R82 Jumbo Hotfix Take 73
|
|
Note - This Take contains all fixes from all earlier Takes. |
|
ID |
Product |
Description |
|---|---|---|
|
Take 73 Released on 17 February 2026 |
||
|
Take 73 - New Functionality
|
||
|
PRJ-64015, |
VPN |
NEW: It is now possible to add host/network/range objects for split tunnel on exclusion/inclusion modes. Refer to R82 Remote Access VPN Administration Guide > Dynamic Split Tunneling for SaaS Using Updatable Objects. |
|
PRJ-65355, |
CPView |
NEW: Added the new Skyline metric "system.traffic.templates". Refer to the Skyline Administration Guide > Skyline Metrics Repository > System > Traffic. |
|
PRJ-65719 |
Security Management |
NEW: Now you can manage Harmony SASE Internet Access policy and HTTPS Inspection policy directly from SmartConsole. By centralizing policy management, the integration ensures consistent policy enforcement across products, streamlines governance for security policies, and consolidates operations into one trusted, management platform. |
|
Take 73 - Improvements and Resolved Issues
|
||
|
PRJ-62103, PMTR-116716 |
Harmony Endpoint |
UPDATE: Check Point response to Apache Tomcat CVEs on Harmony Endpoint Security Management Server - CVE-2025-31651 and CVE-2025-31650. Refer to sk183615. |
|
PRJ-64185, |
Security Management |
UPDATE: JRE updated from version 8.0_8.35 to version 8.0_8.50 |
|
PRJ-62361, |
Security Management |
UPDATE: Policy verification error messages are now improved for scenarios when verification fails because of updatable objects, dynamic objects, and Domain objects in a Remote Access VPN community. |
|
PRJ-63719, PMTR-119125 |
Gaia OS |
UPDATE: Added ability to use the '.', '@', '~', ',' characters for non-local users using the Clish command "set aaa allow-unsanitized-username enable <all/dot/at/comma/tilde>". Refer to sk183201. |
|
PRJ-63580, |
Harmony Endpoint |
UPDATE:
|
|
PRJ-66208, HEC-2331, PRJ-66315, PRJ-66277, HEC-2296, PRJ-66739, PMTR-124220 |
Scalable Platforms |
UPDATE: Added support for reusable target profiles to the Lightshot snapshot configuration. |
|
PRJ-63723 |
Scalable Platforms |
UPDATE: Added the LogHub feature to the Insights tool. |
|
PRJ-63218, |
Scalable Platforms |
UPDATE: Added ElasticXL support for Virtual Machines on Mixed Appliances. Refer to sk183513. |
|
PRJ-65288, ODU-3387 |
Automatic Updates - Web SmartConsole |
UPDATE: New features and improvements are released in Take 157 via self-updatable package. Refer to sk170314. |
|
PRJ-59091, |
Security Management |
Administrators with LSM write permissions cannot delete LSM Gateway objects without also having write permissions for Others/Common Objects. |
|
PRJ-60654, |
Diagnostics |
The Security Gateway freezes or crashes without generating a core dump, and the message "Global htab id 100020 out of range!" appears in the $FWDIR/log/fwk.elgfile, when running CPDiag. Refer to sk183538. |
|
PRJ-62532, |
Security Management |
Importing a large policy package fails with validation and API errors on the Multi-Domain Security Management Server. Refer to sk183697. |
|
PRJ-64885, PRHF-42660 |
Security Management |
In rare scenarios, login using Management API fails with a timeout and the "api status" command returns "API readiness test failed" message. Refer to sk184342. |
|
PRJ-60489, |
Security Management |
In some scenarios, when Configuration Sharing is enabled, audit logs may show failed login attempts to the CPM Server after publishing changes. |
|
PRJ-61809, |
Security Management |
When a user with read-only permissions for Global Domains (for example, a user with the Global Manager profile) connects to the System Domain in SmartConsole, the SmartConsole status bar incorrectly displays the user as having read-write permissions. |
|
PRJ-59516, |
Security Management |
In rare scenarios, after an IPS update, all protections are set to Staging mode in Threat Profiles configured with "Set activation as Staging mode". |
|
PRJ-61328, |
Security Management |
In rare scenarios, an IPS update fails because of duplicate objects. |
|
PRJ-59751, |
Security Management |
In some scenarios, creating a Standby Domain Security Management Server fails with a "You do not have the permissions to complete this action" message. |
|
PRJ-62555, PRHF-40800 |
Security Management |
In SmartConsole, if the Task pane has no tasks to show, the Task pane incorrectly shows an "Error retrieving results" message. |
|
PRJ-60375, PRHF-38836 |
Security Management |
VMcore crashes may occur with core dumps of the LOG_INDEXER, LOG_EXPORTER, and JAVA processes on the Security Management Server, causing high CPU utilization. |
