R82 Jumbo Hotfix Take 126

 

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 126

Released on 09 September 2026

Take 126 - New Functionality

 

PRJ-70074,
PMTR-129515

Security Management

NEW: Introducing the show-ad-content Management API, which enables the retrieval of users, groups, and machines from Active Directory.

PRJ-69931,
HEC-2296

Scalable Platforms

NEW: The Virtualization Screen is added to VS0 Insights, displaying Virtual Systems statistics, including Virtual Systems problem detection, alongside general environment metrics and the Resource Search tool.

  • Resource Search Tool: Provides a cross Virtual Systems interface search capability.

  • Problem Detection: Introduces Virtual System problem indicators in the Status and Problem Categories columns, showing problem classifications. Users can select a Virtual System row in the Virtual Systems table to re-launch Insights in the Virtual System context and investigate issues in AI Detector.

PRJ-69931,
HEC-2296

Scalable Platforms

NEW: Added support for integrating clean-install machines running a higher version into an existing ElasticXL environment.

Take 126 - Improvements and Resolved Issues

 

PRJ-71613,
ODU-4598,

PRJ-71129,
ODU-4470

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 177 and Take 178 of Web SmartConsole. Refer to sk170314.

PRJ-71381,
ODU-4591

Automatic Updates - Policy Insights

UPDATE: Added Take 98 of Policy Insights Release Updates. Refer to sk183421.

PRJ-71258,
ODU-4477

Automatic Updates - Policy Insights

UPDATE: Added Take 97 of Policy Insights Release Updates. Refer to sk183421.

PRJ-71267,
ODU-4449

Automatic Updates -

CloudGuard Network

UPDATE: Added Take 33 of CloudGuard Controller Release Updates. Refer to sk181842.

PRJ-71263,
ODU-4484

Cloud Firewall

UPDATE: Added Take 325 of CME (Cloud Management Extension) Release Updates. Refer to sk157492.

PRJ-66287,
PRHF-43807

Automatic Updates - Smart-1 Cloud

UPDATE: After running the Get Interfaces command, updating VTI interface objects can fail on Spark Firewall clusters if VPN peer names were changed.

PRJ-68591,
PMTR-127145

Automatic Updates - HCP

UPDATE: The HCP configuration sync verifier (the config_verify command) may incorrectly indicate a mismatch in the fwkern.conf file due to differences in the line order between members.

PRJ-71254,
ODU-4492

Automatic Updates - HCP

UPDATE: Added Take 95 of HealthCheck Point (HCP) Release Updates. Refer to sk171436.

PRJ-69264,
PMTR-127012

Security Management

UPDATE: Added support for the match-settings parameters in the application-site Management API.

PRJ-58115,
PMTR-129439

Logging

UPDATE: Added support for displaying the Member ID field in the Logs view through Edit Profile > Columns Profiles.

PRJ-60267,
PRHF-38897

Gaia OS

UPDATE: Gaia Cloning Group synchronization (port 1129) now uses updated and more secure SSL/TLS versions for internal communication. Refer to sk182091.

PRJ-70738

VSNext

UPDATE: The SP Migration Tool now supports migrating VSX ClusterXL to VSNext ElasticXL.

PRJ-62163,
PRHF-40230

VPN

UPDATE: Added support for treating trusted CA certificates with non-compliant attributes as valid. This includes certificates with incorrect Key Usage settings or missing Basic Constraints, based on customer-defined configurations. Refer to sk183800.

PRJ-71485,

PMTR-131442

VPN

UPDATE: Resolved CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN. Refer to sk1000117.

PRJ-71551,

PMTR-131527

VPN

UPDATE: Resolved CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution. Refer to sk1000118.

PRJ-70385,
PMTR-129271

Security Management

SmartConsole may display a "No communication" error message caused by a file descriptor leak in the FWMHA process after prolonged uptime.

PRJ-69442,
PRHF-45656

Security Management

Accelerated policy installation may be skipped if Compliance generates a high number of audit log entries between sessions.

PRJ-67812,
PMTR-126383

Security Management

Disk space on the Security Management Server may become depleted due to the excessive growth of internal PostgreSQL database tables.

PRJ-70234,
PRHF-46050

Security Management

After deleting a Security Management Server object, attempting to create a new management host object with the same IP address may fail with an "IPv4 address is already in use" validation error.

