTR-128831

VPN

Enhanced stability in IKEv2 session establishment.

PRJ-66902,
PMTR-123203

VPN

EDPC tunnel establishment failure after MEP failover to a new Security Gateway.

PRJ-69736,
PMTR-128876

VPN

Improved stability and robustness in VPN session message handling during connection flows.

PRJ-65403,
PMTR-122348

VPN

Improved stability for Permanent Tunnel functionality when using Tunnel Test UDP/18234 in Maestro environments.

PRJ-70269,
PRHF-46350

VPN

In some scenarios with DAIP peers, VPN tunnel tests may fail, causing intermittent disruptions.

PRJ-69881,
PRHF-45871

VPN

High CPU utilization may occur without a corresponding indication of heavy web connection load.

PRJ-70423,
PMTR-125534

VPN

Enhanced the Gaia Clish command vpn(6) overlap_encdom to display overridden encryption domains in VPN Communities.

PRJ-65763,

PMTR-127758

VPN

Improved IKEv2 stability when handling concurrent IKE messages that share the same IKE cookies.

PRJ-69778,
PMTR-128918

VPN

Improved stability in VPN tunnel monitoring workflows.

PRJ-69769,
PMTR-128909

VPN

Added Layer Two Tunneling Protocol (L2TP) stabilization improvement.

PRJ-67860,
PRHF-44977

VPN

In rare scenarios between an LSM Central Gateway and an LSM Satellite Gateway, the Route Injection Mechanism (RIM) may not function correctly.

PRJ-66944,
PRHF-44104

SD-WAN

In a Traditional VSX deployment, the SD-WAN steering process may generate core dumps, even if SD-WAN is not configured on the machine.

PRJ-70375,
PMTR-129571

Cloud Firewall

The vsec_lic_cli view command now marks Certificate Keys with expired contracts as (Expired) and provides warnings for Certificate Keys that require renewal.

PRJ-70116,
CGNSIS-2240

Cloud Firewall

Nightly distribution may fail when no default license pool is set. The system now automatically promotes an available pool during distribution.

PRJ-70059,
PMTR-129147

Cloud Firewall

Reinstalling a Cloud Firewall central license with a regenerated signature may create a duplicate entry in the Management Server's license repository, which could prevent license distribution to managed Security Gateways. The Management Server now detects such conflicts and blocks the installation to avoid creating duplicates.

PRJ-70188,
PRJ-70902

Scalable Platforms

NTP may not function properly after an upgrade.

PRJ-70253,
PMTR-126562

Scalable Platforms

On Maestro running in VSNext mode, configuring a data.vlan interface as the management interface does not update the MHO's uplink with the corresponding VLAN ID.

PRJ-70985,
PMTR-130438

Scalable Platforms

In VSNext environments, creating a management bond interface via gClish using the command add bonding group <Mgmt interface> may fail with the error "this interface is already in use".

PRJ-71350,

PMTR-129846

Scalable Platforms

On Check Point Firewall 3970 and 3980 appliances with a physical Sync port, in an ElasticXL configuration, the Sync bond may come up without its member interface. This prevents cluster synchronization, causing the member to remain in a DOWN state. Refer to sk185241.

See the Critical Information section.

PRJ-70923

Scalable Platforms

After uninstalling an upgrade, the permissions on the $SMODIR/lib directory and related libraries may become more restrictive than required. As a result, the Gaia Portal fails to load pages. Refer to sk185178.

PRJ-67218,
PMTR-124993

Scalable Platforms

A newly joined member may come up with the wrong sync IP in an ElasticXL deployment with Check Point Firewall 3900 appliances.