List of All Resolved Issues and New Features in R82.10 Jumbo Hotfix Accumulator

Jumbo Hotfix Accumulator for R82.10

List of All Resolved Issues and New Features in R82.10 Jumbo Hotfix Accumulator

Download Jumbo Hotfix Accumulator Takes
Review the Critical Information section before installing a new Take.

List of Takes](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/R82.10/R82.10-List-of-all-Resolved-Issues.htm#)

Take Available Since Recommended Since
R82.10 Jumbo Hotfix Take 36 22 Jul 2026 -
R82.10 Jumbo Hotfix Take 24 15 Jun 2026 21 Jun 2026
R82.10 Jumbo Hotfix Take 19 26 May 2026 -
R82.10 Jumbo Hotfix Take 6 06 Apr 2026 -

Download CSV

ID Product Description
Take 36
Released on 22 July 2026
Take 36 - New Functionality
PRJ-69884,
PRJ-69883
Security Management NEW: Introducing Unified Security Management from SmartConsole.
SmartConsole now provides a single management plane for your organization's security - across cloud and on-premises environments. With this release, you can view the AWS firewalls and manage policies associated with your AWS firewalls directly from SmartConsole, with no need to switch between tools or consoles.
Key capabilities:
- Policy visibility - Inspect policies tied to AWS firewalls from one centralized location.

- Cross-account policy sharing - Share and enforce consistent policies across multiple AWS accounts.

- Gateway policy sharing - Extend policy sharing to Check Point Gateways, unifying cloud and on-premises enforcement.

This reduces operational overhead, closes visibility gaps, and ensures consistent security enforcement across your entire environment.
PRJ-69898,
PRJ-69899,
PMTR-128616
Security Management NEW: Added integration between the Security Management Server and Nozomi to extend Check Point OT capabilities. This integration enables the import of Nozomi Assets and Tags into SmartConsole and their direct use in the Access Control Policy. It improves policy visibility and operational awareness, with enforcement performed on the Security Gateway without requiring an additional policy installation.
- Requires R82.10 SmartConsole Build 426 or higher.
PRJ-69893,
PRJ-69894,
PMTR-129080
Security Management NEW: Added integration between the Security Management Server and Akamai Guardicore to extend Check Point micro-segmentation capabilities. This integration enables importing Akamai Guardicore Assets and Labels into SmartConsole and using them directly in the Access Control Policy. It improves policy visibility and operational awareness, with enforcement performed on the Security Gateway without requiring an additional policy installation.
- Requires R82.10 SmartConsole Build 426 or higher.
PRJ-69891,
PRJ-69892
PMTR-129079
Security Management NEW: ServiceNow CMDB integration allows treat ServiceNow as the single source of truth for network objects. Configuration Items and Tags import directly into SmartConsole for use in the Access Control Policy. This removes duplicate object maintenance, improves policy visibility, and enforces on the Security Gateway without an additional policy installation.
- Requires R82.10 SmartConsole Build 426 or higher.
PRJ-69019,
PMTR-127536
Security Management NEW: CloudGuard Controller now supports the Claroty Continuous Threat Detection (CTD) Data Center. Refer to the R82.10 CloudGuard Controller Administration Guide.
PRJ-69471,
PMTR-128479
Security Management NEW: Permission profiles for Access layers via the Management API are now supported. A new field, "additional-permission-profiles", has been added to the existing "add/set access-layer" Management API.
For example: mgmt_cli set access-layer name "Network" additional-permission-profiles.1 "custom_profile"
PRJ-67597 Cloud Firewall NEW: Central License Utility now sends events to Events & AIOps upon license distribution failures and recoveries.
Events are reported for both full distribution runs and single distribution, enabling proactive monitoring and alerting through AIOps. Refer to the Cloud Firewall Central License Tool Administration Guide.
PRJ-67945,
HEC-2296
Scalable Platforms NEW: The Virtualization Screen is added to VS0 Insights, displaying Virtual Systems statistics, including Virtual Systems problem detection, alongside general environment metrics and the Resource Search tool.
- Resource Search Tool: Provides a cross Virtual Systems interface search capability.

- Problem Detection: Introduces Virtual System problem indicators in the Status and Problem Categories columns, showing problem classifications. Users can select a Virtual System row in the Virtual Systems table to re-launch Insights in the Virtual System context and investigate issues in AI Detector.
PRJ-67945,
HEC-2296
Scalable Platforms NEW: Added support for integrating clean-install machines running a higher version into an existing ElasticXL environment.
PRJ-69425,
PRHF-45847
Scalable Platforms NEW: Added a configuration option for Maestro Orchestrator to forward Spanning Tree Protocol (STP) BPDUs to Maestro Security Group Members. Refer to sk185110.
Take 36 - Improvements and Resolved Issues
PRJ-65590,
PRHF-42963
Security Management UPDATE: In environments with thousands of Domain objects or External User Groups, the policy installation duration has been significantly improved.
PRJ-70483,
PMTR-129956
Security Management UPDATE: Resolved CVE-2026-62144 - Management Authentication Bypass and Privilege Escalation. Refer to sk185152.
PRJ-70932,
PMTR-130686
Security Management UPDATE: Resolved CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token. Refer to sk185169.
PRJ-68722,
PRJ-69357,
PMTR-127252
Gaia OS UPDATE: Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia). Refer to sk184928.
PRJ-69475,
PMTR-128555
Gaia OS UPDATE:
- Resolved CVE-2026-25749 - Security scanner flags Vim package on Gaia OS as vulnerable.

