R82 Jumbo Hotfix Take 118

 

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 118

Released on 22 July 2026

Take 118 - New Functionality

 

PRJ-69883,
PRJ-69884

Security Gateway

NEW: Introducing Unified Security Management from SmartConsole.

SmartConsole now provides a single management plane for your organization's security - across cloud and on-premises environments. With this release, you can view the AWS firewalls and manage policies associated with your AWS firewalls directly from SmartConsole, with no need to switch between tools or consoles.

Key capabilities:

  • Policy visibility - Inspect policies tied to AWS firewalls from one centralized location.

  • Cross-account policy sharing - Share and enforce consistent policies across multiple AWS accounts.

  • Gateway policy sharing - Extend policy sharing to Check Point Gateways, unifying cloud and on-premises enforcement.

This reduces operational overhead, closes visibility gaps, and ensures consistent security enforcement across your entire environment.

PRJ-69470,
PMTR-128479

Security Management

NEW: Permission profiles for Access layers via the Management API are now supported. A new field, "additional-permission-profiles", has been added to the existing "add/set access-layer" Management API.

For example: mgmt_cli set access-layer name "Network" additional-permission-profiles.1 "custom_profile"

PRJ-69018,
PMTR-127536,

PRJ-70140,
ODU-4246

Security Management

NEW: CloudGuard Controller now supports the Claroty Continuous Threat Detection (CTD) Data Center. Refer to the R82 CloudGuard Controller Administration Guide.

PRJ-60198,
PRJ-59919

Gaia OS

NEW: Added the option to send Gaia backup to a Remote Server using the SFTP protocol. This feature also supports restore operations via SFTP and scheduled backups (including retention policy support).

  • For information about regular backups, refer to R82 Gaia Administration Guide > Maintenance > System Backup > Backing Up and Restoring the System.

  • For information about scheduled backups, refer to R2 Gaia Administration Guide > Maintenance > System Backup > Configuring Scheduled Backups.

PRJ-67598

Cloud Firewall

NEW: Central License Utility now sends events to Events & AIOps upon license distribution failures and recoveries. Events are reported for both full distribution runs and single distribution, enabling proactive monitoring and alerting through AIOps. Refer to the Cloud Firewall Central License Tool Administration Guide.

PRJ-67947,
HEC-2296

Scalable Platforms

NEW: The Virtualization Screen is added to VS0 Insights, displaying Virtual Systems statistics, including Virtual Systems problem detection, alongside general environment metrics and the Resource Search tool.

  • Resource Search Tool: Provides a cross Virtual Systems interface search capability.

  • Problem Detection: Introduces Virtual System problem indicators in the Status and Problem Categories columns, showing problem classifications. Users can select a Virtual System row in the Virtual Systems table to re-launch Insights in the Virtual System context and investigate issues in AI Detector.

PRJ-67947,
HEC-2296

Scalable Platforms

NEW: Added support for integrating clean-install machines running a higher version into an existing ElasticXL R82 environment.

PRJ-69424,
PRHF-45847

Scalable Platforms

NEW: Added a configuration option for Maestro Orchestrator to forward Spanning Tree Protocol (STP) BPDUs to Maestro Security Group Members. Refer to sk185110.

Take 118 - Improvements and Resolved Issues

 

PRJ-68721,

PRJ-69356,

PMTR-127252

Gaia OS

UPDATE: Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia). Refer to sk184928.

PRJ-70598,

PMTR-129991

Gaia OS

UPDATE: Resolved CVE-2026-62145 - Local privilege escalation in Gaia Portal. Refer to sk185153.

PRJ-65589,
PRHF-42963

Security Management

UPDATE: In environments with thousands of Domain objects or External User Groups, the policy installation duration has been significantly improved.

PRJ-62061,
PMTR-111171

Security Management

UPDATE: In environments with hundreds of Updatable Objects, policy installation time has been significantly improved.

PRJ-70485,

PMTR-129956

Security Management

UPDATE: Resolved CVE-2026-62144 - Management Authentication Bypass and Privilege Escalation. Refer to sk185152.

PRJ-70933,

PMTR-130686

Security Management

UPDATE: Resolved CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token. Refer to sk185169.

-

-

This Jumbo Hotfix Accumulator Take provides additional Management and Gateway hardening fixes, including VPN Site to Site and Remote Access.

PRJ-68502,
PMTR-127051

Logging

UPDATE: In the Logs view, search performance is improved when the search term includes a Cluster.

PRJ-69642,
ODU-4190

Automatic Updates - Security Management

UPDATE: Added Take 89 and Take 90 of the AutoUpdater Utility. Refer to sk165653.

PRJ-69645,
ODU-4086,

PRJ-70601,

ODU-4337

Automatic Updates - Log Exporter

UPDATE: Added Take 65 of and Take 70 of Log Exporter Auto Update Deployment. Refer to sk182866.

PRJ-70009,
ODU-4253,

PRJ-69418,
ODU-4204,

PRJ-70564,

ODU-4316

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 171, Take 173, and Take 176 of Web SmartConsole. Refer to sk170314.

PRJ-69639,
ODU-4225,

PRJ-70662,

ODU-4330

Automatic Updates - Policy Insights

UPDATE: Added Take 94 and Take 96 of Policy Insights Release Updates. Refer to sk183421

PRJ-69588,
ODU-4093

Automatic Updates - Smart-1 Cloud

UPDATE: Added Take 13 and Take 75 of Smart-1 Cloud MaaS Tunnel. Refer to sk166056.

PRJ-69573,
ODU-4218,

PRJ-70684,

ODU-4351

Automatic Updates - HCP

UPDATE: Added Take 93 and Take 94 of HealthCheck Point (HCP) Release. Refer to sk171436.

PRJ-69584,
ODU-4169,

PRJ-70142,
ODU-4232

Automatic Updates - CPView

UPDATE: Added Take 57 and Take 59 of CPquid (QUID) Release Updates. Refer to sk181458.