PRJ-67495,
PRHF-44700

Security Management

In rare scenarios, the accumulation of large API request-status files could cause Security Management Server slowness.

PRJ-68348,
PRHF-45145

Security Management

In some scenarios, running the show access-rulebase Management API command with a non-existent object identifier could return an HTTP 500 error with a "Null Pointer Exception" error message.

PRJ-69187,
PRHF-45542

Security Management

When generating a Show Changes PDF report for a workflow or session, the report could include internal system changes, such as IPS protection changes, that were not performed by the user.

PRJ-68287,
PRHF-44951

Security Management

Policy objects may fail to open in Web SmartConsole with a "Something went wrong" error message.

PRJ-69864,
PRHF-45625

Security Management

When one administrator installs a policy, other logged-in administrators may see an "Error retrieving results" message in the Tasks window instead of the policy installation progress.

PRJ-69861,
PRHF-46038

Security Management

Administrators logging into SmartConsole with certificate authentication at the MDS level using the "\MDS" format may unexpectedly receive read-only permissions instead of the expected read-write access.

PRJ-70784,
PRHF-46219

Security Management

In SmartConsole, selecting a value in a filter category within the Gateways & Servers view may cause other options in that category to disappear, preventing the selection of multiple filter values simultaneously.

PRJ-67776,
PMTR-126316

Security Management

Snort IPS protections are not downloaded to the local domain during Global Policy Assignment.

PRJ-59221,
PRHF-37312

Security Management

In some scenarios, the Changes report for a published policy, sent via email by SmartTasks, may appear as a blank file.

PRJ-57686,
PMTR-109180

Security Management

In some scenarios, the Integration & Services view in Multi-Domain Security Management Servers may show the following error message even though the Allow Upload setting is enabled: "An error occurred on the server "<server_name>": The consent option "Allow Upload" is disabled. Refer to sk176064."

PRJ-67853,
PRHF-45034

Security Management

In rare scenarios, login to SmartConsole may fail due to a timeout.

PRJ-67760,
PRHF-44799

Security Management

Improved debug logging in the cpm.elg file during upgrades of a Multi-Domain Security Management Server.

PRJ-67763,
PRHF-44772

Security Management

In rare scenarios, deleting a Secondary Security Management Server fails because it references objects that no longer exist.

PRJ-66786,
PRHF-43884

Security Management

In SmartConsole, a network object that is no longer referenced by any policy may fail to be deleted with an "object is being used" error message.

PRJ-67610,
PRHF-44814

Security Management

In unpublished sessions, the Change report may not display the names of newly created objects when these objects are added as members of another object.

PRJ-67613,
PRHF-44583

Security Management

In a Management High Availability environment, the statuses of clusters and cluster members may be displayed incorrectly on the secondary Security Management Server.

PRJ-66569,
PRHF-43991

Security Management

Policy installation may fail with error code 0-2-2000078 when a policy rule references a track object that cannot be resolved.

PRJ-70231,
PRHF-45998

Security Management

In some scenarios, when a Multi-Domain Security Management Server is connected to the Check Point Portal, a connectivity failure warning for the Global SmartEvent server may appear, even though Global SmartEvent servers are not supported in the Check Point Portal.

PRJ-71302,
PRHF-46484

Security Management

When a Data Center object is imported into SmartConsole and the session is discarded, the object may not be removed and might remain visible in SmartConsole.

PRJ-71006,
PRHF-46361

Security Management

In some scenarios, logging into SmartConsole may fail or time out.

PRJ-63511,
PRHF-41422

Security Management

The "mds_restore" command may not restore audit logs at the MDS level.

PRJ-69392,
PRHF-45724

Security Management

Security Gateways created using the Management API or SmartConsole might be assigned duplicate Dynamically Assigned IP (DAIP) addresses. Refer to sk185077.

PRJ-71563,
PRHF-47729

Security Management

In some scenarios within Multi-Domain Security Management environments, AI Assist may display the following error message: "There was an internal error processing the query".

PRJ-67755,
PRHF-44852

Security Management

Policy installation may fail when custom authentication .ttm files are not included during policy package preparation, resulting in a "No such file or directory" error message.

PRJ-70410,
PRHF-46322

Security Management

In an environment with multiple Multi-Domain Security Management (MDS) Servers, High Availability synchronization between MDSs may intermittently fail with the "NGM failed to import data" error message because of missing VSEC license objects in the secondary MDS database.