- Resolved CVE-2026-28417, CVE-2026-28421, CVE-2026-33412, and CVE-2023-4752.
PRJ-70597,
PMTR-129991
Gaia OS UPDATE: Resolved CVE-2026-62145 - Local privilege escalation in Gaia Portal. Refer to sk185153.
- - This Jumbo Hotfix Accumulator Take provides additional Management and Gateway hardening fixes, including VPN Site to Site and Remote Access.
PRJ-68503,
PMTR-127051
Logging UPDATE: In the Logs view, search performance is improved when the search term includes a Cluster.
PRJ-69419,
ODU-4204,
PRJ-70008,
ODU-4253,
PRJ-70563,
ODU-4316
Automatic Updates - Web SmartConsole UPDATE: New features and improvements are released in Take 171, Take 173 and Take 176 of Web SmartConsole. Refer to sk170314.
PRJ-69646,
ODU-4086,
PRJ-70600,
ODU-4337
Automatic Updates - Log Exporter UPDATE: Added Take 65 and Take 70 of Log Exporter Auto Update Deployment. Refer to sk182866.
PRJ-67794,
PRHF-44615
Security Gateway UPDATE: Optimized Mobile Access policy installation to improve performance in environments with a large Mobile Access Rule Base (more than 500 rules).
PRJ-67086,
SMBGWY-19644
Security Gateway UPDATE: The Security Gateway now complies with RFC-4291 by blocking the forwarding of IPv6 packets that contain link-local addresses (FE80::/10) in the source or destination fields.
PRJ-67360,
PMTR-125446
Mobile Access UPDATE: Resolved the Mobile Access Portal XSS vulnerability in the PHP file.
PRJ-67026,
PMTR-124210
Gaia OS UPDATE: Added validation for bridge ID during the bridge creation on VSNext in Gaia Portal.
PRJ-69950,
PMTR-129118
Gaia OS UPDATE: OpenSSL has been upgraded from version 3.5.5 to version 3.5.7 to address identified CVEs.
PRJ-68784,
PMTR-127386
Gaia OS UPDATE: Gaia API updates are now included in the Jumbo Hotfix Accumulator (previously were installed by AutoUpdater). See sk143612.
PRJ-69643,
ODU-4190
Gaia OS UPDATE: Added Take 89 and Take 90 of the AutoUpdater Utility. Refer to sk165653.
PRJ-67529,
PMTR-125744
Scalable Platforms UPDATE: Old SVMAC feature is now deprecated ("toggle_same_vmac" parameter is blocked).
Only use the new SVMAC feature ("toggle_same_vmac_os").
Refer to sk165674.
PRJ-64983,
PMTR-121665
Scalable Platforms UPDATE: Improved warning message, user confirmation prompt, and audit logging when running the " set fcd revert" command in gClish on a Scalable Platform Security Group.
PRJ-64006,
PMTR-119902
SecureXL UPDATE: Improved Debug Filtering for specific flows in SecureXL User Space Mode (UPPAK) debug messages.
PRJ-69640,
ODU-4225,
PRJ-70661,
ODU-4330
Automatic Updates - Policy Insights UPDATE: Added Take 94 and Take 96 of Policy Insights Release Updates. Refer to sk183421.
PRJ-69574,
ODU-4218,
PRJ-70683,
ODU-4351
Automatic Updates - HCP UPDATE: Added Take 93 and Take 94 of HealthCheck Point (HCP) Release. Refer to sk171436.
PRJ-69585,
PRJ-70141,
ODU-4169
Automatic Updates - CPView UPDATE: Added Take 57 and Take 59 of CPquid (QUID) Release Updates. Refer to sk181458.
PRJ-66978,
PRHF-44315
Security Management The FWM process may exit because of memory exhaustion and generate large core files (up to 4GB).
PRJ-64194,
PRHF-41943
Security Management In some scenarios, the " show-tasks" Management API command displays incorrect results when the " from-date" and " to-date" parameters are used. Refer to sk184072.
PRJ-67415,
PMTR-125556
Security Management The " show-global-properties" Management API command fails when there is a database inconsistency in the " keep-hit-count-data-up-to" field.
PRJ-66226,
PRHF-43824
Security Management Packet mode search does not return results for Inline Layer rules in SmartConsole and Management API. Refer to sk184638.
PRJ-67667,
PRHF-44882
Security Management The Management API v2 command "show-vpn-communities-star" with details-level full may fail with an "Internal error" message when a Virtual System Cluster member is configured as a satellite in a VPN Star community.
PRJ-65779,
PRHF-43423
Security Management In rare scenarios, some Management API commands may fail with " Management server failed to execute command" error.
PRJ-64046,
PRHF-42109
Security Management In some scenarios, running the " api stats" command with the " -calc_avg_duration" flag on the Security Management Server fails with the " IndexError: list index out of range" error. Refer to sk184144.
PRJ-64523,
PRHF-42149
Security Management In some scenarios, opening a Security Gateway object in SmartConsole fails with " Smart Dashboard component failed to connect to a server".
PRJ-65009,
PRHF-42618
Security Management In some scenarios, the submit-time field in emails generated by SmartTask displays an incorrect value.
PRJ-66059,
PRHF-43447
Security Management Using the " get Interfaces without topology" option on a Security Gateway may remove user-defined interface comments and color settings. Refer to sk180516.
PRJ-66563,
PMTR-123578
Security Management Cross-domain sharing might be incorrectly configured on the PDP Security Gateway when Identity Broker is the sole enabled identity source.
PRJ-67197,
PRHF-44188
Security Management In some scenarios, Multi-Domain Security Management HA synchronization may fail after AI Copilot permissions are updated, until a manual synchronization is performed. Refer to sk185124.
PRJ-67182,
PRHF-41612
Security Management Policy installation may fail with " failed to get tls rulebases from policy id".
PRJ-66162,
PRHF-41727
Security Management The Security Management Server upgrade may fail during the export phase with the " Object not found - Entities can not be found" message.
PRJ-69132,
PMTR-127809
Security Management In some scenarios, the FWM process on the Security Management Server may unexpectedly exit when performing the "Fetch branches" action in the LDAP Account Unit properties window of SmartConsole.
PRJ-67181,
PMTR-124681
Security Management When adding a Shared Secret key to a VPN Community object, the operation may fail with the " Update operation failed" error.
PRJ-66640,
PRHF-44086
Security Management Configuration sharing from a Management Server to the Check Point Portal may fail with a "Did not get reply from Docker" error.
PRJ-66947,
PRHF-44222
Security Management SmartWorkflow may incorrectly show zero changes for a session, preventing the change report from being displayed. Refer to sk184779.
PRJ-64102,
PRHF-42074,
PRJ-66380,
PRHF-43925
Security Management In rare scenarios, the Security Management Server fails to start after performing the "Revert to Revision" operation.
PRJ-64268,
PRHF-36295
Security Management In rare scenarios, the FWM process on the Security Management Server may unexpectedly exit, creating a core dump file.
PRJ-64812,
PRHF-41979
Security Management Policy installation may fail when an inline layer is used more than once in the same policy and this error is displayed " Policy installation had failed due to an internal error. If the problem persists please contact Check Point support".
PRJ-67608,
PRHF-44664
Security Management SmartConsole may display a generic error "Failed to save object <object_name>. Server error is: An internal error has occurred. (Code: 0x8003001D, Could not access file for write operation)" when editing interfaces on Spark Firewall.
PRJ-66180,
PRHF-43671
Security Management In some scenarios, accumulated open sessions can cause the Security Management Server to become unavailable.
PRJ-66720,
BSM-597
Security Management In some scenarios, on a Spark Firewall cluster, adding a cluster interface to an existing cluster member network fails with the error message "Failed to save object".
PRJ-63913,
PRHF-41983
Security Management In some scenarios, fwmtrace.log* files consume a significant amount of disk space.
PRJ-65208,
PRHF-42646
Security Management API login to the Security Management Server may fail with a "Null Pointer Exception" error when the session name, comment, or description is specified.
PRJ-64526,
PRHF-42412
Security Management Opening objects in SmartConsole may fail with the error "SmartDashboard component failed to connect to server".
PRJ-66975,
PRHF-44216
Security Management A SmartTask configured to send an email after policy installation may fail when the target gateway is a VSX object.
PRJ-66326,
PRHF-43883
Security Management In some scenarios, an API key may become invalid after editing an administrator account.
PRJ-66869,
PRHF-44037
Security Management SmartConsole may display the error "the user already exists" when attempting to create a new administrator with the same name as a previously deleted SAML (Identity Provider) administrator.
PRJ-68294,
PRHF-45027
Security Management SmartTasks may fail to send email notifications with a "send mail to failed" error when the Cc field is populated.
PRJ-69281,
PRHF-45720
Security Management Policy installation may fail in a Multi-Domain Security Management Server environment when the Global Policy contains a shared inline layer.
PRJ-68534,
PRHF-45122
Security Management In rare scenarios, the FWM process on the Multi-Domain Security Management Server may not stop after running mdsstop.
PRJ-67192,
PMTR-124870
Security Management In some scenarios, after the FWM process crashes and generates a core dump, High Availability synchronization may fail, and the Security Management Servers may appear as disconnected.
PRJ-66699,
PRHF-38656
Security Management In some scenarios, task notifications are not triggered for the Automatic Revisions Purge process, and the task status is not displayed correctly in SmartConsole.
PRJ-68403,
PRHF-39002
CPView In the VLAN interface, CPView shows the speed of the parent.
PRJ-67373,
PRHF-44242
CPView CPU information may not be displayed in the CPU tab in CPView for an environment with Virtual Systems.
PRJ-68996,
PMTR-127578
AIOps A temporary fix related to the QUID identity database (used by CPDiag and AIOps) caused issues in Maestro environments and led to degradation and occasional agent resets in AIOps, as it relies on this component as its IdentityDB. The fix has therefore been removed.
PRJ-64314,
PMTR-120045
Internal CA Internal CA now automatically recovers from transient database lock errors without requiring a process restart.
PRJ-66039,
PRHF-30761
Logging The logs maintenance is running perpetually and is not clearing disk space when the CPPCAP (Check Point Traffic Capture Tool) is enabled.
PRJ-66323,
PMTR-123346
Logging In some scenarios, the LOG_INDEXER process unexpectedly exits and generates a core dump.
PRJ-66905,
PRHF-44038
Logging High load on the LOG_INDEXER process may impact system performance.
PRJ-68697,
PRHF-36152
Logging SmartEvent processes may unexpectedly exit in environments containing over 1 million network objects.
PRJ-66035,
PRHF-39816
Logging In a Management High Availability environment, configuring threshold settings in SmartView Monitor, fails with the " Couldn't load threshold settings for the selected gateway" error.
PRJ-68785,
PRHF-41211
Logging In some scenarios, the SmartLog Server process may unexpectedly exit and generate a core dump.
PRJ-64140,
PRHF-41934
Security Gateway In a rare scenario, when handling CIFS traffic in the accelerated pipelined path, the PPE and FWK processes may exit. Refer to sk184284.
PRJ-65665,
PRHF-43354
Security Gateway There may be high CPU usage by the CMID process when the ICAP Client is enabled on Security Gateway. Refer to sk184524.
PRJ-66433,
PRHF-43910
Security Gateway The memory usage may increase over time when using the Mirror and Decrypt feature.
PRJ-68595,
PRHF-45113
Security Gateway In a rare scenario, the FWK process crashes when the Mirror and Decrypt feature handles large MTU frames.
PRJ-65933,