PRJ-68747,
ODU-4030

Automatic Updates - Threat Prevention

UPDATE: Added Update 28 of Autonomous Threat Prevention Management Integration Release. Refer to sk167109.

PRJ-67793,
PRHF-44615

Security Gateway

UPDATE: Optimized Mobile Access policy installation to improve performance in environments with a large Mobile Access Rule Base (more than 500 rules).

PRJ-60908,
PRHF-39442

SSL Inspection

UPDATE: Added support for the X.509v3 Subject Key Identifier (SKI) and Authority Key Identifier (AKI) extensions in the HTTPS outbound inspection Certificate Authority (CA). Refer to sk184273.

PRJ-67382,
PMTR-125446

Mobile Access

UPDATE: Resolved the Mobile Access Portal XSS vulnerability in the PHP file.

PRJ-68783,
PMTR-127386

Gaia OS

UPDATE: Gaia API updates are now included in the Jumbo Hotfix Accumulator (previously were installed by AutoUpdater). See sk143612.

PRJ-64837,
PMTR-117977

VSNext

UPDATE: These deprecated VSLS commands were removed as not supported:

  • "set cluster vsls system primary_site"

  • "show cluster vsls system primary_site"

PRJ-64982,
PMTR-121665

Scalable Platforms

UPDATE: Improved warning message, user confirmation prompt, and audit logging when running the "set fcd revert" command in gClish on a Scalable Platform Security Group.

PRJ-67528,
PMTR-125744

Scalable Platforms

UPDATE: Old SVMAC feature is now deprecated ("toggle_same_vmac" parameter is blocked). Only use the new SVMAC feature ("toggle_same_vmac_os"). Refer to sk165674.

PRJ-66880,
PMTR-117271

Scalable Platforms

UPDATE: Change in "asg monitor" and "ast stat -v" commands: when there is a grade difference between sites, manual site failover is now blocked, and a warning is displayed.

PRJ-63575,

PRHF-37359

Scalable Platforms

UPDATE: Global parameter "fwha_grade_should_consider_lacp" is now disabled by default.

PRJ-61157,
PRHF-39669

Diagnostics

When the "Same VMAC" feature is enabled, concurrent connections are not updated during site failover.

PRJ-60390,
PRHF-39002

CPView

In the VLAN interface, CPView shows the speed of the parent.

PRJ-65008,
PRHF-42618

Security Management

In some scenarios, the submit-time field in emails generated by SmartTask displays an incorrect value.

PRJ-66977,
PRHF-44315

Security Management

The FWM process may exit because of memory exhaustion and generate large core files (up to 4GB).

PRJ-59898,

PRHF-38656

Security Management

In some scenarios, task notifications are not triggered for the Automatic Revisions Purge process, and the task status is not displayed correctly in SmartConsole.

PRJ-65795,
PRHF-43447

Security Management

Using the "get Interfaces without topology" option on a Security Gateway may remove user-defined interface comments and color settings. Refer to sk180516.

PRJ-61772,
PRHF-40047

Security Management

Gateway license information may not be visible in SmartConsole when using Demo mode or when connecting with a read‑only user.

PRJ-64101,
PRHF-42074,

PRJ-66379,

PRHF-43925

Security Management

In rare scenarios, the Security Management Server fails to start after performing a "Revert to Revision" operation.

PRJ-65778,
PRHF-43423

Security Management

In rare scenarios, some Management API commands may fail with "Management server failed to execute command" error. 

PRJ-67196,
PRHF-44188

Security Management

In some scenarios, Multi-Domain Security Management HA synchronization may fail after AI Copilot permissions are updated, until a manual synchronization is performed. Refer to sk185124.

PRJ-67414,
PMTR-125556

Security Management

The "show-global-properties" Management API command fails when there is a database inconsistency in the "keep-hit-count-data-up-to" field.

PRJ-66225,
PRHF-43824

Security Management

Packet mode search does not return results for Inline Layer rules in SmartConsole and Management API. Refer to sk184638.

PRJ-63910,
PRHF-41943

Security Management

In some scenarios, the "show-tasks" Management API command displays incorrect results when the "from-date" and "to-date" parameters are used. Refer to sk184072.

PRJ-69131,
PMTR-127809

Security Management

In some scenarios, the FWM process on the Security Management Server may unexpectedly exit when performing the "Fetch branches" action in the LDAP Account Unit properties window of SmartConsole.

PRJ-66946,
PRHF-44222

Security Management

SmartWorkflow may incorrectly show zero changes for a session, preventing the change report from being displayed. Refer to sk184779.

PRJ-64045,
PRHF-42109

Security Management

In some scenarios, running the "api stats" command with the "-calc_avg_duration" flag on the Security Management Server fails with the "IndexError: list index out of range" error. Refer to sk184144.

PRJ-63497,
PRHF-41612

Security Management

Policy installation may fail with "failed to get tls rulebases from policy id" message.

PRJ-64522,
PRHF-42149,

PRJ-64525,
PRHF-42412

Security Management

In some scenarios, opening a Security Gateway object in SmartConsole fails with "Smart Dashboard component failed to connect to a server".

PRJ-63571,
PRHF-41727

Security Management

The Security Management Server upgrade may fail during the export phase with the "Object not found - Entities can not be found" message.

PRJ-66179,
PRHF-43671

Security Management

In some scenarios, accumulated open sessions can cause the Security Management Server to become unavailable.

PRJ-66325,
PRHF-43883

Security Management

In some scenarios, an API key may become invalid after editing an administrator account.

PRJ-68533,
PRHF-45122

Security Management

In rare scenarios, the FWM process on the Multi-Domain Security Management Server may not stop after running mdsstop.

PRJ-68293,
PRHF-45027

Security Management

SmartTasks may fail to send email notifications with a "send mail to <email address> failed" error when the Cc field is populated.