|
PRJ-62551, PMTR-117467 |
Security Management |
In rare scenarios, the Security Management Server fails to start after performing a "Revert to Revision" operation. |
|
PRJ-60527, PRHF-38743 |
Security Management |
When running the "mgmt_cli -r true gaia-api/set-ntp target pocsms enabled true --format json" Management API command, the output is not the same as running it directly from Gaia API. Refer to sk184510. |
|
PRJ-62195, PMTR-116551 |
Security Management |
When using the "set-threat-protection" Management API command, overriding either the packet-capture or track values also overrides the action field and sets it to "inactive". |
|
PRJ-56730, PRHF-35654 |
Security Management |
In some scenarios, Compliance Software Blade presents the results of Firewall Best Practices as "N/A". |
|
PRJ-65809, PRHF-43517 |
Security Management |
The "show-packages" Management API command executed with "async-response" parameter may fail with "generic_err_invalid_parameter_name". |
|
PRJ-63793, PRHF-41803 |
Multi-Domain Security Management |
On Multi-Domain Security Management Servers, custom Compliance Software Blade Best Practices may differ between the Multi-Domain Security Management level and the Domain level. |
|
PRJ-65236, PMTR-121265 |
Multi-Domain Security Management |
In certain scenarios, an upgrade of the Multi-Domain Security Management Server may fail with a "During synchronization a new object was found through a relationship that was not marked cascade PERSIST" message.
|
|
PRJ-56359, PRHF-34777 |
CPView |
CPView may display incorrect concurrent connection statistics (negative values) because of improper aggregation of connection data during a Cluster failover. |
|
PRJ-55405, PRHF-34152 |
Logging |
In rare scenarios, the description of IPS Logs in the Logs view may be unclear. Refer to sk182386. |
|
PRJ-64465, PRHF-42386 |
Logging |
In some scenarios, exporting logs to CSV in SmartView fails and the LOG_INDEXER process unexpectedly exits. Refer to sk184475. |
|
PRJ-65364, PMTR-122317 |
Logging |
Improper memory handling within the CPD process may result in unexpected process restart. |
|
PRJ-62132, PRHF-40631 |
Security Gateway |
The FWK memory leak may occur during FTP connections with high file volume. Refer to sk183662. |
|
PRJ-56833, PRHF-35857 |
Security Gateway |
Potential memory leak in the CPD process. |
|
PRJ-64397, |
Security Gateway |
When changing the CoreXL configuration (for example, adjusting the number of SND and FW instances), a network interface may unexpectedly go down. This can cause traffic disruption. |
|
PRJ-64493, |
Security Gateway |
The Security Gateway may drop packets and potentially crash because of memory allocation issues. |
|
PRJ-59735, |
Security Gateway |
In some scenarios, when SecureXL is working in User Mode (UPPAK) mode, QoS service is unable to start, displaying the "QoS is not responding. Verify that QoS is installed on the gateway" error. Refer to sk183752. |
|
PRJ-62920, |
Security Gateway |
Infinite routing loop may occur because of TTL handling in SecureXL Medium Path. Refer to sk183728. |
|
PRJ-65819, PMTR-122907 |
Security Gateway |
When using a Security Gateway as a Proxy "Non-transparent" and HTTPS Inspection is set to "inspect" with "X-Forward-For header", video playback on YouTube fails. See the Critical Information section. |
|
PRJ-63942, |
Security Gateway |
In a Maestro VSX environment, Layer 2 MAC address table in Bridge Mode (Bridge Forwarding Database) entries may be incorrectly deleted, causing connectivity issues. |
|
PRJ-65131, PMTR-108249 |
Security Gateway |
A PYTHON3.11 zombie process may be running in the background without impact on system performance. |
|
PRJ-64496, PRHF-42513 |
SSL Inspection |
Running the "show cp-trusted-ca-certificate" Management API with invalid validFrom/validTo values in the database causes an error and blocks the Trusted Certificates view. |
|
PRJ-66542, PMTR-123417 |
SSL Inspection |
SSL Network Extender (SNX) package installation fails with a verification error. |
|
PRJ-62837, |
Mobile Access |
Mobile Access Software Blade may incorrectly terminate Guacamole-based clientless RDP/SSH sessions due to client idleness. |
|
PRJ-60482, PMTR-110991 |
Mobile Access |
Mobile Access SSL Network Extender (SNX) remote users with Windows 11 24H2 fail to connect. Refer to sk182923. |
|
PRJ-62831, |
Mobile Access |
In rare scenarios, Mobile Access SmartConsole Logs may not match views/queries, including the "MAC address" or "Methods" field names. |
|
