R82.10 Jumbo Hotfix Take 6

 

ID

Product

Description

Take 6

Released on 06 April 2026

Take 6 - New Functionality

 

PRJ-65396,
PRHF-32290

Identity Awareness

NEW: Added new OID (1.3.6.1.4.1.2620.1.38.55) to monitor the Identity Collector connection status in the $CPDIR/lib/snmp/chkpnt.mib file.

  • This capability is supported for Identity Collector agents running with version R82.120.0000 or higher.

PRJ-64974,
AAD-4768

VPN

NEW: Added support for nested groups with host/range/network objects for split tunnel on exclusion/inclusion options. Refer to R82.10 Remote Access VPN Administration Guide.

PRJ-64016,
PMTR-119998

VPN

NEW: It is now possible to add host/network/range objects for split tunnel on exclusion/inclusion modes. Refer to R82.10 Remote Access VPN Administration Guide.

Take 6 - Improvements and Resolved Issues

 

PRJ-65055,

PRJ-65041

Security Management

UPDATE: When connecting a Domain to the Check Point Portal, Dedicated Log Servers in the Domain are now connected automatically.

PRJ-65494,
PMTR-122413

Logging

UPDATE: SmartEvent now supports the "system alert" log type for URL Filtering and Application Control Software Blades.

PRJ-64478,

ODU-3143,

PRJ-64639,

ODU-3259,

PRJ-65289,

ODU-3387,

PRJ-66547,

ODU-3619,

PRJ-67136,

ODU-3714

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 155, Take 156, Take 157, Take 163, Take 164 via self-updatable package. Refer to sk170314.

PRJ-64906,
ODU-3275,

PRJ-67145,

ODU-3682

Automatic Updates - CPView

UPDATE: Added Take 210, Take 223 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522.

PRJ-64830,

ODU-3235

Automatic Updates - Threat Prevention

UPDATE: Added Take 27 of Autonomous Threat Prevention Management integration Release. Refer to sk167109.

PRJ-64543,

ODU-3199,

PRJ-64744,

ODU-3267

Automatic Updates - CPView

UPDATE: Added Take 52, Take 53 of CPquid (QUID) Release Updates. Refer to sk181458.

PRJ-67226,

ODU-3738

Automatic Updates - HCP

UPDATE: Added Update 26 of HealthCheck Point (HCP) Release. Refer to sk171436.

PRJ-65177,

ODU-3419,

PRJ-66383,

ODU-3435,

PRJ-67189,

ODU-3845

Automatic Updates - Policy Insights

UPDATE: Added Take 80, Take 82, Take 87 of Policy Insights Release Updates. Refer to sk183421.

PRJ-66729,

ODU-3666,

PRJ-67127,

ODU-3803

Automatic Updates - Log Exporter

UPDATE: Added Take 53, Take 60 to Log Exporter Auto Update Deployment. Refer to sk182866.

PRJ-66623,

ODU-3347

Automatic Updates - Security Management

UPDATE: Added Update 4 of Server-Side Change Report Generator Release Updates. Refer to sk179508.

PRJ-67139,

ODU-3698

Automatic Updates - CPView

UPDATE: Added Take 88 of CPViewExporter Release Updates. Refer to sk180521.

PRJ-67229,
ODU-3467

Automatic Updates - Threat Prevention

UPDATE: Added Update 28 of Autonomous Threat Prevention Management Integration Release. Refer to sk167109.

PRJ-64542,
PMTR-120942

Security Management

When using the "add/set data-type-weighted-keywords" and "add/set data-type-file-attributes" Management API commands, the field "description" is missing from the response.

PRJ-64703,

PRHF-42579

Security Management

Hitcount of NAT Rule Base fails after Security Management Server upgrade. Refer to sk184336.

PRJ-65810,

PRHF-43517

Security Management

The "show-packages" Management API command executed with "async-response" parameter may fail with "generic_err_invalid_parameter_name".

PRJ-64945,

PRHF-41803

Multi-Domain Security Management

On Multi-Domain Security Management Servers, custom Compliance Software Blade Best Practices may differ between the Multi-Domain Security Management level and the Domain level.

PRJ-65350,
PMTR-122267

Compliance

In some scenarios, scheduled Compliance scans are not executed after setting the intervals via the "set compliance-settings" Management API command.

PRJ-64468,
PRHF-42386

Logging

In some scenarios, exporting logs to CSV in SmartView fails and the LOG_INDEXER process unexpectedly exits. Refer to sk184475.