PRJ-66974,
PRHF-44216

Security Management

A SmartTask configured to send an email after policy installation may fail when the target gateway is a VSX object.

PRJ-67191,
PMTR-124870

Security Management

In some scenarios, after the FWM process crashes and generates a core dump, High Availability synchronization may fail, and the Security Management Servers may appear as disconnected.

PRJ-66868,
PRHF-44037

Security Management

SmartConsole may display the error "the user already exists" when attempting to create a new administrator with the same name as a previously deleted SAML (Identity Provider) administrator.

PRJ-63533,
PRHF-41677

Security Management

Rulebase search for a specific user may fail to return rules that include user groups in which the user is a member.

PRJ-62108,
PRJ-61548

Security Management

In some scenarios, the automatic update of Data Center assets fails. Refer to sk184316.

PRJ-61279,
PRHF-39745

Security Management

In some scenarios, the "show-simple-clusters" Management API command with details-level set to "full" may fail with the error message "Configuration Sharing Failed to update Infinity Portal".

PRJ-58734,
PRHF-37560

Security Management

In some scenarios, the "show simple-gateways" Management API command fails with "Object not found - Can't find BlobAuthKey object with hash ID=' '." error message.

PRJ-67607,
PRHF-44664

Security Management

SmartConsole may display a generic error "Failed to save object <object_name>. Server error is: An internal error has occurred. (Code: 0x8003001D, Could not access file for write operation)" when editing interfaces on Spark Firewall.

PRJ-66639,

PRHF-44086

Security Management

Configuration sharing from a Management Server to the Check Point Portal may fail with a "Did not get reply from Docker" error.

PRJ-60903,
PRHF-39412

Security Management

In some scenarios, when attempting to view a revision in SmartConsole, it unexpectedly crashes after several minutes with the error message: “SmartConsole has experienced a serious problem and needs to relaunch.”

PRJ-63914,
PRHF-41983

Security Management

In some scenarios, fwmtrace.log* files consume a significant amount of disk space.

PRJ-65207,
PRHF-42646

Security Management

API login to the Security Management Server may fail with a "Null Pointer Exception" error when the session name, comment, or description is specified.

PRJ-67666,
PRHF-44882

Security Management

The Management API v2 command "show-vpn-communities-star" with details-level full may fail with an "Internal error" message when a Virtual System Cluster member is configured as a satellite in a VPN Star community.

PRJ-67372,
PRHF-44242

CPView

CPU information may not be displayed in the CPU tab in CPView for an environment with Virtual Systems

PRJ-68995,
PMTR-127578

AIOps

A temporary fix related to the QUID identity database (used by CPDiag and AIOps) caused issues in Maestro environments and led to degradation and occasional agent resets in AIOps, as it relies on this component as its IdentityDB. The fix has therefore been removed.

PRJ-63014,
PRHF-41211

Logging

In some scenarios, the SmartLog Server process may unexpectedly exit and generate a core dump.

PRJ-66904,
PRHF-44038

Logging

High load on the LOG_INDEXER process may impact system performance.

PRJ-63441,
PRHF-39816

Logging

In a Management High Availability environment, configuring threshold settings in SmartView Monitor, fails with the "Couldn't load threshold settings for the selected gateway" error.

PRJ-66069,
PRHF-30761

Logging

The logs maintenance is running perpetually and is not clearing disk space when the CPPCAP (Check Point Traffic Capture Tool) is enabled.

PRJ-66322,
PMTR-123346

Logging

In some scenarios, the LOG_INDEXER process unexpectedly exits and generates a core dump.

PRJ-60251,
PRHF-36152

Logging

SmartEvent processes may unexpectedly exit in environments containing over 1 million network objects.

PRJ-65522,
PRHF-42914

Security Gateway

RSH connections fail when Destination NAT is configured for the RSH server. Refer to sk184768.

PRJ-65229,
PRHF-42920

Security Gateway

Active Streaming Layer connections become stuck, resulting in increased memory consumption over time on the Security Gateway. 

PRJ-67746,
PMTR-125710

Security Gateway

In a rare scenario, the FWD daemon may restart because of the Application Control Dynamic URL List version file.

PRJ-67080,
PRHF-44360

Security Gateway

On ClusterXL and in Maestro Security Groups, after performing a rolling upgrade that includes a change in the CoreXL instance count, newly created firewall instances may remain in local-sync-only mode. As a result, these instances do not receive state updates from their peers, leading to intermittent connection failures and "First packet isn't SYN" drops. Refer to sk184786.

PRJ-66621,
PRHF-44062

Security Gateway

In rare cases, the FWK process may restart unexpectedly while the Security Gateway is processing a URL Filtering categorization response and a policy installation is running simultaneously.

PRJ-66432,
PRHF-43910

Security Gateway

The memory usage may increase over time when using the Mirror and Decrypt feature.

PRJ-57233,
PRHF-29611

Security Gateway

In a rare scenario, the CPD process may crash because of a race condition.

PRJ-62435,
PRHF-40579

Security Gateway

FTP traffic does not pass through Security Gateway when using the FTP Extended Passive Mode. Refer to sk183853.

PRJ-66420,
PRHF-43935

Security Gateway

In a rare scenario, a memory leak may occur due to a race condition between policy installation and Application Control/IPS signature updates, and persists until the next policy installation.

PRJ-66489,
PRHF-43994

Security Gateway

In a rare HTTP/2 traffic scenario, a valid connection may fail.

PRJ-64093,
PRHF-40610

Security Gateway

The RAD daemon may unexpectedly exit when customizing RAD internal parameters ("max_flows" and "queu_max_capacity"). Refer to sk182136.

PRJ-65932,

SMBGWY-18437

Security Gateway

In rare HTTP/S inspection flows, the Security Gateway may crash if there is a parsing error.

PRJ-64287,
PMTR-116967

Security Gateway

In a very rare scenario, HTTP parsing of unencrypted (clear-text) traffic may trigger the FWK process to exit.