PRJ-62523,
PRHF-40980

Security Management

On a Multi-Domain Security Management Server, the "api stats-group-by-domain" command may report all requests as "unknown domain" instead of categorizing them per domain. Refer to sk183892.

PRJ-64480,
PRHF-42459

Security Management

In some scenarios, desktop policy installation fails with a "Could not find type of Network Object 'ReferenceObject'. Desktop policies will not be installed on Policy Servers" error message.

PRJ-65796,
PMTR-120362

Security Management

Changes made to .def and .conf files are not applied during an accelerated policy installation if a previous policy installation failed after the files were updated.

PRJ-70501,
PMTR-129992

Security Management

New licenses may not be synced to the Check Point Portal if the license expiration date includes a single-digit day.

PRJ-60816,
PRHF-39436

Multi-Domain Management

When logging in to SmartUpdate on a Multi-Domain Security Management Server, domain licenses may not appear in the Domain Licenses view.

PRJ-70589,
PRHF-46795

Multi-Domain Management

The mds_backup command does not include the configuration of MDS-level log exporters in the backup.

PRJ-68526,
PRHF-45066

SmartProvisioning

When running the LSMcli AddROBO command with the -S (SubstitutedNamePart) parameter, the cluster profile name suffix may not be substituted correctly.

PRJ-67345,
PRHF-44310

Logging

In rare scenarios, the LOG_INDEXER process may crash unexpectedly due to improper memory handling.

PRJ-57167,
PRHF-36102

Logging

When viewing Forensics Reports in SmartView through the Check Point Portal, non-ASCII characters may appear distorted.

PRJ-69436,
PMTR-126941

Logging

The LOG_INDEXER process on the Security Management Server may generate a core dump due to a memory handling issue.

PRJ-70004,
PRHF-41245

Logging

In some scenarios, the Service field may not appear in logs for certain connections, primarily for dropped traffic, even when destination port information is available in the raw log.

PRJ-67637,
PMTR-125374

Logging

In some scenarios, the LOG_INDEXER process may crash repeatedly, causing core dumps on the Security Management server.

PRJ-69456,
PMTR-126981

Logging

In some scenarios, the LOG_INDEXER process may unexpectedly exit and generate a core dump while processing log files.

PRJ-69986,
PRHF-46185

Logging

When viewing logs in the Check Point Portal, a "Query failed" error message may intermittently appear for several minutes.

PRJ-68884,
PRHF-45417

Logging

Exporting logs that contain "ampersent" in their fields to a CSV file via SmartView web application may fail with a “Failed to export” error message.

PRJ-69246,
PRHF-45525

Logging

When right-clicking the "*_interface" field in the SmartView Logs web view and selecting Add as Filter, the query may fail, resulting in no logs being displayed.

PRJ-67801,
PRHF-45012

Security Gateway

When a user configures NAT to convert a connection's destination IP address from unicast to multicast, the Security Gateway may transmit packets with an incorrect MAC address when SecureXL is enabled.

PRJ-66556,
PRHF-43835

Security Gateway

In rare scenarios, a Security Gateway may crash when LSP (Link State Propagation) is enabled.

PRJ-66265,
PRHF-43044

Security Gateway

The FWK process may restart unexpectedly due to improper handling of a connection.

PRJ-62868,
PRHF-41020

Security Gateway

HTTPS POST request fails if the uploaded content exceeds 10KB. Refer to sk184936.

PRJ-66070,
SWSCFG-654

Security Gateway

The PDPD daemon may encounter high CPU utilization when Nested Groups query method 5 (query by SIDs) is in use. Refer to sk183748.

PRJ-65548,
PRHF-42950

Security Gateway

Optimized DNS handling to align with the DNS additional configuration formats.

PRJ-69205,
PRHF-45101

Security Gateway

In some scenarios, Spike Detective file descriptors may remain undeleted.

PRJ-69102,
PRHF-45611

Security Gateway

The RAD daemon may unexpectedly exit on VSX Gateways.

PRJ-61607,
PRHF-40126

Security Gateway

The custom trap for BGP may not work on MDPS when BGP is configured in the Data Plane. Refer to sk183633.

PRJ-69870,
PRHF-46057

Security Gateway

The ROUTED process may restart unexpectedly when using the DHCPv6 relay code.

PRJ-66299,
PRHF-43833

Security Gateway

The FWK process may unexpectedly restart because of an incorrect integration with CPView.