PRJ-58680, |
SecureXL |
Concurrent NAT64 and NAT46 operations may cause packet processing threads to become unresponsive because of improper issue handling in the SIM v6 kernel module. |
|
PRJ-64334, |
SecureXL |
Potential USIM process exit when using virtio devices and changing the MTU value. |
|
PRJ-64457, |
SecureXL |
Traffic may be disrupted when reconfiguring the virtual hardware interfaces. |
|
PRJ-61312, |
SecureXL |
In some scenarios, the VSX Security Gateway may not route traffic correctly for non-accelerated connections and accelerated connections that require Active or Passive Streaming when SecureXL User Mode (UPPAK) is enabled. |
|
PRJ-61616, |
SecureXL |
The USIM process may exit when multiple routes are using the same nexthop and the nexthop is not yet resolved |
|
PRJ-62960, |
SecureXL |
The USIM process may exit when viewing the fg_conn table using the "fwaccel tab -t" command. |
|
PRJ-62908, |
SecureXL |
The USIM process may exit during the FWK restart. |
|
PRJ-57694, |
SecureXL |
Multiple "radix_get_value" messages may appear in fwk.elg log files. |
|
PRJ-63632, |
SecureXL |
The USIM process may exit while configuring a PPPoE interface via WebUI. |
|
PRJ-64881, |
SecureXL |
When a VLAN interface is configured as the synchronization interface for the VSX cluster and SecureXL User Mode (UPPAK) is enabled, Virtual Systems on non-active members cannot forward traffic to Virtual Systems on the active member through a warp interface. |
|
PRJ-64613, |
SecureXL |
Multiple threads may be performing a routing next hop lookup for the same next hop at the same time, causing a rare race condition and USIM-related processes to exit. |
|
PRJ-61827, |
SecureXL |
Interface cards are not displayed in the output of the "show asset network" command when SecureXL User Mode (UPPAK) and MDPS are enabled. Refer to sk184218. |
|
PRJ-64143, PMTR-120092 |
SecureXL |
In a Maestro setup, the USIM process may exit under high load when handling encrypted VPN traffic with the other Security Gateway. |
|
PRJ-60845, PRHF-39251 |
SecureXL |
In some scenarios, the Security Gateway may crash when IoC feed contains an IPv6 address. |
|
PRJ-62421, PMTR-115630 |
SecureXL |
In some scenarios, the Security Gateway may crash. |
|
PRJ-61623, PMTR-116027 |
SecureXL |
Rate Limiting policy installation (when the Rate Limiting policy is updated or country code data is updated) may take a long time. |
|
PRJ-59396, AAD-4359 |
VPN |
VPN traffic outage may occur in ClusterXL environments after a Cluster failover. |
|
PRJ-58822, AAD-3662 |
VPN |
IPv6 Site-2-Site connectivity may not be stable in Enhanced Link Selection configuration on ClusterXL environments. |
|
PRJ-63346, PMTR-104766 |
VPN |
A race condition may cause the PROBEMOND process to exit during policy installation when VPN network probes are removed/added. |
|
PRJ-59231, AAD-4299 |
VPN |
IPv6 traffic outage in Enhanced Link Selection configuration after tunnel deletion on one side during tunnel renegotiation. |
|
PRJ-63020, |
VSX |
Services fail after Virtual System failover in Maestro dual-site environment using the Same Virtual MAC feature. Refer to sk183956 and sk184194. |
|
PRJ-64573, PMTR-120689 |
VSX |
In an ElasticXL Cluster in the VSNext Mode, when physical interfaces are configured as management interfaces on Virtual Systems, these interfaces are down after reboot. |
|
PRJ-63757, PMTR-119447 |
VSX |
In a Maestro environment, Security Group member may not be in the ACTIVE state with an Active Distutil PNOTE raised. |
|
PRJ-62535, PRHF-40972 |
Gaia OS |
Gaia Portal Session Cookie missing the SameSite attribute. Security scanners and penetration tests flag the missing SameSite attribute as a vulnerability. Refer to sk183645. |
|
PRJ-63262, |
Gaia OS |
The LLDP Clish "lldpneighbors" command may have a corrupted output in case of extensive data. Refer to sk182065. |
|
PRJ-60766, |
Gaia OS |
DHCP traffic peaks may cause high utilization, potentially impacting connectivity. |
|
PRJ-62041, |
Gaia OS |
The MONITORD process unexpectedly exits on Security Gateways. Refer to sk184076. |
|
PRJ-62466, |
Gaia OS |
SNMP Power Supply trap reports false "Down" status. Refer to sk183702. |
|
PRJ-63423, PMTR-118146 |
Gaia OS |
Restoring backup using WebUI (or gClish) when there is a single member in the Security Group fails. |
|
PRJ-59019, PMTR-110956 |
Gaia OS |
LACP bonds may continue passing traffic when running SecureXL User Space Mode and the value drops below the configured minimum number of links, although the bond interface should stop passing traffic. |