SMBGWY-18437
Security Gateway In rare HTTP/S inspection flows, the Security Gateway may crash if there is a parsing error.
PRJ-67081,
PRHF-44360
Security Gateway On ClusterXL and in Maestro Security Groups, after performing a rolling upgrade that includes a change in the CoreXL instance count, newly created firewall instances may remain in local-sync-only mode. As a result, these instances do not receive state updates from their peers, leading to intermittent connection failures and " First packet isn't SYN" drops. Refer to sk184786.
PRJ-66490,
PRHF-43994
Security Gateway In a rare HTTP/2 traffic scenario, a valid connection may fail.
PRJ-65979,
PRHF-43452
Security Gateway After an upgrade, the "show configuration" command output for MDPS may be missing bond configuration.
PRJ-67747,
PMTR-125710
Security Gateway In a rare scenario, the FWD daemon may restart because of the Application Control Dynamic URL List version file.
PRJ-66622,
PRHF-44062
Security Gateway In rare cases, the FWK process may restart unexpectedly while the Security Gateway is processing a URL Filtering categorization response and a policy installation is running simultaneously.
PRJ-65230,
PRHF-42920
Security Gateway Active Streaming Layer connections become stuck, resulting in increased memory consumption over time on the Security Gateway.
PRJ-68861,
PMTR-127344
Security Gateway Jumbo Hotfix Accumulator installation on Security Gateways with MDPS enabled may fail with a verification error "Installation is not allowed". Refer to sk184950.
PRJ-66421,
PRHF-43935
Security Gateway In a rare scenario, a memory leak may occur due to a race condition between policy installation and Application Control/IPS signature updates, and persists until the next policy installation.
PRJ-65630,
PRHF-40610
Security Gateway The RAD daemon may unexpectedly exit when customizing RAD internal parameters (" max_flows" and " queu_max_capacity"). Refer to sk182136.
PRJ-65523,
PRHF-42914
Security Gateway RSH connections fail when Destination NAT is configured for the RSH server. Refer to sk184768.
PRJ-65995,
PRHF-41793
Security Gateway FTP transfers of files smaller than 1KB fail and result in empty files on the destination server. Refer to sk184200.
PRJ-64057,
PRHF-42098
Security Gateway In rare scenarios, the FWK process may unexpectedly restart when an HTTP/2 connection containing specific stream characteristics is released.
PRJ-68446,
PRHF-40579
Security Gateway FTP traffic does not pass through Security Gateway when using the FTP Extended Passive Mode. Refer to sk183853.
PRJ-67157,
PRHF-44365
Security Gateway In some scenarios related to Check Point Active Streaming (CPAS), the Security Gateway may unexpectedly crash.
PRJ-66910,
PRHF-30817
Security Gateway There may be log entries related to the drop optimization feature, although the dropped traffic matches a non-logging rule.
PRJ-64757,
PRHF-38664
Security Gateway The ICAP client does not work correctly, impacts the allowed number of characters for the ":service" field in the $FWDIR/conf/icap_client_blade_configuration.C ICAP configuration file.
PRJ-66749,
PRHF-44002
Security Gateway When ISP Redundancy is enabled, and the administrator changes the priority, the primary ISP may not be updated in the Security Gateway (the route is updated, but the Security Gateway continues to consider the old ISP as the primary/standby). Refer to sk184923.
PRJ-64915,
PRA-4998
Security Gateway When ESP traffic is present in the environment, and the fwmultik_dispatcher_in_tap_mode parameter is enabled, the Security Gateway may drop ESP traffic.
PRJ-65816,
PRHF-42940
Security Gateway Some service ports may be missing in some instances, resulting in unexpected behavior for some services.
PRJ-64000,
PRHF-42068
Security Gateway Suspicious Activity Monitoring (SAM) rules may not function properly on a standalone device. Refer to sk184330.
PRJ-64340,
PRA-5002
Security Gateway In a rare scenario, the FWD process may crash during Policy Installation because of memory corruption related to licensing.
PRJ-64847,
PMTR-120708
Security Gateway HTTPS inspection causes connections to fail when using a custom service with a non-standard HTTPS port (for example, TCP/9400), and the custom service object is configured with "Protocol: None". Refer to sk184294.
PRJ-67492,
PRHF-44637
Security Gateway In some scenarios, SmartConsole RSA SecurID administrator login fails, and the FWM process unexpectedly exits. Refer to sk184844.
PRJ-67648,
PRHF-44347
Security Gateway In some scenarios, internal memory mishandling in global connections may cause unexpected behavior or connectivity issues.
PRJ-67506,
PMTR-125680
Threat Prevention In some scenarios, enforcement of an Indicator of Compromise (IoC) feed containing mail observables may fail if the feed file includes a single malformed entry because of a parsing error.
PRJ-69203,
PMTR-124700
Threat Prevention In some scenarios, Zero Phishing becomes inactive during traffic inspection when Anti-Virus performs a Deep Scan on HTML or JavaScript files.
PRJ-69365,
PRHF-37274
Threat Prevention SSH connections may fail after enabling SSH Deep Packet Inspection (DPI).
PRJ-65308,
PRHF-42982
Threat Prevention In rare scenarios, the Anti-Virus fails to inspect HTTP file downloads.
PRJ-68773,
PMTR-127315
Threat Prevention IoC feed observables may continue to be enforced even after Anti-Virus and Anti-Bot are disabled.
PRJ-68163,
PMTR-126680
Identity Awareness Scaled PDP recovery was improved when specific scaled daemons crashed while Multi-Instance PDP was enabled.
PRJ-65879,
PRHF-36392
Identity Awareness The Microsoft Graph API access token does not renew if an authorization error occurs while working in on-demand fetch mode.
PRJ-70633,
PMTR-130209
Identity Awareness After upgrading an Identity Broker subscriber from R82 or earlier versions to R82.10, broker connections may fail.
PRJ-64787,
PRHF-42302
Identity Awareness In some scenarios, the PDPD process stops responding and users cannot authenticate through the Identity Awareness. Refer to sk184407.
PRJ-69143,
PMTR-127848
Identity Awareness The default role in Aruba Networks ClearPass CPPM does not match the identity sessions.
PRJ-64623,
PRHF-38576
Identity Awareness SNMP queries to the Security Gateway may return unexpected results: specific IP addresses or Identity Collector objects may continue to appear in SNMP outputs even after being removed from the topology configuration. Additionally, polling OIDs such as 1.3.6.1.4.1.2620.1.38.55 or 1.3.6.1.4.1.2620.1.38.53 may result in the message " No Such Instance currently exists at this OID".
PRJ-67890,
PMTR-125897
Identity Awareness In environments with PDP multi-process enabled, the pdpDispatchd daemon may unexpectedly exit when the Active Directory Query identity source is configured.
PRJ-67951,
PMTR-126644
SSL Inspection TLS Inspection and HSM statistics are not available through SNMP requests.
PRJ-65580,
AAD-8717
SSL Inspection A memory leak may occur in the parsers_is TLS module when HTTPS Inspection is enabled and used to inspect non-standard TLS traffic transmitted over a proxy.
PRJ-66474,
PMTR-123521
SSL Inspection When HTTPS Inspection is enabled, the Security Gateway uses the global (default) outbound CA certificate, even though an outbound CA override is configured in SmartConsole. Refer to sk184880.
PRJ-67376,
PMTR-125272
IPS In some scenarios, the Custom Threat Prevention policy fails to enforce IPS protection overrides on rules configured with a network group in the "Install On" column.
PRJ-66562,
PRHF-43834
Application Control When using custom applications and SD-WAN, HTTPS traffic may be blocked with " Reason: Application Control - Internal system error" in SmartConsole log.
PRJ-67580,
PRHF-44375
URL Filtering In a rare scenario, the RAD request may drop when hostname header includes unsupported characters.
PRJ-65134,
PRHF-42745
URL Filtering An HTTPS Inspection rule that contains a custom application whose name includes spaces or certain unsupported characters does not match during policy enforcement. Refer to sk184773.
PRJ-64971,
PMTR-121545
URL Filtering The Resource Advisor module continues to perform categorization even when a match is found in the override category.
PRJ-65025,
PRHF-42722
Anti-Virus In rare scenarios, the RAD process may exit generating a core dump.
PRJ-66022,
PMTR-123156
ClusterXL In a ClusterXL Load Sharing Unicast configuration, the Pivot member intermittently fails to forward packets to the relevant non-Pivot cluster members. This results in packet drops, related to MAC address handling.
PRJ-64061,
PRHF-42044
ClusterXL When processing VPN traffic in a ClusterXL environment with " sync-to-all" enabled, the absence of sequence number updates from the active site can cause the Fast Acceleration (FnA) mechanism to become unresponsive. As a result, affected connections may be dropped, and such log entry is generated " dropped by fw_conn_inspect Reason: Frozen connection".
PRJ-69330,
PRJ-69885
SecureXL In some scenarios, the VSX Security Gateway passes traffic without performing proper NAT from a Virtual Router or Switch's external interface when SecureXL User Mode is enabled.
PRJ-68528,
PMTR-125648
SecureXL When both Quality of Service (QoS) and VPN features are enabled, memory corruption may occur in the mbuf. This can lead to an exit of the USIM process during the handling of QoS flows.
PRJ-67819,
PMTR-126262
SecureXL After rebooting the Security Gateway, the Allow List entry is present when viewing the list, but it is not enforced. The Deny List takes precedence, and traffic from the IP is blocked, even though it should be allowed according to the configuration.
PRJ-69944,
PMTR-127433
SecureXL In some scenarios, VPN packets are dropped in User Mode (UPPAK) during encryption when QoS is active.
PRJ-70341,
PRHF-46357
SecureXL In some scenarios, VLAN tags are stripped and MAC addresses become malformed after traffic passes through the bridge. Refer to sk185101.
PRJ-65887,
PRHF-43515
SecureXL PPTP/GRE traffic fails when Hide NAT is used and SecureXL runs in UPPAK mode and the " fw_pptp_enforce_protocol" parameter is enabled. Refer to sk184641.
PRJ-67411,
PMTR-125154
SecureXL On Check Point 3000 Series Appliances, the Multi-Queue Management utility mq_mng displays incorrect interface statistics when run in verbose mode for integrated switch ports.
PRJ-66065,
PMTR-123155
SecureXL The USIM process may exit with a core dump during modular configuration.
PRJ-66068,
PMTR-121465
SecureXL In a Cloud Firewall environment with Kernel Performance Pack (KPPAK) enabled by default, when modifying the TX queue size parameter for supported network interfaces to 2048 (2K) or 4096 (4K), reverting the setting back to the default value of 1024 (1K) is not possible.
The issue is observed with these synthetic network drivers: virtio (used in GCP and KVM environments), vmxnet3 (used in VMware ESXi), and ena (used in AWS).
PRJ-64175,
PRHF-42253
SecureXL The " arping" command on the Security Gateway returns this output " Sent 4 probes Received 0 response" in SecureXL User Mode (UPPAK). Refer to sk184292.
PRJ-65899,
PMTR-123034
SecureXL Error messages are generated when running the " fwaccel dos statistics get" command, cluttering the usim_x86.elg log file.
PRJ-66213,
PMTR-123304
SecureXL A reference count issue in the UPPAK module can cause a USIM core dump, particularly on busy systems with long uptime.
PRJ-68731,
PMTR-127310,
PRJ-69057,
PMTR-127714