PRJ-70303,
PRHF-46417

Security Gateway

In some scenarios, servers sent compressed data with Content-Encoding: deflate but included an additional zlib header (starting with 78 01), while the Security Gateway expected raw deflate data without any header.

PRJ-62560,
PRHF-40560

Security Gateway

Enhanced stability when manual edits to the fwkern.conf file result in a malformed configuration. To manage the file, it is recommended to use the -f option of the fw ctl set command, as detailed in sk26202. Refer to sk184081.

PRJ-58567,
PRHF-26696

Security Gateway

In some cases, the Captive Portal fails to authenticate users when SAML authentication is enabled.

PRJ-70364,
PRHF-46526

Security Gateway

In some scenarios, a memory leak in the FWK process occurs when two HTTP/2 upgrade requests are sent over the same connection.

PRJ-67359,
PRHF-41891

Security Gateway

In some scenarios, the Security Gateway may not close connections properly when a device stops responding during an active download, leading to a gradual memory leak over time.

PRJ-70038,
PRHF-46215

Security Gateway

In some scenarios, incorrect memory size allocation identified in the c_icap open-source code may cause a crash in the ICAP Server.

PRJ-66835,
PRHF-43754

Security Gateway

In some scenarios, CPView may display an incorrect value for CPU user time. Refer to sk184722.

PRJ-68602,
PRHF-45088

Security Gateway

Threat Prevention inspection of Server Message Block (SMB) traffic during CREATE+WRITE operations may cause a memory leak during file write processes.

PRJ-67539,
PRHF-44757

Security Gateway

In some scenarios, multicast traffic and a race condition during route lookup may lead to a crash in the Security Gateway.

PRJ-69500,
PRHF-40443

Security Gateway

In some cases, an ICAP server closing the connection to an ICAP client with an RST may cause an FWK process crash.

PRJ-71456,
PRHF-47521

Security Gateway

In some scenarios, users can connect to Mobile Access/SSL Network Extender, but do not have access to internal resources after upgrading. Refer to sk185259.

PRJ-70135,
PMTR-129198

Security Gateway

When using ISP Redundancy in a VSNext environment, failover between ISPs may not occur if the WRP interface is configured as one of the ISPs.

PRJ-67417,
PMTR-124725

Security Gateway

In some scenarios, the ICAP Server may crash because of memory issues.

PRJ-70509,
PMTR-130005

Threat Prevention

In certain scenarios, the Security Gateway may fail to apply a new GeoIP database update.

PRJ-69948,
PRHF-46128

Threat Prevention

The Anti-Virus may fail to load external IOC feeds that contain URL-type observables.

PRJ-65680,
PRHF-43309

Threat Emulation

Files without extensions were receiving a Scan Pass verdict from the ICAP server. As a result, malicious files without extensions were also assigned a Scan Pass verdict, which ultimately led to a Benign classification.

PRJ-64892,
PRHF-42488

Identity Awareness

In certain scenarios, Captive Portal may return an HTTP 500 error after successful Kerberos SSO authentication. Refer to sk184373.

PRJ-69216,
PRHF-39546

Identity Awareness

Improved handling of duplicate Identity Collector events on the PDP Security Gateway.

PRJ-69104,
PRHF-45589

Identity Awareness

In rare scenarios, the FWK process may exit unexpectedly on the PEP side when Identity Sharing is configured to receive identities from remote PDPs. Refer to sk185012.

PRJ-57875,
PRHF-34201

Identity Awareness

In some scenarios, errors in rule number calculation prevented packet tagging from working.

PRJ-65133,
PRHF-42745

URL Filtering

An HTTPS Inspection rule that contains a custom application whose name includes spaces or certain unsupported characters does not match during policy enforcement. Refer to sk184773.

PRJ-64168,
PMTR-118916

IPS

Enforced compliance with the HTTP RFC by requiring a "/" in the request path for non-proxy HTTP connections, except for the CONNECT and OPTIONS methods. Traffic that does not meet this requirement will be dropped if "Non-Compliant HTTP" is set to "Drop" and "Strict Request Parsing" is enabled.

PRJ-67477,
PRHF-44630

SSL Inspection

Certificate validation may fail for certificates containing an ASN.1 NumericString in the X.509 Subject attribute.