PRJ-58250,
PMTR-109582

Security Gateway

The message "ws_mux_handle_dpi_jobs: async_params has no pm or hash job" can be printed in the fwk.elg log file when passing HTTP traffic.

PRJ-60596,
FMW-2291

Security Gateway

In cluster configurations, synchronization between members was optimized to reduce CPU overhead.

PRJ-67647,
PRHF-44347

Security Gateway

In some scenarios, internal memory mishandling in global connections may cause unexpected behavior or connectivity issues.

PRJ-68166,
PMTR-113101

Security Gateway

Policy installation may fail because of empty settings in Suspicious Activity Monitoring (SAM) rules.

PRJ-60246,
PMTR-113336

Security Gateway

In some scenarios, active connections using HyperFlow are closed following a crash of the dmd_run process, and the FWK process may also crash. This error appears in the dmd.elg file: "mux_dmd_handle_errors_from_dmd: Handling errors from DMD. error SESSION_COLLISION".

PRJ-66909,
PRHF-30817

Security Gateway

There may be log entries related to the drop optimization feature, although the dropped traffic matches a non-logging rule.

PRJ-65978,
PRHF-43452

Security Gateway

After an upgrade, the "show configuration" command output for MDPS may be missing bond configuration.

PRJ-64056,
PRHF-42098

Security Gateway

In rare scenarios, the FWK process may unexpectedly restart when an HTTP/2 connection containing specific stream characteristics is released.

PRJ-63659,
PRHF-41793

Security Gateway

FTP transfers of files smaller than 1KB fail and result in empty files on the destination server. Refer to sk184200.

PRJ-63931,
PRHF-41934

Security Gateway

In a rare scenario, when handling CIFS traffic in the accelerated pipelined path, the PPE and FWK processes may exit. Refer to sk184284.

PRJ-65815,
PRHF-42940

Security Gateway

Some service ports may be missing in some instances, resulting in unexpected behavior for some services.

PRJ-64846,
PMTR-120708

Security Gateway

HTTPS inspection causes connections to fail when using a custom service with a non-standard HTTPS port (for example, TCP/9400), and the custom service object is configured with "Protocol: None". Refer to sk184294.

PRJ-68594,
PRHF-45113

Security Gateway

In a rare scenario, the FWK process crashes when the Mirror and Decrypt feature handles large MTU frames.

PRJ-66748,
PRHF-44002

Security Gateway

When ISP Redundancy is enabled, and the administrator changes the priority, the primary ISP may not be updated in the Security Gateway (the route is updated, but the Security Gateway continues to consider the old ISP as the primary/standby). Refer to sk184923.

PRJ-65664,
PRHF-43354

Security Gateway

There may be high CPU usage by the CMID process when the ICAP Client is enabled on Security Gateway. Refer to sk184524.

PRJ-63682,
PRA-5002

Security Gateway

In a rare scenario, the FWD process may crash during Policy Installation because of memory corruption related to licensing.

PRJ-64349,
PMTR-120451

Security Gateway

When processing CIFS IPv6 traffic in the accelerated pipelined path, the dmd_run process crashes. HyperFlow is not supported for CIFS over IPv6.

PRJ-63999,
PRHF-42068

Security Gateway

Suspicious Activity Monitoring (SAM) rules may not function properly on a standalone device. Refer to sk184330.

PRJ-64914,
PRA-4998

Security Gateway

When ESP traffic is present in the environment, and the fwmultik_dispatcher_in_tap_mode parameter is enabled, the Security Gateway may drop ESP traffic.

PRJ-64211,
PMTR-120377

Internal CA

The supported CRL file size limit is increased to prevent CRL recreation failures with large SIC CRL files.

PRJ-65307,
PRHF-42982

Threat Prevention

In rare scenarios, the Anti-Virus fails to inspect HTTP file downloads.

PRJ-68772,
PMTR-127315

Threat Prevention

IoC feed observables may continue to be enforced even after Anti-Virus and Anti-Bot are disabled.

PRJ-58886,
PRHF-37274

Threat Prevention

SSH connections may fail after enabling SSH Deep Packet Inspection (DPI).

PRJ-66413,
PMTR-115188

Threat Emulation

In some scenarios, processing large Threat Emulation messages causes high memory usage and DLPU instability, resulting in crashes. Refer to sk184623.

PRJ-66676,
PMTR-115995

Threat Prevention

In some scenarios, HTTP file downloads fail with a connection timeout when both Threat Emulation and Threat Extraction are enabled.

PRJ-61557,
PMTR-114140

Threat Prevention

In some scenarios, Anti-Virus fails to load external IoC feeds that contain IP observables.

PRJ-67505,
PMTR-125680

Threat Prevention

In some scenarios, enforcement of an Indicator of Compromise (IoC) feed containing mail observables may fail if the feed file includes a single malformed entry because of a parsing error.

PRJ-69202,
PMTR-124700

Threat Prevention

In some scenarios, Zero Phishing becomes inactive during traffic inspection when Anti-Virus performs a Deep Scan on HTML or JavaScript files.

PRJ-69142,
PMTR-127848

Identity Awareness

The default role in Aruba Networks ClearPass CPPM does not match the identity sessions.

PRJ-59799,
PRHF-38576

Identity Awareness

SNMP queries to the Security Gateway may return unexpected results: specific IP addresses or Identity Collector objects may continue to appear in SNMP outputs even after being removed from the topology configuration. Additionally, polling OIDs such as 1.3.6.1.4.1.2620.1.38.55 or 1.3.6.1.4.1.2620.1.38.53 may result in the message "No Such Instance currently exists at this OID"

PRJ-57713,
PRHF-36392

Identity Awareness

The Microsoft Graph API access token does not renew if an authorization error occurs while working in on-demand fetch mode.