Routing On VSNext Clusters, during startup, the ROUTED daemon does not install cluster Virtual IPs (VIPs) on certain non-VS0 Virtual System (VS) routing instances. As a result, Dynamic Routing protocols (such as OSPF, BGP) fail to operate correctly on the affected instances.
PRJ-69595,
PMTR-128407
Routing In the VSX environment, the BGP Routed Critical Device (PNOTE) never clears after rebooting both cluster members simultaneously or during an upgrade.
PRJ-66230,
PRHF-43674
Routing The ROUTED daemon may exit when running the " show bgp paths" command.
PRJ-67019,
PRHF-44174
Routing The ROUTED daemon may exit with a pnote on Security Group Members after the Orchestrator daemon (ORCHD) stops. Refer to sk184771.
PRJ-66210,
PRHF-37998
Gaia OS When the nstat utility (in the iproute2 package) encounters a corrupted state file (for example, if /tmp/.nstat.u0 contains invalid data), it aborts with a core dump instead of providing an error message.
PRJ-67604,
PRHF-44603
Gaia OS In some scenarios, SNMP monitoring may incorrectly report 100% CPU usage.
PRJ-65650,
PRHF-43017
Gaia OS Excessive log entries for RADIUS users logging into Gaia Portal. Refer to sk184534.
PRJ-66885,
PRHF-43932
Gaia OS In rare scenarios, the CORE_UPLOADER process on Security Gateways may unexpectedly generate a core dump when the number of detected CPU cores exceeds a specific threshold.
PRJ-64558,
PRHF-42434
Gaia OS Unable to enter Virtual System with " virtual-system-access all" configured. Refer to sk184282.
PRJ-68162,
PMTR-123017
Gaia OS In a rare scenario, after several reboots, the Security Gateway restarts with an empty
/etc/udev/rules.d/ rules file. As a result, the interface renaming configuration is lost, and network interfaces revert to default names, potentially disrupting network connectivity and management.
PRJ-67503,
PRHF-44333
Gaia OS After an upgrade, in some scenarios, two-factor authentication (2FA) may not be enforced for SSH access. This results in users are able to authenticate via SSH without the required 2FA.
PRJ-68854,
PRHF-45491
Gaia OS In some scenarios, VPN throughput slowness occurs on Check Point Firewall 3900 Appliances.
PRJ-65948,
PRHF-43616
Gaia OS Remote and local backup operations fail after installation of Jumbo Hotfix Accumulator with the " Cannot complete the backup process: not enough space in /var/log/CPbackup/backups" error. Refer to sk183767.
PRJ-67026,
PMTR-124210
Gaia OS In Gaia Portal, for VSNext, the Bridge Group field displays the validation error "The minimum value for this field is 1001," but does not enforce it, and it is possible to submit and create bridge object IDs with values below the minimum threshold. The fix adds validation for the bridge ID during bridge creation in VSNext.
PRJ-65927,
PRHF-43620
Gaia OS Clish may restart unexpectedly when running the set snapshot-onetime command.
PRJ-69113,
PRHF-44815
Gaia OS After disabling Two-factor authentication (2FA) in Gaia OS, the user still requires a 2FA code on login attempts.
PRJ-68251,
PMTR-126527
Gaia OS For IDNS-Resolver, when the DNS server returns "TC=1", and communication should be moved to TCP instead of UDP, TCP communication does not block DNS requests.
PRJ-69004,
PRHF-45517
Gaia OS In Gaia Portal, bond member interfaces can be edited when they should be disabled.
PRJ-65922,
PMTR-122737
Gaia OS After restoring the system backup, the restored date and time are displayed incorrectly.
PRJ-68683,
PRHF-44285
Gaia OS The Bash Shell Logging procedure is now working in R82.10 and higher versions. Refer to sk99134.
PRJ-68692,
PRHF-45133
Gaia OS In some scenarios, a Security Gateway crashes because of a memory write overflow in the I/O driver.
PRJ-70250,
PMTR-129404
Mobile Access After hardening non-RFC-compliant HTTP requests, some Mobile VPN connections fail. Since multiple clients send bare LF requests (a specific type of non-RFC-compliant traffic), bare LF errors are now disabled by default. This behavior can be enabled using the kernel parameter "ws_block_bare_lf".
PRJ-68991,
PMTR-116331
VPN Added the ability to import additional .p12 certificate types as inbound and outbound certificates.
PRJ-67986,
PRHF-45155
VPN Automatic Security Gateway certificate enrollment using CMP with an external OPSEC PKI CA (for example, EJBCA) fails with "Internal Error" status in SmartConsole.
PRJ-65678,
PRHF-41115
VPN Added CA Certificate matching improvements.
PRJ-70031,
PMTR-129280
VPN Improved certificate validation during IKEv2 VPN negotiations to ensure VPN connections are established only after successful certificate-based authentication.
PRJ-69115,
PMTR-126293
VPN When IKEv2 is configured in a Remote Access community, Remote Access clients are incorrectly classified as DAIP (Dynamic Address IP) gateways during IKEv2 negotiation. This causes authentication with machine certificates to fail, preventing successful VPN client connections.
PRJ-65985,
PMTR-122751
VPN Remote Access IKEv2 VPN authorization may fail for LDAP Active Directory users whose Common Name (CN) in their certificate is email-based (for example, user@domain.com). When such users authenticate using an External User Certificate, they are unable to pass traffic to the Encryption Domain, resulting in dropped connections.
PRJ-65327,
PRHF-42932
VPN When using Capsule VPN or Endpoint Security VPN (Connect) clients in IPsec mode with IKED enabled, users can successfully authenticate and establish a VPN tunnel. However, group information received from the RADIUS server is not passed to the IKED process. As a result, security policies and access roles that rely on RADIUS group membership do not apply, and users are unable to access internal resources through the VPN.
PRJ-70096,
PRHF-45664
VPN In ElasticXL environments, a stale NAT-T port in the cluster sync overwrites the correct port.
PRJ-69268,
PRHF-45001
VPN In some scenarios, the VPN tunnel flaps every 40 seconds when the in-kernel tunnel test is enabled.
PRJ-64807,
PRHF-42566
VPN Traffic passing through a route-based VPN tunnel may cause high CPU usage if the traffic is fragmented.
PRJ-69527,
PMTR-128338
VPN Improved address validation in the VPN Remote Access proxy to correctly restrict outbound connections to internal and link-local destinations.
PRJ-67353,
PMTR-125245
VPN In VPN Site-to-Site environments, a memory leak in VPN-related processes may occur after a VPN driver restart, or during prolonged system runtime.
PRJ-69428,
PMTR-128278
VPN Improved input validation in the VPN L2TP PPP packet parser to handle malformed configuration options correctly.
PRJ-64322,
PRHF-41687
VPN CRL files may not be synchronized as expected in Management High Availability and Multi-Domain Security Management environments.
PRJ-65322,
PRHF-42883
VPN The VPND or IKED daemon may crash during IKEv2 negotiation.
PRJ-66771,
AAD-9554
VPN VPN traffic outage may occur in ClusterXL environments with IKEv2 after a Cluster failover.
PRJ-66468,
AAD-9083
VPN In ClusterXL environments, a VPN traffic outage of up to 60 seconds may occur after an ungraceful cluster failover.
PRJ-66466,
AAD-8776
VPN VPN traffic outage may occur in ClusterXL environments with SD-WAN Overlay or Enhanced Link Selection after a Cluster failover. The new Active cluster member fails to properly handle VPN traffic because of synchronization or MAC address handling problems.
PRJ-67308,
PMTR-124732
VPN In a MaaS (Management as a Service) environment, VPN clients (Windows and macOS) enrolling for new certificates may encounter the " failed to enroll new certificate" error.
PRJ-65668,
PMTR-119883
VPN When Hub Mode is not enabled, traffic destined for dynamic objects included in the Remote Access VPN Split Tunneling Inclusion group may be incorrectly dropped. As a result, remote users may be unable to access resources defined by these dynamic objects, even though they are specified for inclusion in the split tunnel.
PRJ-66430,
PMTR-123715
VPN IKE negotiation fails during Phase 1 when AES-GCM encryption algorithms are used, with third-party devices as the VPN peer. This affects both Site-to-Site and Remote Access VPN scenarios.
PRJ-69367,
PRJ-69283
VSNext In some scenarios, on Maestro VSNext setups, a bridge is shown in a down state in the WebUI interfaces table immediately after creation in the Virtual System (VS) context.
PRJ-67743,
PMTR-124791
VSNext In some scenarios, on VSNext environments, Backup and Restore fails to restore a backup, causing all Virtual Systems to be in a DOWN state.
PRJ-68230,
PMTR-126764
VSX After deleting several Virtual Systems, stale wrpj interfaces remain attached to Virtual Switches. SmartConsole shows these orphaned interfaces with error text " Virtual System with the ID X does not exist".
PRJ-67626,
PRHF-44844
VSX When using VSX SmartProvisioning on Maestro, the operation fails if the VSX Gateway name includes the substring "wrp0".
PRJ-69524,
HEC-1792
VSX Added new SNMP OIDs to enable monitoring of physical resources per Virtual System (VS) via VS0.
PRJ-67939,
PRHF-44890
QoS QoS Policy installation fails when using the DiffServ class in the QoS Policy.
PRJ-67684,
PRHF-44765
SD-WAN In a rare scenario, the FWK process may crash when handing SD-WAN traffic.
PRJ-65445,
PMTR-107842
SD-WAN VPN traffic outage may occur in SD-WAN overlay environments.
PRJ-65610,
PMTR-107052
SD-WAN SD-WAN overlay traffic debugging is improved, enhancing visibility and troubleshooting capabilities.
PRJ-64474,
PMTR-120815
SD-WAN In some scenarios, SD-WAN ISP link status may fluctuate between UP and DOWN states. Reduced SD-WAN ARP probing default sensitivity to packet drops.
PRJ-66778,
PRHF-43782
SD-WAN In some scenarios, enabling SD-WAN Symmetric Return may lead to elevated CPU utilization on Secure Network Distributor (SND) cores.
PRJ-68333,
AAD-9724
SD-WAN On the Scalable Platform Cluster, LS fragmented packets may be dropped on the receiving member with an error "handle_sim_inbound_frag: error (2): frag freed, ret_val (11): FRAG_ERROR_MSG_DUPLICATE in fragment" on a loaded environment with a lot of corrected fragmented packets.
This may also occur with Cluster HA; however, correcting packets is negligible in such environments.
PRJ-66472,
AAD-9375
SD-WAN VPN traffic outage may occur in ClusterXL environments after a Cluster failover.
PRJ-66470,
AAD-9373
SD-WAN VPN traffic outage may occur in ClusterXL environments after a Cluster failover.
PRJ-68797,
PMTR-127298
Cloud Firewall Deleting a license pool while Cloud Firewall Gateways are still associated with it causes all licensing operations (add, distribute, remove) to continuously fail until the orphaned reference is manually cleared from the database.
The fix allows licensing operations to complete normally without administrator intervention.
PRJ-69052,
PMTR-127703
Cloud Firewall When a Cloud license's support contract expires, the system now keeps all gateways licensed and alerts the administrator with remediation steps, instead of silently removing their licenses.
PRJ-67515,
PMTR-125729
Cloud Firewall Moving Cloud licenses from one pool to another triggers license alignment: If adding a new license to CK fails, license removal will not be initiated on the Security Gateways.
PRJ-65793,
PRA-5195
Scalable Platforms The unique IP address assigned to the standby site may not function correctly during a VSNext deployment.
PRJ-67567,
PMTR-127675
Scalable Platforms When deleting a bond in an ElasticXL environment, site failover may occur.
PRJ-68832,
PMTR-127137
Scalable Platforms In some scenarios, a 3950 appliance in an ElasticXL cluster fails to bring the Sync interface up because of the link-speed binding.
PRJ-67167,
PRHF-43859
Scalable Platforms - When a large number of bond interfaces are configured, the synchronization of link states may fail.