PRJ-67474,
PRHF-44623

SSL Inspection

In some scenarios, a memory leak may occur in the WSTLSD process when it fails to decode a certificate.

PRJ-65972,
PRHF-43606

SSL Inspection

In rare cases, NAT may have been incorrectly identified in specific probing scenarios during HTTPS inbound inspection.

PRJ-64060,
PRHF-42044

ClusterXL

When processing VPN traffic in a ClusterXL environment with "sync-to-all" enabled, the absence of sequence number updates from the active site can cause the Fast Acceleration (FnA) mechanism to become unresponsive. As a result, affected connections may be dropped, and a log entry is generated "dropped by fw_conn_inspect Reason: Frozen connection".

PRJ-63127,
PRHF-41335

ClusterXL

In a Cluster HA environment, the Gaia Portal on the standby member may present an incorrect server certificate. Instead of the correct certificate, the standby member displays the default self-signed certificate (192.168.1.1).

PRJ-64264,
PRHF-41806

ClusterXL

In scenarios involving asymmetric traffic, where the same connection tuple is reused frequently, connections may be dropped and flagged as "out of state". Refer to sk184181.

PRJ-67117,
PMTR-120253

SecureXL

In some scenarios, the VSX Gateway may experience significant latency when passing traffic between Virtual Systems through a Virtual Router.

PRJ-58857,
PMTR-110610

SecureXL

Multicast routes may not update or respond correctly to changes in the network.

PRJ-70342,
PRHF-46357

SecureXL

In some scenarios, VLAN tags are stripped and MAC addresses become malformed after traffic passes through the bridge. Refer to sk185101.

PRJ-66073,
PRHF-43570

SecureXL

In rare scenarios, a performance issue may occur when a policy is installed on multiple Virtual Systems simultaneously. Refer to sk184585.

PRJ-67269,
PMTR-125173

SecureXL

In some scenarios, the Security Gateway may restart unexpectedly when passing traffic through LightSpeed hardware acceleration interfaces with SecureXL User Mode enabled.

PRJ-57642,
PRHF-33964

SecureXL

In some scenarios, the Security Gateway may not properly remove closed TCP connections, processed through Active Streaming, from its accelerated connections table if a new security policy was installed beforehand.

PRJ-69943,
PMTR-127433

SecureXL

In some scenarios, VPN packets are dropped in User Mode (UPPAK) during encryption when QoS is active.

PRJ-70272,
PRHF-45730

SecureXL

A rare scenario handling Jumbo Frames of specific sizes on Intel-based NICs may trigger a driver internal protection (MDD) error, potentially impacting performance or connectivity.

PRJ-66861,
PMTR-124252

SecureXL

In some scenarios, the VSX Gateway may unexpectedly restart when passing traffic through a Virtual Switch with SecureXL User Mode enabled.

PRJ-70926,
PRHF-46835

SecureXL

In certain scenarios, the VSX Gateway may transmit packets with incorrect MAC addresses for cleartext connections when SecureXL is enabled, specifically when these packets are sent through a Virtual Router or Virtual Switch.

PRJ-67772,
PMTR-119674

SecureXL

In some scenarios, the VSX Gateway may experience poor performance when passing traffic between Virtual Systems through a Virtual Switch with SecureXL User Mode enabled.

PRJ-70356,
PMTR-127257

SecureXL

In some scenarios, the VSX Gateway may not properly assign CPUs to a Firewall instance or SND after booting up when SecureXL User Mode is enabled.

PRJ-69468,
PRHF-45709

Gaia OS

Updated Neighbor Advertisement logic to set the Router (R) flag to 1 for cluster-generated IPv6 NAs, ensuring RFC 4861 compliance and maintaining stable IPv6 connectivity by preventing hosts from removing the cluster IPv6 Gateway from their Default Router List. Refer to sk185119.

PRJ-68605,
PRHF-44741

Gaia OS

In rare scenarios, the Security Gateway may unexpectedly crash due to timer corruption.

PRJ-66702,
PRHF-43888

Gaia OS

Duplicate interface configuration entries appear in the show configuration command output. Refer to sk184759.

PRJ-70121,
PRHF-45729

Gaia OS

When syslog messages are forwarded to the Security Management Server using the set syslog cplogs on command, they may be misclassified under an incorrect blade instead of Syslog. This misclassification can make it challenging to filter, correlate, and analyze the logs effectively.