PRJ-65789,
PRHF-42181

Identity Awareness

Identity Awareness AD user authentication takes a long time. Refer to sk183748.

PRJ-64786,
PRHF-42302

Identity Awareness

In some scenarios, the PDPD process stops responding and users cannot authenticate through the Identity Awareness. Refer to sk184407.

PRJ-65696,
PRHF-42937

Identity Awareness

In some scenarios, when Identity Sharing is configured to work with both IPv4 and IPv6 addresses, identity-based roles may not match the access roles.

PRJ-66561,
PRHF-43834

Application Control

When using custom applications and SD-WAN, HTTPS traffic may be blocked with "Reason: Application Control - Internal system error" in SmartConsole log.

PRJ-64970,
PMTR-121545

URL Filtering

The Resource Advisor module continues to perform categorization even when a match is found in the override category.

PRJ-67579,
PRHF-44375

URL Filtering

RAD request drop may occur in rare case header includes unsupported characters.

PRJ-67375,
PMTR-125272

IPS

In some scenarios, the Custom Threat Prevention policy fails to enforce IPS protection overrides on rules configured with a network group in the "Install On" column.

PRJ-70209,
PRJ-70210

IPS

In some scenarios, the Packet Capture option is missing from IPS logs in SmartConsole.

PRJ-65024,
PRHF-42722

Anti-Virus

In rare scenarios, the RAD process may exit generating a core dump.

PRJ-65579,
AAD-8717

SSL Inspection

A memory leak may occur in the parsers_is TLS module when HTTPS Inspection is enabled and used to inspect non-standard TLS traffic transmitted over a proxy.

PRJ-66473,
PMTR-123521

SSL Inspection

When HTTPS Inspection is enabled, the Security Gateway uses the global (default) outbound CA certificate, even though an outbound CA override is configured in SmartConsole. Refer to sk184880.

PRJ-70251,
PMTR-129404

Mobile Access

After hardening non-RFC-compliant HTTP requests, some Mobile VPN connections fail. Since multiple clients send bare LF requests (a specific type of non-RFC-compliant traffic), bare LF errors are now disabled by default. This behavior can be enabled using the kernel parameter "ws_block_bare_lf".

PRJ-66021,
PMTR-123156

ClusterXL

In a ClusterXL Load Sharing Unicast configuration, the Pivot member intermittently fails to forward packets to the relevant non-Pivot cluster members. This results in packet drops, related to MAC address handling.

PRJ-62274,
PMTR-111975

ClusterXL

Policy installation may fail on a Cluster Member in this scenario:

  1. In the legacy file $FWDIR/conf/cpha_specific_vlan_data.conf, an interface was added without a VLAN ID.

  2. The value of the kernel parameter "fwha_monitor_specific_vlan" is "0".

PRJ-64488,
PMTR-120867

SecureXL

In rare scenarios, instability of the User Space Firewall during system boot may cause failures in SecureXL User Mode (UPPAK).

PRJ-67818,
PMTR-126262

SecureXL

After rebooting the Security Gateway, the Allow List entry is present when viewing the list, but it is not enforced. The Deny List takes precedence, and traffic from the IP is blocked, even though it should be allowed according to the configuration.

PRJ-66212,
PMTR-123304

SecureXL

A reference count issue in the UPPAK module can cause a USIM process core dump, particularly on busy systems with long uptime.

PRJ-69886,
PRJ-69330

SecureXL

In some scenarios, the VSX Security Gateway passes traffic without performing proper NAT from a Virtual Router or Switch's external interface when SecureXL User Mode is enabled.

PRJ-64174,
PRHF-42253

SecureXL

The "arping" command on the Security Gateway returns this output "Sent 4 probes Received 0 response" in SecureXL User Mode (UPPAK). Refer to sk184292.

PRJ-61884,
PRJ-61014

SecureXL

In some scenarios, an error occurs in UPPAK mode when packets are cloned. This can lead to random crashes in the USIM process, causing instability during interface changes or high traffic.

PRJ-67203,
PRHF-44788

SecureXL

In some scenarios, when the QoS is enabled in UPPAK mode, the USIM process crashes.

PRJ-63600,
PMTR-117005

SecureXL

In some scenarios, DOS/Rate Limiting causes blocking errors during boot.

PRJ-66602,
PMTR-117662

SecureXL

In some scenarios, a crash occurs when many concurrent nexthop lookups are performed.

PRJ-64013,
PMTR-119496

SecureXL

In some scenarios in UPPAK mode, the nexthops may be incorrectly indexed, which leads to packet drops.

PRJ-66067,
PMTR-121465

SecureXL

In a Cloud Firewall environment with Kernel Performance Pack (KPPAK) enabled by default, when modifying the TX queue size parameter for supported network interfaces to 2048 (2K) or 4096 (4K), reverting the setting back to the default value of 1024 (1K) is not possible.

The issue is observed with these synthetic network drivers: virtio (used in GCP and KVM environments), vmxnet3 (used in VMware ESXi), and ena (used in AWS).

PRJ-65898,
PMTR-123034

SecureXL

Error messages are generated when running the "fwaccel dos statistics get" command, cluttering the usim_x86.elg log file.

PRJ-65886,
PRHF-43515

SecureXL

PPTP/GRE traffic fails when Hide NAT is used and SecureXL runs in UPPAK mode and the "fw_pptp_enforce_protocol" parameter is enabled. Refer to sk184641.

PRJ-66229,
PRHF-43674

Routing

The ROUTED daemon may exit when running the "show bgp paths" command.

PRJ-67018,
PRHF-44174

Routing

The ROUTED daemon may exit with a pnote on Security Group Members after the Orchestrator daemon (ORCHD) stops. Refer to sk184771.

PRJ-69056,
PMTR-127714,

PRJ-68730,
PMTR-127310

Routing

On VSNext Clusters, during startup, the ROUTED daemon does not install cluster Virtual IPs (VIPs) on certain non-VS0 Virtual System (VS) routing instances. As a result, Dynamic Routing protocols (such as OSPF, BGP) fail to operate correctly on the affected instances.