|
PRJ-59519, PMTR-111921 |
SD-WAN |
A Virtual System may lose connectivity on the Backup and the Standby member when route-based traffic is configured with specific SD-WAN configurations in VSX environments. |
|
PRJ-63462, |
Harmony Endpoint |
Full Disk Encryption user update password fails with auth_type 3 (certificate and password). |
|
PRJ-61893, |
Harmony Endpoint |
Posture Management scans initiated manually or automatically remain stuck at the "Scan initialize" status. This issue affects all devices with Endpoint Security installed. |
|
PRJ-63038, |
Harmony Endpoint |
After upgrading the Endpoint Security Client from a non-compliant version to E88.62 on Azure AD devices (protected by Full Disk Encryption), multiple clients may enter a disconnected state. |
|
PRJ-61896, |
Harmony Endpoint |
Security Management Server and Policy Server may lose connectivity after uploading production licenses. Running "cplic print -x" on the Policy Server shows no output, while the Security Management Server output is uploaded for review. |
|
PRJ-65469, PRJ-65480 |
CloudGuard Network |
The CloudGuard Network Central License utility fails to distribute a single license using CLI. |
|
PRJ-61275, |
QoS |
Security Gateway cannot fetch the QoS policy from Security Management. Refer to sk183709. |
|
PRJ-63694, |
Scalable Platforms |
Members added to a Security Group with the MDPS feature enabled may stay in the Down state because of a missing license (licenses are not distributed from the SMO member to the added Security Group members). |
|
PRJ-65088, PRJ-65089, PRHF-42654 |
Scalable Platforms |
Traffic impact on a Maestro Gateway with the MDPS feature enabled during a major version upgrade to R82. |
|
PRJ-64436, |
Scalable Platforms |
Maestro Orchestrator fails to add a new Security Appliance to a Security Group when the Maestro Fastforward feature is enabled in the Security Group. Refer to sk184233. |
|
PRJ-64818 |
Scalable Platforms |
The "hcp -r" Orchestrators Ports Link Integrity test does not report link integrity issues when there is a bad signal on the MHO physical ports. |
|
PRJ-64123, |
Scalable Platforms |
In an ElasticXL Cluster in the VSNext Mode, it is not possible to configure more than 32 CoreXL IPv4 / IPv6 Firewall instances in a Virtual Gateway in the CLI. The Gaia gClish command "set vsnext corexl-instances virtual-gateway ID ipv4-instances Value" fails with the "CLINFR0409 Invalid number: Value. Not in range 1..32." error. |
|
PRJ-64062, |
Scalable Platforms |
When Maestro Fastforward feature is enabled, policy installation may fail with "Maestro acceleration (MXL) failed, reason: General error. Please check /var/log/acl_cli.log on the security group SMO for more details" instead of indicating that it is a policy parser issue. |
|
PRJ-60421, |
Scalable Platforms |
In a VSNext environment with a Virtual Switch (VSW), SNMP data for ASG branches may not be collected. |
|
PRJ-64345, |
Scalable Platforms |
After an upgrade, a local connection from Standby members on the VS management interface fails. |
|
PRJ-65636, PMTR-122661 |
Scalable Platforms |
In the Maestro and Chassis environment with multiple Virtual Systems (VSs) and updatable objects, the disk may reach full capacity. Refer to sk184576. See the Critical Information section. |
|
PRJ-64593, PMTR-121110 |
Scalable Platforms |
In rare scenarios, in a Maestro setup, traffic interruption may occur after Security Gateway reboots when the Gaia Database is corrupted. |
|
PRJ-62818, PRHF-41165 |
Scalable Platforms |
In a Maestro VSX VSLS Cluster, after setting the kernel parameters "fwha_monitor_all_vlan=1" and "fwha_enable_if_probing=1", memory consumption may immediately increase to 100% and cause an outage. |
|
PRJ-63476, PMTR-119026 |
Scalable Platforms |
Installing policy to the Maestro Security Group under extreme load with Resource Separation may fail. |
|
PRJ-64632, PRHF-41710 |
Scalable Platforms |
The "Invalid property name for chassis" error is displayed when changing the "alert_threshold packet_rate_total_threshold_low_ratio" value. |
|
PRJ-64504, |
Carrier Security |
Policy installation fails with an internal error when the Security Gateway policy includes rules that match a specific Access Point Name (APN) for GTPv0 or GTPv1 traffic. |
|
PRJ-56452, |
Carrier Security |
SAM rules fail to gracefully terminate PDP context when the timer expires. |
|
PRJ-56448, PRHF-31901 |
Carrier Security |
Running to "snmpwalk" or "stattest" command for any of GX OIDs results in the "No Such Instance currently exists at this OID" error. |