PRJ-65907,

PMTR-122146

Logging

In the "HTTPS Inspection Statistics" in SmartView, filtering by the "bypass_reason" field returns no results.

PRJ-64075,
SL-9462

Logging

In some scenarios, incorrect values are shown in the "Total Bytes" field in the logs.

PRJ-65820,

PMTR-122907

Security Gateway

When using a Security Gateway as a Proxy "Non-transparent" and HTTPS Inspection is set to "inspect" with "X-Forward-For header", video playback on YouTube fails.

PRJ-65227,

PRA-5005

Security Gateway

In a rare scenario, the FWK process may restart unexpectedly when the Security Gateway processes accelerated connections.

PRJ-64850,

PRJ-64783

Security Gateway

The FWK core dumps may be generated when the Security Gateway is processing HTTP traffic.

PRJ-64079,
PRHF-41256

Security Gateway

In scenarios where a network connection is closed before the Anti-Virus ThreatCloud emulation or scanning response is received, the affected session may experience connectivity instability.

PRJ-65781,

PRHF-40380

Security Gateway

When configuring NAT64 rules for specific targets, the rules may fail to apply. Return traffic may be dropped.

PRJ-65924,

PMTR-122717

Threat Prevention

In some scenarios, External Risk Management (ERM) enrichment for SSH connections may be incomplete, resulting in only partial contextual data or risk insights associated with the SSH session.

PRJ-66297,

PMTR-123479

Threat Prevention

In a rare scenario, the Threat Prevention Rule Base may fail to match traffic to any rule.

PRJ-66142,

PMTR-122910

Threat Prevention

File downloads may get stuck at 100% completion when either the Anti-Virus or Threat Emulation Software Blade is actively scanning the file.

PRJ-65834,

PRHF-42534

Identity Awareness

In a rare scenario, a Policy Decision Point (PDP) Security Gateway that acts as both an Identity Broker Subscriber and a sharing identity with a Policy Enforcement Point (PEP) may become unresponsive.

PRJ-64695,

PRHF-42522

Identity Awareness

When the Packet Tagging feature is enabled on the Full Identity Agent, new user and machine identity sessions reported to the Identity Awareness Gateway may not be assigned the correct Access Roles. As a result, traffic from these sessions may not match Access Control Policy rules that use Access Roles with Packet Tagging enabled.

PRJ-65900,

PRHF-41176

Identity Awareness

In a rare scenario, there may be no access to resources for identities received from the Remote Access identity source.

PRJ-64765,

PRJ-60821

Anti-Virus

False threat alerts may appear in Anti-Virus logs for benign traffic (action: accept). This is a cosmetic issue with no security impact.

PRJ-64114,

PRHF-41553

HTTPS Inspection

In some traffic flows, packets containing certain headers may be dropped regardless of how the non-compliant HTTP Inspection is configured.

PRJ-64497,

PRHF-42513

SSL Inspection

Running the "show cp-trusted-ca-certificate" Management API with invalid validFrom/validTo values in the database causes an error and blocks the Trusted Certificates view.

PRJ-64021,
PRHF-39978

Mobile Access

Mobile Access Software Blade may incorrectly terminate Guacamole-based clientless RDP/SSH sessions due to client idleness.

PRJ-64023,
PRHF-41229

Mobile Access

In rare scenarios, Mobile Access SmartConsole Logs may not match views/queries, including the "MAC address" or "Methods" field names.

PRJ-66156,
PRJ-58737

Mobile Access

After an upgrade, the Mobile Access Software Blade's CVPND process fails to load and the Mobile Access Portal becomes inaccessible when adding new Virtual Systems (VSs) or converting to a VSX Gateway, due to improper updates to the gateway-side configuration file cvpnd.C. Refer to sk183293.

PRJ-65452,

PMTR-121744

SecureXL

Permanently disabling the "cphwd_enable_ecmp" global parameter on a VSX Gateway using the "-f" option of the "fwl ctl set" command may fail.

PRJ-64959,

PRHF-38461

SecureXL

In an asymmetric UDP traffic scenario (Client-to-Site VPN and Site-to-Site VPN distributed to different members), the connection may not get accelerated.

PRJ-64796,

PMTR-121309,

PMTR-121673

SecureXL

The CX4 firmware does not update automatically as expected, and there is no error message indicating that the firmware is not the latest version.

PRJ-65602,

PMTR-122439

SecureXL

When SecureXL works in User Mode (UPPAK) on Security Gateways with CPAC-4-10F-C interface modules, invalid Ethernet frames permanently shut down the port's transmit queue, causing complete connectivity loss.