PRJ-69594,
PMTR-128407

Routing

In the VSX environment, the BGP Routed Critical Device (PNOTE) never clears after rebooting both cluster members simultaneously or during an upgrade.

PRJ-68229,
PMTR-126764

VSNext

After deleting several Virtual Systems, stale wrpj interfaces remain attached to Virtual Switches. SmartConsole shows these orphaned interfaces with error text "Virtual System with the ID X does not exist".

PRJ-64940,
PMTR-121363

VSNext

When a Virtual System (VS) is deleted from a VSX Security Gateway, the Dynamic Split feature does not properly recognize the removal and continues to attempt fetching data or updating CPU affinity for the deleted VS. This results in repeated errors or log entries referencing the non-existent Virtual System, and may interfere with CPU core allocation and affinity management for the remaining VSs.

PRJ-67744,
PMTR-124791

VSNext

In some scenarios, on VSNext environments, Backup and Restore fails to restore a backup, causing all Virtual Systems to be in a DOWN state.

PRJ-69283,
PMTR-128399

VSNext

In some scenarios, on Maestro VSNext setups, a bridge is shown in a down state in the WebUI interfaces table immediately after creation in the Virtual System (VS) context.

PRJ-65143,
PMTR-121946

VSNext

Connecting a Virtual Gateway to a Virtual Switch with a long name in Gaia API may fail.

PRJ-69852,
PMTR-128972

VSNext

A connectivity issue may occur in DNS per-virtual-system after an upgrade because of a missing configuration file.

PRJ-67625,
PRHF-44844

VSX

When using VSX SmartProvisioning on Maestro, the operation fails if the VSX Gateway name includes the substring "wrp0".

PRJ-62322,
PMTR-116925

VSX

In some scenarios, the CPView utility causes high CPU usage or becomes stuck while calculating disk space.

PRJ-69523,

HEC-1792

VSX

Added new SNMP OIDs to enable monitoring of physical resources per Virtual System (VS) via VS0.

PRJ-67930,

PRHF-45114

Multi-Portal

In a rare scenario, a security hardening change related to Multi-Portal connections may cause an unexpected Security Gateway restart when such a connection is terminated.

PRJ-65073,
PMTR-121700

Gaia OS

After a clean installation using CPUSE, interfaces configured with IPv6 are in an "off" state.

PRJ-67502,
PRHF-44333

Gaia OS

After an upgrade, in some scenarios, two-factor authentication (2FA) may not be enforced for SSH access. This results in users are able to authenticate via SSH without the required 2FA.

PRJ-64589,
PRHF-41203

Gaia OS

CPU spikes may occur in a cluster when SNMP is enabled.

PRJ-69372,
PRHF-44863

Gaia OS

A change in shared memory (shmem) behavior may potentially cause a freeze on Management appliances.

PRJ-65926,
PRHF-43620

Gaia OS

Clish may restart unexpectedly when running the set snapshot-onetime command.

PRJ-67603,
PRHF-44603

Gaia OS

In some scenarios, SNMP monitoring may incorrectly report 100% CPU usage. 

PRJ-66884,
PRHF-43932

Gaia OS

In rare scenarios, the CORE_UPLOADER process on Security Gateways may unexpectedly generate a core dump when the number of detected CPU cores exceeds a specific threshold.

PRJ-65947,
PRHF-43616

Gaia OS

Remote and local backup operations fail after installation of Jumbo Hotfix Accumulator with the "Cannot complete the backup process: not enough space in /var/log/CPbackup/backups" error. Refer to sk183767.

PRJ-65649,
PRHF-43017

Gaia OS

Excessive log entries for RADIUS users logging into Gaia Portal. Refer to sk184534.

PRJ-59154,
PRHF-37998

Gaia OS

When the nstat utility (in the iproute2 package) encounters a corrupted state file (for example, if /tmp/.nstat.u0 contains invalid data), it aborts with a core dump instead of providing an error message.

PRJ-64557,
PRHF-42434

Gaia OS

Unable to enter Virtual System with "virtual-system-access all" configured. Refer to sk184282.

PRJ-66615,
PRHF-43985

Gaia OS

Newly added SGM remains "Down" on Scalable Chassis with SSM440 configured with MTU higher than 9000. Refer to sk184653.

PRJ-67025,

PMTR-124210

Gaia OS

In Gaia Portal, for VSNext, the Bridge Group field displays the validation error "The minimum value for this field is 1001," but does not enforce it, and it is possible to submit and create bridge object IDs with values below the minimum threshold. The fix adds validation for the bridge ID during bridge creation in VSNext.

PRJ-69003,
PRHF-45517

Gaia OS

In Gaia Portal, bond member interfaces can be edited when they should be disabled.

PRJ-69112,
PRHF-44815

Gaia OS

After disabling Two-factor authentication (2FA) in Gaia OS, the user still requires a 2FA code on login attempts.

PRJ-59009,
PMTR-110978

Gaia OS

The "config_verify" command or the HCP configuration sync validation incorrectly fails because of a fwkern.conf file mismatch between the Security Group members.

PRJ-68250,
PMTR-126527

Gaia OS

For IDNS-Resolver, when the DNS server returns "TC=1", and communication should be moved to TCP instead of UDP, TCP communication does not block DNS requests.

PRJ-70032,

PMTR-129280

VPN

Improved certificate validation during IKEv2 VPN negotiations to ensure VPN connections are established only after successful certificate-based authentication.

PRJ-65326,
PRHF-42932

VPN

When using Capsule VPN or Endpoint Security VPN (Connect) clients in IPsec mode with IKED enabled, users can successfully authenticate and establish a VPN tunnel. However, group information received from the RADIUS server is not passed to the IKED process. As a result, security policies and access roles that rely on RADIUS group membership do not apply, and users are unable to access internal resources through the VPN

PRJ-70097,

PRHF-45664

VPN

In ElasticXL environments, a stale NAT-T port in the cluster sync overwrites the correct port.