- In rare scenarios, a cluster member may become stuck in the "active (sync)" state. When this occurs, the affected member does not handle network traffic as expected.

- There may be inconsistencies in the reported link state across Security Group Members (SGMs), as observed with the " asg stat -v" command.
PRJ-65702,
PMTR-122627
Scalable Platforms " TCP packet out of state" or " connection dropped due to state mismatch" messages may be seen in SmartLog or SmartView Tracker. These drops specifically occur on the sync interface, which is used for internal communication and synchronization between Security Group members.
PRJ-70255,
PMTR-129110
Scalable Platforms Deleting a bond may trigger a site failover because LACP negotiation resets the IPs of slave interfaces, leading to an IAC pnote and failover.
PRJ-68809,
PMTR-126879
Scalable Platforms When a Security Group member transitions from a down state to an active state, the synchronization process with other members in the Security Group may not complete before the recovered member becomes active. This can result in traffic drops because of incomplete state synchronization.
PRJ-67822,
PMTR-125843
Scalable Platforms Virtual Systems are sometimes stuck with a during_boot pnote if multiple Virtual Systems are created simultaneously. As a result, Secure Internal Communication (SIC) with the Security Management Server is not established.
PRJ-67330,
PMTR-125157
Scalable Platforms The Tunnel Test mechanism may incorrectly select a Sync interface IP address instead of the appropriate external interface IP. This leads to NAT drops and subsequent VPN tunnel disconnections.
PRJ-67194,
PRHF-41860
Scalable Platforms On Maestro appliances, /var/log/messages may be flooded with " asg_copy_capture" error messages when the system attempts to retrieve packet capture files that do not exist on remote Security Group members.
PRJ-67536,
PRHF-44544
Scalable Platforms A remote user may not be able to switch between Virtual Systems (VSs) in the Gaia Portal. While a local admin user is able to switch between VSs as expected.
PRJ-67911,
PMTR-126596
Scalable Platforms The PERFANALYZE process may exit because of an incorrect value type. As a result, SNMP performance data for the Security Group (ASG) is not updated.
PRJ-67073,
PMTR-124934
Scalable Platforms License commands such as " g_cplic putlic 192.0.2.15>" fails because of an incorrect calculation of member ID in ElasticXL environment, although the Sync IP address 192.0.2.15 (set up as per sk101556) exists.
PRJ-67740,
PRHF-44577
Scalable Platforms When adding or removing VS, if the freeze timeout ended before the VS was fully stable, the VS might still have a Critical Device (pnote), which will cause the member to go down. Refer to sk185115.
PRJ-67238,
PMTR-124193
Scalable Platforms In some scenarios, Anti-Spoofing generates excessive drops on ICMPv6 Neighbor Advertisement packets because traffic reaches other cluster members.
PRJ-65599,
PMTR-122629
Scalable Platforms Intermittent VS failover when both Maestro Hyperscale Orchestrators (MHOs) have the interface link state set to Down. Refer to sk184568.
PRJ-69289,
PMTR-127622
Scalable Platforms In VSLS clusters with multiple members, when a member rejoins the cluster after a reboot, an Interface Active Check (IAC) problem notification may incorrectly appear on the rejoining member, showing it in ACTIVE state. This occurs even though all interfaces are physically UP and the cluster is fully functional.
PRJ-65604,
PMTR-119583
Scalable Platforms In a dual-site Security Group configuration, if all members of site 1 are removed from the Security Group, the Hardware tab in SmartConsole displays an error message instead of the expected hardware information.
PRJ-66761,
PMTR-121709
Scalable Platforms Upgrade of a Scalable Group in the Traditional VSX / VSNext mode fails.
- The Jumbo Hotfix Accumulator package must be installed on both the Management Server and the Scalable Group.
PRJ-65087,
PMTR-126433
Scalable Platforms Added monitoring to detect connectivity failures between Dual-Site MHOs when the site-sync path is not directly connected. Refer to sk184381.
PRJ-67707,
PRJ-67595
Scalable Platforms After joining a VSNext ElasticXL member to a second site via automation, a pnote for the management (magg1) interface appears under vs0 in " cphaprob -a if", instead of under Virtual Switch (vswOID) as expected.
PRJ-67640,
PMTR-125756
Scalable Platforms In some scenarios, a Gateway that leaves the cluster is still shown as an active member to other Security Group members. This can result in the Gateway not being displayed as an available Gateway.
PRJ-65992,
PMTR-121081
Scalable Platforms After a Virtual System (VS) is deleted, its CTX folders are not removed.
PRJ-69305,
PMTR-128199
Scalable Platforms In Single Site mode, Security Groups containing more than 14 members may experience connectivity issues.
PRJ-69362,
PMTR-126478
Scalable Platforms The "set management interface" command does not show WRP interfaces on Maestro in VSNext mode.
PRJ-69402,
PMTR-128388
Scalable Platforms The "CliError( ) called without module or error code" error message is displayed when attempting to run VSX commands on an unsupported configuration in Clish.
PRJ-65998,
HEC-2256
Scalable Platforms Added the ability for alerts to send traps to trap receiver servers using IPv6.
PRJ-65098,
HEC-1550
Scalable Platforms All traps coming from a dedicated Member of a Security Group now include the hostname.
For example, a trap for Member 1_4 will include the hostname (for example, hostname-s01-04), providing clearer identification than just 1_4.
PRJ-65542,
PMTR-108818
Scalable Platforms In Maestro or ElasticXL environments with VPN enabled, traffic may be dropped with the log message " fwha_select_should_drop_vmac".
PRJ-64018,
PRHF-41940
Scalable Platforms Policy installation on one Virtual System (VS) fails without a visible error message. Refer to sk184194.
PRJ-67460,
PMTR-109489
Scalable Platforms When performing a SIC reset after Anti-Malware (AMW) has been installed, some members may enter a "cluster-down" state with an AMW Critical Device.
PRJ-66712,
CST-437
Carrier Security A GTPv0 tunnel fails to establish under certain conditions.
PRJ-69165,
CST-492
Carrier Security In a rare scenario, a processed malformed GTP packet may cause the Security Gateway to crash.
Take 24
Released on 15 June 2026 and declared as Recommended on 21 June 2026
Take 24 - Improvements and Resolved Issues
PRJ-69649,
PMTR-128753
VPN UPDATE:
- Resolved CVE-2026-50751 - User Authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange. Refer to sk185033.