PRJ-62540,
PRHF-40963

Gaia OS

The selected interfaces under Network Management > Hosts and DNS > DNS Proxy Forwarding Domains > "Listen on specific interfaces" option may not be applied correctly in Gaia Portal.

PRJ-58309,
PRHF-37219

Gaia OS

The lower bottom threshold for the PCH-Vin sensor on Check Point Firewall 9700 appliances was set incorrectly.

PRJ-70006,
PRJ-69901

Gaia OS

NTP synchronization failure when using IPv6.

PRJ-64571,
PRHF-42478

Gaia OS

After backup and restore, Gaia Portal enforces 2FA, but Clish allows password-only login and does not prompt fora 2FA code. Refer to sk184285.

.

PRJ-68556,
PRHF-44964

Gaia OS

Two-Factor Authentication (2FA) initial setup may not be triggered via the Gaia Portal on Scalable Platforms.

PRJ-69552,
PRHF-45732

Gaia OS

Performance improvements have been made to the VSX interface configuration process.

PRJ-66895,
PRHF-44101

Gaia OS

In some scenarios, duplicate interface entries appear in the output of the "show configuration" Clish command.

PRJ-66758,
PMTR-122832

Gaia OS

Upgrading a Scalable Group in Traditional VSX or VSNext mode may fail if the Jumbo Hotfix Accumulator package is not installed on both the Security Management Server and the Scalable Group.

PRJ-70692,
PRHF-46741

Gaia OS

Added the ability for remote TACACS+ superusers to switch between Virtual Systems in the Gaia Portal.

PRJ-69254,
PMTR-126101

Gaia OS

In some scenarios, the Security Gateway may fail to access interface data correctly when SecureXL User Mode is enabled.

PRJ-69096,
PRHF-45473

Gaia OS

Clish may crash when running the show virtual-system all command under specific conditions.

PRJ-70020,
PMTR-129289

Gaia OS

In a rare scenario, the CPU time may be displayed incorrectly.

PRJ-69617,
PRHF-45826

Gaia OS

The show arp dynamic all Clish command displays (null) MAC address for 15-character IP addresses. Refer to sk185044.

PRJ-63783,
PRHF-41841

Gaia OS

When the backup file size is large, export to Microsoft Azure may fail. Refer to sk184010.

PRJ-70346,
PMTR-129663

Routing

In some cases, the ROUTED daemon incorrectly identified itself as a slave on both cluster members after boot, causing ROUTED PNOTEs to remain permanently set.

PRJ-60409,
TPDO-4412

Routing

Certain standard IPv6 addresses may have been incorrectly identified as multicast addresses.

PRJ-69978,
PRHF-45943

Routing

In some scenarios where the SPT cannot be set on an entry with the Decap bit enabled, the Decap bit is now reset to ensure that incoming Register packets can be processed.

PRJ-70632,
PMTR-126125

Routing

When receiving an equal-cost LSA from two different ASBRs, only one next hop was previously installed for the route. Now, all relevant next hops are installed.

PRJ-70716,
PMTR-130236

VSNext

Creating a new Virtual System with an automatically assigned ID could fail after a failover, displaying an error that the Virtual System ID already exists.

PRJ-70468,
PMTR-129616

VSNext

VLAN filtering was incorrectly enabled on VSNext bridges, causing traffic to be tagged with VLAN 1 or dropped.

PRJ-70129,
PMTR-129435

VSNext

MTU changes made to a WRP interface are now automatically propagated to the corresponding WRPJ interface.

PRJ-70094,
PRJ-69973

VSNext

In Maestro in VSNext mode, using a Virtual Switch with a data interface as the management interface may cause traffic flapping due to incorrect MAC address assignments between the members.

PRJ-68694,
PRHF-45292

Traditional VSX

In rare scenarios, a crash may occur in Traditional VSX during a call to kmem_cache_alloc.

PRJ-67299,
PRHF-44576

Mobile Access

The Mobile Access Blade portal may not function properly with web applications that set HTTP cookies containing the pipe ('|') character in their values.

PRJ-69267,
PRHF-45001

VPN

In some scenarios, the VPN tunnel flaps every 40 seconds when the in-kernel tunnel test is enabled.

PRJ-70669,
PRHF-45155

VPN

Automatic Security Gateway certificate enrollment using CMP with an external OPSEC PKI CA (for example, EJBCA) fails with "Internal Error" status in SmartConsole.