PRJ-64806,
PRHF-42566

VPN

Traffic passing through a route-based VPN tunnel may cause high CPU usage if the traffic is fragmented.

PRJ-68990,
PMTR-116331

VPN

Added the ability to import additional .p12 certificate types as inbound and outbound certificates.

PRJ-62440,
PMTR-116975

VPN

Improved SSL Network Extender (SNX) certificate-based authentication stability and session reliability.

PRJ-67352,
PMTR-125245

VPN

In VPN Site-to-Site environments, a memory leak in VPN-related processes may occur after a VPN driver restart, or during prolonged system runtime.

PRJ-65667,
PMTR-119883

VPN

When Hub Mode is not enabled, traffic destined for dynamic objects included in the Remote Access VPN Split Tunneling Inclusion group may be incorrectly dropped. As a result, remote users may be unable to access resources defined by these dynamic objects, even though they are specified for inclusion in the split tunnel.

PRJ-64223,
PMTR-119552

VPN

IKEv2 Endpoint VPN Client cannot establish a connection when machine certificate authentication is mandatory.

PRJ-69427,
PMTR-128278

VPN

Improved input validation in the VPN L2TP PPP packet parser to handle malformed configuration options correctly.

PRJ-69526,
PMTR-128338

VPN

Improved address validation in the VPN Remote Access proxy to correctly restrict outbound connections to internal and link-local destinations.

PRJ-69114,
PMTR-126293

VPN

When IKEv2 is configured in a Remote Access community, Remote Access clients are incorrectly classified as DAIP (Dynamic Address IP) gateways during IKEv2 negotiation. This causes authentication with machine certificates to fail, preventing successful VPN client connections.

PRJ-66684,
PMTR-123507

VPN

During VPN IKEv2 negotiations with third-party peers that offer multiple combined encryption algorithms (both AES-GCM-128 and AES-GCM-256), the Security Gateway may not properly match the proposal, resulting in IKE failure logs and the tunnel establishment failure.

PRJ-65984,
PMTR-122751

VPN

Remote Access IKEv2 VPN authorization may fail for LDAP Active Directory users whose Common Name (CN) in their certificate is email-based (for example, user@domain.com). When such users authenticate using an External User Certificate, they are unable to pass traffic to the Encryption Domain, resulting in dropped connections.

PRJ-62806,
PMTR-110092

VPN

In some scenarios, the Maestro site failover occurs despite a mismatch in site state or grade. This fix adds visibility and warns when site grades are not the same upon manual site failover. Refer to sk184816.

PRJ-57366,
PRHF-36014

VPN

Certificate validity period not applied after using the "set_cert_validity" command. Refer to sk184230.

PRJ-63662,
PRHF-41115

VPN

Added CA Certificate matching improvements.

PRJ-65609,
PMTR-107052

SD-WAN

SD-WAN overlay traffic debugging is improved, enhancing visibility and troubleshooting capabilities.

PRJ-65547,
PMTR-107842

SD-WAN

VPN traffic outage may occur in SD-WAN overlay environments.

PRJ-64735,
SDWANGW-5773

SD-WAN

A VPN IPv6 traffic outage may occur when a host/network object is defined with the Security Gateway's main IPv6 address.

PRJ-66777,
PRHF-43782

SD-WAN

In some scenarios, enabling SD-WAN Symmetric Return may lead to elevated CPU utilization on Secure Network Distributor (SND) cores.

PRJ-67654,
PRHF-44765

SD-WAN

In a rare scenario, the FWK process may crash when handing SD-WAN traffic.

PRJ-68327,
AAD-9724

SD-WAN

On the Scalable Platform Cluster, LS fragmented packets may be dropped on the receiving member with an error "handle_sim_inbound_frag: error (2): frag freed, ret_val (11): FRAG_ERROR_MSG_DUPLICATE in fragment" on a loaded environment with a lot of corrected fragmented packets.

This may also occur with Cluster HA; however, correcting packets is negligible in such environments.

PRJ-64473,
PMTR-120815

SD-WAN

In some scenarios, SD-WAN ISP link status may fluctuate between UP and DOWN states. Reduced SD-WAN ARP probing default sensitivity to packet drops.

PRJ-68796,
PMTR-127298

Cloud Firewall

Deleting a license pool while Cloud Firewall Gateways are still associated with it causes all licensing operations (add, distribute, remove) to continuously fail until the orphaned reference is manually cleared from the database.
The fix allows licensing operations to complete normally without administrator intervention.

PRJ-67514,
PMTR-125729

Cloud Firewall

Moving Cloud licenses from one pool to another triggers license alignment: If adding a new license to CK fails, license removal will not be initiated on the Security Gateways.

PRJ-69051,
PMTR-127703

Cloud Firewall

When a Cloud license's support contract expires, the system now keeps all gateways licensed and alerts the administrator with remediation steps, instead of silently removing their licenses.

PRJ-68717,
PRJ-67567

Scalable Platforms

When deleting a bond in an ElasticXL environment, site failover may occur.

PRJ-68808,
PMTR-126879

Scalable Platforms

When a Security Group member transitions from a down state to an active state, the synchronization process with other members in the Security Group may not complete before the recovered member becomes active. This can result in traffic drops because of incomplete state synchronization.

PRJ-65598,
PMTR-122629

Scalable Platforms

Intermittent VS failover when both Maestro Hyperscale Orchestrators (MHOs) have the interface link state set to Down. Refer to sk184568.

PRJ-65541,
PMTR-108818

Scalable Platforms

In Maestro or ElasticXL environments with VPN enabled, traffic may be dropped with the log message "fwha_select_should_drop_vmac".