- Resolved CVE-2026-50752 VPN site-to-site certificate bypass vulnerability in deprecated IKEv1 key exchange. Refer to sk185035.
PRJ-69508,
PRHF-45889
Security Management In rare scenarios, the CPD process may exit because of certain Secure Internal Communication (SIC) transactions.
See the Critical Information section.
Take 19
Released on 26 May 2026
Take 19 - New Functionality
PRJ-66478,
PMTR-119455
Security Management NEW: Policy Auditor is a policy analytics and auditing tool that provides visibility into traffic behavior within the user's network. In SmartConsole > Security Policies > Access Control, Policy Auditor presents a matrix view of the network's logical segments and the access rules defined between them. The tool allows administrators to audit these security rules and verify that they align with organizational access policies and segmentation requirements.
- Requires R82.10 SmartConsole Build 424 or higher.
PRJ-65860,
PRJ-65719
Security Management NEW: Now you can manage SASE Internet Access policy and HTTPS Inspection policy directly from SmartConsole. By centralizing policy management, the integration ensures consistent policy enforcement across products, streamlines governance for security policies, and consolidates operations into one trusted, management platform.
PRJ-67022,
PMTR-124959
Security Management NEW: Added a new Management API command to retrieve an entire Access Control Layer (including inline layers) - " export-access-rulebase".
PRJ-66628,
PMTR-124234
Security Management
Cloud Firewall
NEW: Added integration between the Security Management Server and Illumio to extend Check Point micro-segmentation capabilities. This integration enables importing Illumio Workloads and Labels into SmartConsole and using them directly in the Access Control Policy. It improves policy visibility and operational awareness, with enforcement performed on the Security Gateway without requiring an additional policy installation. Refer to R82.10 CloudGuard Controller Administration Guide > CloudGuard Controller for Illumio Policy Compute Engine
Take 19 - Improvements and Resolved Issues
PRJ-67985,
PMTR-126652
Security Gateway UPDATE: Resolved CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero. Refer to sk184981.
PRJ-67840,
PMTR-126457
Security Gateway UPDATE: Resolved CVE-2026-48132 - VPN process may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP. Refer to sk184982.
PRJ-67875,
PMTR-126538
Security Gateway UPDATE: Resolved CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion. Refer to sk184993.
PRJ-67837,
PMTR-126454
Security Gateway UPDATE: Resolved CVE-2026-48134 - SQL injection issue in UserCheck Web Portal when DLP is active. Refer to sk184983.
PRJ-68010,
PMTR-126694
Security Gateway UPDATE: Resolved CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests. Refer to sk184991.
PRJ-68356,
PMTR-126828
Security Management UPDATE: Resolved CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance. Refer to sk184992.
- - This Jumbo Hotfix Accumulator Take includes dozens of code and functionality hardening changes.
PRJ-66495,
PMTR-123718
SSL Inspection UPDATE: Upgraded OpenSSL from version 3.5.4 to version 3.5.5 to fix CVE-2025-66199.
PRJ-66682,
PMTR-124314
Mobile Access UPDATE: The Magnific Popup JavaScript library is upgraded from the 1.1.0 version to 1.2.0.
PRJ-66598,
PMTR-123078
SSL Inspection UPDATE: The HSM password is now configured in the secrets_manager tool using the " secrets_manager setpassword hsm" command. This provides centralized management and improved handling after configuration.
PRJ-67355,
PRHF-43660
Security Management UPDATE: JRE is updated from version 8.0_8.50 to version 8.0_8.60.
PRJ-66177,
PRHF-44771
Security Management UPDATE: Policy installation is now accelerated after performing Global Domain Reassignment.
PRJ-67101,
PMTR-89328
Security Management UPDATE: Added a validation that helps to prevent assigning a single Security Gateway as both the Center and Satellite member within the same VPN Star Community.
PRJ-65618,
HEC-1347
HCP UPDATE: Added a new HCP test that analyzes load balancing and NAT utilization, and suggests optimal distribution adjustments accordingly. Refer to sk171436.
PRJ-66950,
PRHF-44085
Security Gateway UPDATE: Added the " tap_mode" parameter to a dispatcher ( fwmultik_dispatcher_in_tap_mode). This parameter puts the multi-core dispatcher into the Tap Mode for inbound traffic. Refer to sk184455.
PRJ-63785,
PMTR-118923
Security Gateway UPDATE: Added the ability to automatically stop kernel debugging after a specified number of seconds. See the R82 Quantum Security Gateway Administration Guide. Refer to the command " fw ctl debug -T ".
PRJ-66840 VPN UPDATE: Improved the warning messages related to Tunnel Sharing behavior when transitioning between Route-Based and Domain-Based VPN community routing modes.
PRJ-65823,
CGNSIS-157
Cloud Firewall UPDATE: Added support for Microsoft Azure Network Adapter (MANA) driver. Refer to sk183754.
PRJ-66209,
HEC-2331,
PRJ-66278,
PRJ-66316,
HEC-2296,
PRJ-66648,
PMTR-124220
Scalable Platforms UPDATE: Added support for reusable target profiles to the Lightshot snapshot configuration.
PRJ-67871,
ODU-3950
Automatic Updates - CPSDC UPDATE: Added Take 43 of Check Point Support Data Collector (CPSDC) for Scalable Platforms and Maestro Security Appliances. Refer to sk164414.
PRJ-68136,
ODU-3901
Automatic Updates - Policy Insights UPDATE: Added Take 91 of Policy Insights Release Updates. Refer to sk183421.
PRJ-67868,
ODU-3957
Automatic Updates - HCP UPDATE: Added Update 27 of HealthCheck Point (HCP) Release. Refer to sk171436.
PRJ-67791,
ODU-3852,
PRJ-67787,
ODU-3894,
PRJ-68756,
ODU-4023
Automatic Updates - Web SmartConsole UPDATE: New features and improvements are released in Take 165, Take 167, Take 170 via self-updatable package. Refer to sk170314.
PRJ-68748,
ODU-4030
Automatic Updates - Threat Prevention UPDATE: Added Update 28 of Autonomous Threat Prevention Management Integration Release. Refer to sk167109.
PRJ-65163,
PRHF-42879
Security Management In SmartTask-generated emails, the Sender field displays the username instead of the user's email address.
PRJ-69084,
PMTR-127828
Security Management Reinstallation of R82.10 Jumbo Hotfix Accumulator Take 6 may result in configuration loss.
See the Critical Information section.
PRJ-65037,
PRHF-42720
Security Management In some scenarios, the status of a Security Gateway is incorrectly displayed in the Gateways & Servers View.
PRJ-66345,
PMTR-123469
Security Management The " set-checkpoint-host" Management API command with the "interfaces" field may fail with the " generic_err_invalid_parameter" error.
PRJ-65448,
PRHF-43029
Security Management In some scenarios, Global Domain assignment may fail with the " Failed to save the access policy assignment properties" error.
PRJ-66377,
PRHF-43684
Security Management In some scenarios, SmartConsole disconnects during policy installation.
PRJ-64819,
PRHF-41049
Security Management In some scenarios, when updatable objects are used in the policy, policy installation fails with error code "0-2-2000245". Refer to sk183844.
PRJ-66607,
PMTR-124200
Security Management If the MGMTCOMP-DIFF-REPORT-CLIENT process becomes suspended on the Security Management Server, the Server-side Change Report Generator fails to generate and send reports when processing a large number of changes.
PRJ-66032,
PRHF-43621
Security Management In some scenarios, the Management Server may generate excessive log messages, causing the cpm.elg log file to reach its size limit quickly.
PRJ-66396,
PRHF-38392
Security Management Upon creation of a new Domain on a Multi-Domain Security Management Server, the Domain Server's virtual IP address is not added to the Gaia database, making it inaccessible via Clish commands. Refer to sk183941.
PRJ-66099,
PMTR-125251
Security Management The "get interfaces" operation may fail when performed after adding a Data Center object to a VPN community.
PRJ-64691,
PRHF-34095
Security Management The delay may be observed during the "compiling policy" and "generating policy files" stages in SmartConsole.
PRJ-65671,
PRHF-43067
Multi-Domain Security Management In some scenarios, the Domain Log Management Server fails to connect to the Check Point Portal.
PRJ-67039 CPView In some scenarios, CPVIEW_API_SERVICE may unexpectedly restart and generate a core dump file.
PRJ-68480,
PMTR-127026
CPView A race condition may occur in the CPView API Service, which may result in the CPVIEWD daemon exiting during shutdown.
PRJ-68510,
PRJ-68481,
PMTR-127053
CPView The CPVIEWD daemon may exit during startup.
PRJ-66685,
PRHF-41752
Logging In SmartConsole, when exporting logs from the Logs tab to a CSV file, the "Rule" column may display only the parent rule number instead of the specific inline rule number.
PRJ-66532,
PRHF-44001
Logging CPView may display "N/A" values for logging-related metrics when there is insufficient free disk space in the log partition.
PRJ-66652,
PRHF-35509
Logging In the Connection logs, the Source Country and Destination Country fields may contain missing or incorrect values.
PRJ-66843,
PRHF-44182
Logging In some scenarios, non-ASCII characters may appear garbled in SmartEvent Automatic Reaction emails.
PRJ-67271,
PRHF-38494
Logging In HTTPS Inspection logs, some log entries may incorrectly display "Log Update" in the Software Blade field.
PRJ-65333,
PRHF-42927
Logging In SmartView Monitor, opened from Logs & Events > Tunnel & User Monitoring, the "SmartEvent Correlation Unit" status may be displayed as "Not running" although the CPSEMD process is running.
PRJ-65365,
PMTR-122317
Logging Improper memory handling within the CPD daemon may result in unexpected process restart.
PRJ-65551,
PRHF-39872
Security Gateway Test feed fails when testing a Network Feed object with the feed parsing format configured as JSON. Refer to sk183618.
PRJ-64136,
PRHF-38489
Security Gateway In rare scenarios, the FWK process may exit with core files because of a segmentation fault.
PRJ-67520,
PRHF-30983
Security Gateway Running the " g_tcpdump mcap" with " -C" flag fails with the file matching or captured packets merging error.
PRJ-65712,
PRHF-41491
Security Gateway Enabling the ForceAuth option for Remote Access VPN fails because of a typo in the saml_force_authn_override.sh script ( sk182042).
PRJ-64181,
PRHF-41504
Security Gateway In rare scenarios, the FWK process may exit when parsing an invalid SIP packet.
PRJ-66805,
PRHF-44149
Security Gateway In rare scenarios, the FWK process may unexpectedly exit when the Anti-Bot Software Blade inspects a specific malformed domain.
PRJ-65443,
PRHF-42991
Security Gateway The SD-WAN NAT rule may not be applied when no NAT is defined in the Access Control policy.
PRJ-64520,
PRHF-41790
Security Gateway First packet may be delayed for around 10 seconds because of pending WSDNSD DNS lookup over TCP. Refer to sk184096.