PRJ-65221,
PRHF-42915

Gaia OS

SNMP monitoring systems may report format errors related to the structure of the chkpnt.mib file.

PRJ-65527,
PRHF-43016

Gaia OS

Upon logging in to the Gaia Portal, the login page accepts the credentials, briefly displays the homepage, and then automatically redirects back to the login screen.

PRJ-65224,
PRHF-42944

Gaia OS

When integrating SNMP monitoring systems with Gaia OS, compilation of the GaiaTrapsMIB.mib file with the CHECKPOINT-MIB (chkpnt.mib) may fail. SNMP management stations or MIB browsers (such as HP OpenView, CA Spectrum, or HP Network Node Manager) return errors like "File GaiaTrapsMIB.mib failed to parse" or "ERROR : Cannot find symbol file://GaiaTrapsMIB.mib:Line XX:Column XX:multiDiskName".

PRJ-65858,

PMTR-122180

Gaia OS

Users cannot create read-only roles, cannot modify roles by removing permissions, or assign roles with all features to specific virtual servers, and all operations fail silently without warnings.

PRJ-65301,

PMTR-122146

Gaia OS

If multiple snapshots are stored on the Gateway server, creating a new snapshot fails with the "Cannot create snapshot, insufficient space in /boot" error, even though there is enough unpartitioned space.

PRJ-66998,

PRJ-67000,

PRJ-67034,

PMTR-124920,

PRHF-44366

VPN, Internal CA

Starting March 1st, 2026, newly created certificates and newly generated CRL may fail validation. Refer to sk184766.

PRJ-65904,

PMTR-122006

VSX

During interface reallocation between Virtual Systems (VSs) on a VSX Gateway, Management access (SSH/Gaia Portal) to VS0 may be disrupted after the interface move. Returning the interface to its original VS does not recover connectivity.

PRJ-65675,
PMTR-122185

VSX

When attempting to create a new Virtual System (VS) with management connectivity enabled, the operation may fail. This prevents the successful provisioning of the Virtual System in the environment.

PRJ-66176,
PMTR-122234

VSX

Creating a large number of Virtual Systems (VSs) simultaneously may intermittently fail.

PRJ-65243,

PMTR-121780

VSNext

After adding a virtual link between a Virtual System (VS) and a Virtual Switch (VSW), policy installation may fail with the "Installation failed. Reason: TCP connectivity failure [ error no. 10 ]" error.

PRJ-65484,

PRHF-43055

VSNext

Three out of four Virtual Systems (VS) on a single site may show a "Problem" Health status in the output of the "asg stat vs all" test. This is a cosmetic issue.

PRJ-65480,

PMTR-122468

Cloud Firewall

The Cloud Firewall Central License utility fails to distribute a single license using CLI.

PRJ-65593,

PMTR-122597

Cloud Firewall

When a new Cloud Firewall Gateway is added to the Security Management Server, and a security policy is installed, the Security Gateway may not appear in the Central License Tool (vsec_lic_cli). As a result, the Security Gateway fails to receive a central license.

PRJ-64443,

PRHF-42470

Scalable Platforms

Maestro Orchestrator fails to add a new Security Appliance to a Security Group when the Maestro Fastforward feature is enabled in the Security Group. Refer to sk184233.

PRJ-64394,
PMTR-119685

Scalable Platforms

When adding a subordinate to an LACP bond, a member may go down, which triggers a site failover.

PRJ-65637,

PMTR-122661

Scalable Platforms

After an upgrade in the Maestro and Chassis environment with multiple Virtual Systems (VSs), the disk may reach full capacity.

PRJ-65501,

PMTR-122485

Scalable Platforms

These actions applied through the Gaia Portal are not applied to all Security Group members, but only to the SMO:

  • create/delete/edit scheduled backup

  • edit mail-address/notification-level for mailing

  • delete backup

PRJ-65970,

PMTR-92125

Scalable Platforms

After creating a bridge interface using Gaia Portal and rebooting, the Security Gateway state is down.

PRJ-66016,

PMTR-123154

Scalable Platforms

Using a unique IP address with the Same VMAC feature enabled may cause connections to the Standby unique IP address to fail.

PRJ-65965,

PMTR-120383

Scalable Platforms

Link-local per-member address calculation between ElasticXL members may not be correct.

PRJ-64505,
CST-399

Carrier Security

Policy installation fails with an internal error when the Security Gateway policy includes rules that match a specific Access Point Name (APN) for GTPv0 or GTPv1 traffic.