PRJ-65603,
PMTR-119583

Scalable Platforms

In a dual-site Security Group configuration, if all members of site 1 are removed from the Security Group, the Hardware tab in SmartConsole displays an error message instead of the expected hardware information.

PRJ-65792,
PRA-5195

Scalable Platforms

The unique IP address assigned to the standby site may not function correctly during a VSNext deployment.

PRJ-67166,
PRHF-43859

Scalable Platforms

  • When a large number of bond interfaces are configured, the synchronization of link states may fail.

  • In rare scenarios, a cluster member may become stuck in the "active (sync)" state. When this occurs, the affected member does not handle network traffic as expected.

  • There may be inconsistencies in the reported link state across Security Group Members (SGMs), as observed with the "asg stat -v" command.

PRJ-67193,
PRHF-41860

Scalable Platforms

On Maestro appliances, /var/log/messages may be flooded with "asg_copy_capture" error messages when the system attempts to retrieve packet capture files that do not exist on remote Security Group members.

PRJ-67535,
PRHF-44544

Scalable Platforms

 A remote user may not be able to switch between Virtual Systems (VSs) in the WebUI. While a local admin user is able to switch between VSs as expected.

PRJ-65701,
PMTR-122627

Scalable Platforms

"TCP packet out of state" or "connection dropped due to state mismatch" messages may be seen in SmartLog or SmartView Tracker. These drops specifically occur on the sync interface, which is used for internal communication and synchronization between Security Group members.

PRJ-67485,
PMTR-121081

Scalable Platforms

After a Virtual System (VS) is deleted, its CTX folders are not removed.

PRJ-70256,

PMTR-129110

Scalable Platforms

Deleting a bond may trigger a site failover because LACP negotiation resets the IPs of slave interfaces, leading to an IAC pnote and failover.

PRJ-62476,
PMTR-116202

Scalable Platforms

In some scenarios, the "asg monitor" freeze timer is missing for ElasticXL clusters.

PRJ-67910,
PMTR-126596

Scalable Platforms

The PERFANALYZE process may exit because of an incorrect value type. As a result, SNMP performance data for the Security Group (ASG) is not updated.

PRJ-68538,
PMTR-127622

Scalable Platforms

In VSLS clusters with multiple members, when a member rejoins the cluster after a reboot, an Interface Active Check (IAC) problem notification may incorrectly appear on the rejoining member, showing it in ACTIVE state. This occurs even though all interfaces are physically UP and the cluster is fully functional.

PRJ-67237,
PMTR-124193

Scalable Platforms

In some scenarios, Anti-Spoofing generates excessive drops on ICMPv6 Neighbor Advertisement packets because traffic reaches other cluster members.

PRJ-63908,
PRHF-41940

Scalable Platforms

Policy installation on one Virtual System (VS) fails without a visible error message. Refer to sk184194.

PRJ-69361,
PMTR-126478

Scalable Platforms

The "set management interface" command does not show WRP interfaces on Maestro in VSNext mode.

PRJ-64404,
HEC-1550

Scalable Platforms

All traps coming from a dedicated Member of a Security Group now include the hostname.

For example, a trap for Member 1_4 will include the hostname (for example, hostname-s01-04), providing clearer identification than just 1_4.

PRJ-58703,
PMTR-97177

Scalable Platforms

The command "set backup restore ftp" executed in gClish is applied only to the SMO member and not to all Security Group members.

PRJ-62839,
PMTR-117623

Scalable Platforms

On ElasticXL, changing the freeze interval by running the command "set cluster configuration high-availability freeze_interval 30" is not applied to Virtual Systems other than VS0.

PRJ-69401,
PMTR-128388

Scalable Platforms

The "CliError( ) called without module or error code" error message is displayed when attempting to run VSX commands on an unsupported configuration in Clish.

PRJ-65997,
HEC-2256

Scalable Platforms

Added the ability for alerts to send traps to trap receiver servers using IPv6.

PRJ-64157,
PMTR-120199

Scalable Platforms

In some scenarios, when proxy ARP is used, unloading and reloading the policy causes members to enter a down state with a configuration pnote.

PRJ-67459,
PMTR-109489

Scalable Platforms

When performing a SIC reset after Anti-Malware (AMW) has been installed, some members may enter a "cluster-down" state with an AMW Critical Device.

PRJ-68395,
PRHF-44781

Scalable Platforms

Reduced CPU overall load caused by monitoring processes on Maestro Orchestrator.

PRJ-66762,
PMTR-121709

Scalable Platforms

Upgrade of a Scalable Group in the Traditional VSX / VSNext mode fails.

  • The Jumbo Hotfix Accumulator package must be installed on both the Management Server and the Scalable Group.

PRJ-67741,
PRHF-44577

Scalable Platforms

When adding or removing VS, if the freeze timeout ended before the VS was fully stable, the VS might still have a Critical Device (pnote), which will cause the member to go down. Refer to sk185115.

PRJ-67639,
PMTR-125756

Scalable Platforms

In some scenarios, a Gateway that leaves the cluster is still shown as an active member to other Security Group members. This can result in the Gateway not being displayed as an available Gateway.

PRJ-67329,
PMTR-125157

Scalable Platforms

The Tunnel Test mechanism may incorrectly select a Sync interface IP address instead of the appropriate external interface IP. This leads to NAT drops and subsequent VPN tunnel disconnections.

PRJ-60809,
PMTR-109844

Scalable Platforms

The HCP configuration sync verifier ("config_verify") incorrectly reports a failure because the asg_diag_file.dat file is not synced between members.

PRJ-64748,
PMTR-121220

Scalable Platforms

Added the ability to sync new VS when members pull the configuration.

PRJ-69164,
CST-492

Carrier Security

In a rare scenario, a processed malformed GTP packet may cause the Security Gateway to crash.

PRJ-66711,
CST-437

Carrier Security

A GTPv0 tunnel fails to establish under certain conditions.