PRJ-67358,
PRHF-44269
Security Gateway In rare scenarios, after an upgrade, the Security Gateway may crash because of a missing route.
PRJ-66005,
PRHF-43522
Security Gateway In a rare scenario, an incorrect zone assignment occurs when NAT Rule Base returns HOLD. Refer to sk184530.
PRJ-64835,
PRHF-42537
Security Gateway Legitimate files may be incorrectly flagged as malicious when scanned with ICAP. Refer to sk184628.
PRJ-65054,
PRHF-42145
Security Gateway In some scenarios, SNMPv3 monitoring fails on Data Plane when MDPS is enabled. Refer to sk184379.
PRJ-66199,
PRHF-43742
Security Gateway In some scenarios, when processing HTTPS traffic in the accelerated pipelined path, the FWK process may unexpectedly exit.
PRJ-66360,
PRHF-43916
Security Gateway The BMAC/VMAC verification for a VSX Maestro Security Group member incorrectly reports a failure on warp interfaces.
PRJ-66174,
PRHF-43692
Security Gateway The Security Gateway may fail to correctly handle return traffic for pass-through GRE connections in scenarios with NAT.
PRJ-65269,
PMTR-121815
Security Gateway In some scenarios, non-accelerated traffic from a Standby VSX Cluster member may not be routed to the correct virtual instance on the current Active member when SecureXL User Mode (UPPAK) is enabled.
PRJ-65586,
PRHF-43161
Threat Prevention In Smart-1 Cloud environments, the "Threat Prevention" view may display 0 in the "Logs" column under the "Top Protections" widget. Refer to sk184505.
PRJ-65697,
PRHF-42937
Identity Awareness In some scenarios, when Identity Sharing is configured to work with both IPv4 and IPv6 addresses, identity-based roles may not match the access roles.
PRJ-66257,
PMTR-123472
Identity Awareness The TLS-based Identity Sharing connection between the Policy Decision Point (PDP) and Policy Enforcement Point (PEP) may fail to establish when using IPv6 transport.
PRJ-66217,
AAD-8684
Identity Awareness In some scenarios, identity sessions are not propagated to the PEP when PDP multi-process is enabled.
PRJ-65790,
PRHF-42181
Identity Awareness Identity Awareness AD user authentication takes a long time. Refer to sk183748.
PRJ-66925,
PMTR-122417
Identity Awareness In some scenarios, when PDP Multi-Process is enabled, users or machines do not match their Identity-Based policy rules.
PRJ-65877,
PMTR-123004
Application Control In a rare scenario, when using Dynamic URL List, updating the version file may result in a FWK process restart.
PRJ-65961,
PMTR-123099
Application Control Updating two or more Dynamic URL Lists may result in partial updates.
PRJ-66301,
PRJ-66185
Anti-Virus In some scenarios, the Security Gateway may drop DNS traffic with non-malicious Domains.
PRJ-66453,
PMTR-121764
SSL Inspection Several WSTLSD processes running for each Security Gateway may exhaust memory consumption.
PRJ-66595,
PRHF-44051
Mobile Access When Mobile Access is working in Path Translation (PT) Link Translation mode, the Citrix application may not load after an upgrade to Citrix version LTSR 2507.
PRJ-67249,
PRHF-44244
Mobile Access On a Check Point Firewall 3900 appliance, the CVPND process may exit while serving Citrix applications.
PRJ-65902,
PMTR-123186
ClusterXL After rebooting specific Security Group Members (SGMs) in a dual-site Maestro environment, PDP (Policy Decision Point) to PEP (Policy Enforcement Point) connections are not always corrected to the SMO (Single Management Object) as expected. This results in connection restarts and additional CPU load.
PRJ-64917,
PRHF-42671
ClusterXL After creating a High Availability ClusterXL and syncing to Smart-1 Cloud, running the " get interfaces with topology" in Smart-1 Cloud may cause the Sync interface to be removed from the Cluster object.
PRJ-64091,
PRA-5003
ClusterXL When MDPS is enabled, cluster members may remain in INIT or DOWN state after reboot.
PRJ-66294,
PMTR-123321
ClusterXL In rare scenarios, CPHASTART, CPHACONF, and CPHAMCSET processes may intermittently unexpectedly exit.
PRJ-67240,
PRHF-44218
SecureXL IPv4 addresses in the SYN Defender Allow List in SmartConsole may be loaded with the address octets reversed.
PRJ-67686,
PMTR-125951
SecureXL Changes to the SYN Defender Allow List made in SmartConsole may not override or replace local modifications made directly on the Security Gateway.
PRJ-67243,
PRHF-44335
SecureXL When loading the SYN Defender Allow List from the Gateway CLI using only the " -L" parameter, the entries are merged with the existing Allow List (including those configured in SmartConsole), rather than overwriting it.
PRJ-67246,
PRHF-44550
SecureXL Maestro backplane interfaces may appear in the SYN Defender interface list. This is a cosmetic issue.
PRJ-67252,
PRHF-44552
SecureXL The USIM process may exit on Check Point Firewall 3900 appliances during IPsec VPN traffic decryption.
PRJ-66368,
PMTR-121210
SecureXL Local VXLAN connections may not work as expected.
PRJ-66508,
PMTR-122586
SecureXL In some scenarios in a VSX Maestro Security Group, when SecureXL User Mode (UPPAK) is enabled, a cluster member may incorrectly forward traffic through a Warp interface to the incorrect Virtual System. This results in traffic not being processed by the intended Virtual System, potentially causing "Out of State" drops.
PRJ-66571 SecureXL When SecureXL is running in User Mode (UPPAK) on ESXi with iavf SR-IOV enabled, setting the SND core count using " cpconfig" or the queue count using " mq_mng" to a value that is not a power of two (for example, any number other than 2, 4, 8, 16, and so on) may result in the Security Gateway entering an infinite boot loop.
PRJ-67078,
PMTR-121785
SecureXL When using Virtio or net_iavf drivers, when configuring " mq_mng" and setting the core count to match the SND (Send) core count, a portion of network traffic may be lost.
PRJ-67067,
PMTR-124718
SecureXL The FWK process may exit during an upgrade if DOS/Rate limiting is active.
PRJ-66172,
PRHF-43757
SecureXL In some scenarios, when installing a policy fails, the Sand Blast Security Gateway becomes unresponsive and reboots automatically. The " Installation failed. Reason: Due to a timeout value of 600000 (millisecond) (port) (IP), Security Management Server aborted the connection with the peer" error is displayed in SmartConsole.
PRJ-65915,
PMTR-122248
SecureXL When SecureXL User Mode (UPPAK) is enabled on a VSX Security Gateway, taking down a warp interface on any Virtual System may cause all Virtual Systems connected to the same Virtual Router or Switch to lose network connectivity.
PRJ-65449,
PMTR-120207
SecureXL The Security Gateway with SecureXL User Mode (UPPAK) enabled may not properly update routes when bond interfaces are configured.
PRJ-65918,
PMTR-122434
Routing A VSX Security Gateway may drop traffic with IPv4 options or IPv6 extension headers arriving from a Virtual Switch (VSW) interface.
PRJ-67174,
PRHF-44146
Routing A ROUTED daemon may exit with a dump file during an OSPF route lookup on a route being redistributed between BGP and OSPF.
PRJ-66409,
PRHF-43907
Gaia OS The SNMPD daemon fails to restart when an interface configured with an IPv6 address is set as the SNMP agent interface.
PRJ-65891,
PRHF-30690
Gaia OS Custom log rotation configured using Gaia OS does not apply to SAML-related log files, so these logs are not rotated automatically. Refer to sk113241.
PRJ-65890,
PRHF-34965
Gaia OS Custom log rotation configured using Gaia OS does not apply to UserCheck Portal log files, so these logs are not rotated automatically. Refer to sk113241.
PRJ-66752,
PRHF-44108
Gaia OS Cloning groups may fail during configuration updates. Refer to sk184701.
PRJ-67883,
PMTR-126636
Gaia OS In a Maestro setup with MDPS enabled, the Security Gateway may crash when processing IPv6 traffic while under load.
PRJ-66616,
PRHF-43985
Gaia OS Newly added SGM remains "Down" on Scalable Chassis with SSM440 configured with MTU higher than 9000. Refer to sk184653.
PRJ-68363,
PMTR-126985
Gaia OS In rare scenarios, a Check Point Firewall 3900 appliance (3950, 3970/3980 model) may fail to identify the hard disk.
PRJ-64590,
PRHF-41203
Gaia OS CPU spikes may occur in a cluster when SNMP is enabled.
PRJ-66271,
PMTR-123507
VPN During VPN IKEv2 negotiations with third-party peers that offer multiple combined encryption algorithms (both AES-GCM-128 and AES-GCM-256), the Security Gateway may not properly match the proposal, resulting in IKE failure logs and the tunnel establishment failure.
PRJ-66821,
PMTR-124036
VPN Multiple Entry Point (MEP) validation may be incorrectly triggered when switching a Star Community to a Route-Based community.
PRJ-65544,
PMTR-123634
VPN VPN participant Domains may not be automatically removed when a device is deleted from a community.
PRJ-65012,
PRA-5001
VPN SSL Network Extender Portal is accessible even when it is disabled in SmartConsole. Refer to sk184344.
PRJ-65827,
PRHF-43529
VPN A customized Per-gateway Secure Configuration Verification (SCV) policy is not enforced for Remote Access VPN clients. Refer to sk184863.
PRJ-64814,
PMTR-120624
VPN When switching a VPN community from Route-Based to Domain-Based mode, the Tunnel Sharing setting may not reset to its default value. After the switch, Tunnel Sharing remains set to Per Gateway Pair instead of reverting to the Domain-Based default of Per Subnet Pair. No notification is displayed to alert about the discrepancy, which may impact performance.
PRJ-65420,
PMTR-121924
VPN After a Cluster failback, RDP (Routed Data Path) or DPD (Dead Peer Detection) probing may not be triggered, which can result in traffic continuing to use outdated Multiple Entry Point (MEP) Gateway selections.
PRJ-66366,
PMTR-123613
VPN In some scenarios, over time, prolonged VPN traffic may lead to gradual memory growth.
PRJ-64081,
PRHF-41901
VPN When generating a CPInfo file using the CPInfo utility, major CPU spikes may occur on the Security Gateway or Security Management Server.
PRJ-66013,
PMTR-117053
VPN VPN traffic from L2TP clients may fail to pass through the Security Gateway working in SecureXL User Mode (UPPAK).
PRJ-68887,
PRJ-68715,
PMTR-127505
VPN Remote Access Endpoint Security Client may disconnect and reconnect approximately every 15 seconds.
PRJ-65463,
PMTR-122433
VPN Remote Access Endpoint Security Client may fail to connect.
PRJ-67928,
PRHF-45114
Multi-Portal In a rare scenario, a security hardening change related to Multi-Portal connections may cause an unexpected Security Gateway restart when such a connection is terminated.
See the Critical Information section.
PRJ-67447,
PMTR-121363
VSX When a Virtual System (VS) is deleted from a VSX Security Gateway, the Dynamic Split feature does not properly recognize the removal and continues to attempt fetching data or updating CPU affinity for the deleted VS. This results in repeated errors or log entries referencing the non-existent Virtual System, and may interfere with CPU core allocation and affinity management for the remaining VSs.