PRJ-58818,
AAD-3020

VPN

Improved Site-to-Site connectivity in Enhanced Link Selection configurations with only IPv6 links.

PRJ-70270,

VPN

In some scenarios with DAIP peers, VPN tunnel tests may fail, causing intermittent disruptions.

PRJ-66901,
PMTR-123203

VPN

EDPC tunnel establishment failure after MEP failover to a new Security Gateway.

PRJ-70579,
PRHF-46735

VPN

In rare scenarios, the VPND process may crash during Capsule VPN connections that use Mobile Device Management (MDM) compliance and certificate-based authentication.

PRJ-65402,
PMTR-122348

VPN

Improved stability for Permanent Tunnel functionality when using Tunnel Test UDP/18234 in Maestro environments.

PRJ-70687,
PRHF-46758

VPN

Capsule Connect / VPN users are unable to log in and receive the error message "Client's configuration is not verified". Refer to sk185144.

PRJ-70270,
PRHF-46350

VPN

In some scenarios with DAIP peers, VPN tunnel tests may fail, causing intermittent disruptions.

PRJ-65762,
PMTR-127758

VPN

Improved IKEv2 stability when handling concurrent IKE messages that share the same IKE cookies.

PRJ-69880,
PRHF-45871

VPN

High CPU utilization may occur without a corresponding indication of heavy web connection load.

PRJ-70103,
PMTR-128918

VPN

Improved stability in VPN tunnel monitoring workflows.

PRJ-70123,
PMTR-128909

VPN

Added Layer Two Tunneling Protocol (L2TP) stabilization improvement.

PRJ-70112,
PMTR-128876

VPN

Improved stability and robustness in VPN session message handling during connection flows.

PRJ-70107,
PMTR-128831

VPN

Enhanced stability in IKEv2 session establishment.

PRJ-70044,
PMTR-128892

VPN

Enhanced stability and reliability in IKEv2 certificate handling.

PRJ-67859,
PRHF-44977

VPN

In rare scenarios between an LSM Central Gateway and an LSM Satellite Gateway, the Route Injection Mechanism (RIM) may not function correctly.

PRJ-66943,
PRHF-44104

SD-WAN

In a Traditional VSX deployment, the SD-WAN steering process may generate core dumps, even if SD-WAN is not configured on the machine.

PRJ-70376,
PMTR-129571

Cloud Firewall

The vsec_lic_cli view command now marks Certificate Keys with expired contracts as (Expired) and provides warnings for Certificate Keys that require renewal.

PRJ-70117,
CGNSIS-2240

Cloud Firewall

Nightly distribution may fail when no default license pool is set. The system now automatically promotes an available pool during distribution.

PRJ-70060,
PMTR-129147

Cloud Firewall

Reinstalling a Cloud Firewall central license with a regenerated signature may create a duplicate entry in the Management Server's license repository, which could prevent license distribution to managed Security Gateways. The Management Server now detects such conflicts and blocks the installation to avoid creating duplicates.

PRJ-63465,
PMTR-118740

Scalable Platforms

In some scenarios, a member may become stuck in the INIT state after being rebooted during a sync loss between sites.

PRJ-68896,
PRHF-45528

Scalable Platforms

On Check Point Firewall appliances configured with ElasticXL and two Sync interfaces, the second Sync interface is not recognized as a candidate and cannot be added as a subordinate to the Sync bonding group in Gaia Clish.

PRJ-61935,
PMTR-108858

Scalable Platforms

In rare scenarios, a full sync may fail to occur after a reboot because the sync is triggered before the full sync request is completely registered.

PRJ-70187,
PRJ-70900

Scalable Platforms

Network Time Protocol (NTP) may stop functioning after an upgrade.

PRJ-60205,
PMTR-113500

Scalable Platforms

On a Maestro Orchestrator (MHO), the FWD process may unexpectedly start during cpstart, displaying "FireWall-1: This is a Security Management server, No security policy will be loaded" messages on the console.

PRJ-70924,
PRJ-70917

Scalable Platforms

After uninstalling an upgrade, the permissions on the $SMODIR/lib directory and related libraries may become more restrictive than required. As a result, the Gaia Portal fails to load pages. Refer to sk185178.

PRJ-70986,
PMTR-130438

Scalable Platforms

In VSNext environments, creating a management bond interface via gClish using the command add bonding group <Mgmt interface> may fail with the error "this interface is already in use".