PRJ-66798,
PRHF-41154
VSX A malformed or incorrect interface name in the " cphaprob -a if" command on VS0 triggers a fatal error in the cluster process, causing the member to go DOWN and generating a core dump.
PRJ-65935,
HEC-2260
VSX The " show configuration" gClish command may fail for showing configuration for LLDP, VSNext, VSLS, SSH, and OSPF.
PRJ-65674,
PMTR-122609
VSX Deleting a Virtual Switch (VSW) may break connectivity for unrelated Virtual Systems (VSs).
PRJ-67231,
PMTR-125258
VSX Incorrect MAC address configuration on WRP interfaces in a VSNext environment leads to ClusterXL Load Sharing malfunctions and traffic correction issues.
PRJ-67115,
PMTR-123775
VSX When adding or deleting static routes in the huge VSX environment (more than 50 Virtual Systems and hundreds of static routes), VS creation fails with " Unable to watch directory /etc/routed-mc-enable: init: Too many open files". Refer to sk181317.
PRJ-65389,
PMTR-122044
VSNext In VSNext ElasticXL and VSNext Maestro, running the " cpconfig" command from Clish/gClish within a Virtual System context may trigger execution in the Global context.
PRJ-65387,
PMTR-122058
VSNext When the Same VMAC Mode is enabled on ElasticXL, VS0 may lose connectivity (SSH).
PRJ-66386,
PRHF-43223
Cloud Firewall The FWM may unexpectedly exit when attaching a license to a Security Gateway using vSEC license distribution (vsec_lic_cli).
PRJ-65297,
PRHF-42496
Cloud Firewall When using VSLS with Identity Sharing enabled, CloudGuard Controller may fail to send updates to Virtual Systems that have no Data Center Objects in their policy.
PRJ-65014,
PRHF-42642
Cloud Firewall Registration of Data Center assets with a numeric, non-UID unique identifier may fail, potentially causing performance impact on the Security Management Server.
PRJ-65940,
PRHF-42485
SD-WAN In rare scenarios, SD-WAN objects (such as Peer VPN Domain, My VPN Domain, or SD-WAN Internet) may be incomplete, causing SD-WAN rules to match traffic incorrectly. Refer to sk184814.
PRJ-64736,
SDWANGW-5773
SD-WAN A VPN IPv6 traffic outage may occur when a host/network object is defined with the Security Gateway's main IPv6 address.
PRJ-66034,
PMTR-109757
VoIP Real-time Transport Protocol (RTP) may not function correctly, this results in the VoIP/RTP traffic being dropped.
PRJ-65801,
PRHF-42758
VoIP Security Gateway may drop legitimate H323 traffic with " Illegal H.225(Q931) No Q.931 User-user IE found". Refer to sk184591.
PRJ-66899,
PRJ-56967
Scalable Platforms Maestro/ElasticXL policy installation may fail during a major version upgrade.
PRJ-65099,
HEC-1552
Scalable Platforms In a Maestro environment with Multi-Domain Security Management and enabled MDPS, SNMP per member queries do not survive member failover. Additionally, SNMP queries to the SMO may be routed to the dplane instead of the mplane.
PRJ-67016,
PMTR-121790
Scalable Platforms In a Maestro setup, VXLAN tunnels may not consistently forward traffic with multiple Security Group Members.
PRJ-66487,
PMTR-121957
Scalable Platforms In a Maestro environment, deleting a configured VXLAN from the Security Gateway using gClish on VS0 results in a " Segmentation fault (core dumped)" error, despite successful deletion from SmartConsole.
PRJ-66559,
PMTR-121905
Scalable Platforms In ElasticXL setups, it may not be possible to add a second Sync interface to the bonding group.
PRJ-67483,
PMTR-125457
Scalable Platforms If a management interface on ElasticXL Security Gateway is a part of a bond, the license distribution mechanism may not work as expected.
PRJ-67177,
PMTR-120169
Scalable Platforms In ElasticXL Clusters, a new member that exits ungracefully (force shutdown, power loss, unexpected exit) may not appear in the Clish "delete cluster member" options and cannot be deleted from the cluster configuration.
PRJ-66522,
SPC-3384
Scalable Platforms Rebooting an Active member in the Single Management Object (SMO) role may trigger a brief connectivity loss.
PRJ-66921,
PMTR-124111
Scalable Platforms After upgrading the Multi-Version Cluster to R82.10, failback to an older version may cause connection drops.
PRJ-66706,
PMTR-124344
Scalable Platforms After an upgrade to R82.10 of the Maestro environment, connecting using SSL Network Extender (SNX) fails. The Security Gateway drops the packets with the reason " clear text packet should be encrypted".
PRJ-68246 Scalable Platforms After uninstalling the R82.10 Jumbo Hotfix Accumulator, previously installed RPM packages are not restored to their original state.
PRJ-65694,
PMTR-122746
Scalable Platforms In VSX setup, a configuration note may be generated after a reboot, although the configuration is synchronized.
PRJ-67350,
PMTR-123997
Scalable Platforms A Security Group Member may enter a continuous boot loop after the other members were upgraded. An incorrect image file (with an invalid or mismatched MD5 checksum) is presented on the Single Management Object (SMO). As a result, the problematic member fails to complete the autoclone and repeatedly reboots.
PRJ-66512,
PMTR-122125
Scalable Platforms Members added to an ElasticXL Security Group with the MDPS feature enabled may remain in the Down state because of a missing license. Licenses are not automatically distributed from the SMO member to newly added Security Group members.
PRJ-65728,
HEC-2236
Scalable Platforms In VSNext setup, when a numbered VTI interface is created for a route-based VPN under VS0 and attached to a Virtual System, the interface appears correctly in the output of the " ifconfig" command under VS0 but becomes invisible in " ifconfig" within the assigned VS context, although it remains visible in the Clish commands output.
PRJ-65996,
PRJ-65903
Scalable Platforms On Maestro running VSNext, when a Virtual Switch (VSW) shares a physical interface with a Virtual System (using different VLANs), the VSW's VLAN interface may not be propagated to the Maestro Hyperscale Orchestrator (MHO).
PRJ-67338,
PRJ-67210
Scalable Platforms Bond interface deletion or IP address change may cause a site failover.
PRJ-65685,
PRHF-42942
Carrier Security The FWK process may exit when GTP Intra Tunnel Inspection is enabled.
PRJ-65688,
CST-423
Carrier Security GTP-U intra-tunnel packets may be dropped with " Packet too short" and " Invalid IP packet" errors in Bridge Mode, preventing proper inspection of encapsulated traffic.
PRJ-66715,
CST-439
Carrier Security A " Tunnel established" message may be printed for rejected sessions. The issue is cosmetic.
Take 6
Released on 06 April 2026
Take 6 - New Functionality
PRJ-65396,
PRHF-32290
Identity Awareness NEW: Added new OID (1.3.6.1.4.1.2620.1.38.55) to monitor the Identity Collector connection status in the $CPDIR/lib/snmp/chkpnt.mib file.
- This capability is supported for Identity Collector agents running with version R82.120.0000 or higher.
PRJ-64974,
AAD-4768
VPN NEW: Added support for nested groups with host/range/network objects for split tunnel on exclusion/inclusion options. Refer to R82.10 Remote Access VPN Administration Guide.
PRJ-64016,
PMTR-119998
VPN NEW: It is now possible to add host/network/range objects for split tunnel on exclusion/inclusion modes. Refer to R82.10 Remote Access VPN Administration Guide.
Take 6 - Improvements and Resolved Issues
PRJ-65055,
PRJ-65041
Security Management UPDATE: When connecting a Domain to the Check Point Portal, Dedicated Log Servers in the Domain are now connected automatically.
PRJ-65494,
PMTR-122413
Logging UPDATE: SmartEvent now supports the "system alert" log type for URL Filtering and Application Control Software Blades.
PRJ-64478,
ODU-3143,
PRJ-64639,
ODU-3259,
PRJ-65289,
ODU-3387,
PRJ-66547,
ODU-3619,
PRJ-67136,
ODU-3714
Automatic Updates - Web SmartConsole UPDATE: New features and improvements are released in Take 155, Take 156, Take 157, Take 163, Take 164 via self-updatable package. Refer to sk170314.
PRJ-64906,
ODU-3275,
PRJ-67145,
ODU-3682
Automatic Updates - CPView UPDATE: Added Take 210, Take 223 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522.
PRJ-64830,
ODU-3235
Automatic Updates - Threat Prevention UPDATE: Added Take 27 of Autonomous Threat Prevention Management integration Release. Refer to sk167109.
PRJ-64543,
ODU-3199,
PRJ-64744,
ODU-3267
Automatic Updates - CPView UPDATE: Added Take 52, Take 53 of CPquid (QUID) Release Updates. Refer to sk181458.
PRJ-67226,
ODU-3738
Automatic Updates - HCP UPDATE: Added Update 26 of HealthCheck Point (HCP) Release. Refer to sk171436.
PRJ-65177,
ODU-3419,
PRJ-66383,
ODU-3435,
PRJ-67189,
ODU-3845
Automatic Updates - Policy Insights UPDATE: Added Take 80, Take 82, Take 87 of Policy Insights Release Updates. Refer to sk183421.
PRJ-66729,
ODU-3666,
PRJ-67127,
ODU-3803
Automatic Updates - Log Exporter UPDATE: Added Take 53, Take 60 to Log Exporter Auto Update Deployment. Refer to sk182866.
PRJ-66623,
ODU-3347
Automatic Updates - Security Management UPDATE: Added Update 4 of Server-Side Change Report Generator Release Updates. Refer to sk179508.
PRJ-67139,
ODU-3698
Automatic Updates - CPView UPDATE: Added Take 88 of CPViewExporter Release Updates. Refer to sk180521.
PRJ-67229,
ODU-3467
Automatic Updates - Threat Prevention UPDATE: Added Update 28 of Autonomous Threat Prevention Management Integration Release. Refer to sk167109.
PRJ-64542,
PMTR-120942
Security Management When using the " add/set data-type-weighted-keywords" and " add/set data-type-file-attributes" Management API commands, the field "description" is missing from the response.
PRJ-64703,
PRHF-42579
Security Management Hitcount of NAT Rule Base fails after Security Management Server upgrade. Refer to sk184336.
PRJ-65810,
PRHF-43517
Security Management The " show-packages" Management API command executed with " async-response" parameter may fail with " generic_err_invalid_parameter_name".
PRJ-64945,
PRHF-41803
Multi-Domain Security Management On Multi-Domain Security Management Servers, custom Compliance Software Blade Best Practices may differ between the Multi-Domain Security Management level and the Domain level.
PRJ-65350,
PMTR-122267
Compliance In some scenarios, scheduled Compliance scans are not executed after setting the intervals via the " set compliance-settings" Management API command.
PRJ-64468,
PRHF-42386
Logging In some scenarios, exporting logs to CSV in SmartView fails and the LOG_INDEXER process unexpectedly exits. Refer to sk184475.
PRJ-65907,
PMTR-122146
Logging In the "HTTPS Inspection Statistics" in SmartView, filtering by the "bypass_reason" field returns no results.
PRJ-64075,
SL-9462
Logging In some scenarios, incorrect values are shown in the "Total Bytes" field in the logs.
PRJ-65820,
PMTR-122907
Security Gateway When using a Security Gateway as a Proxy "Non-transparent" and HTTPS Inspection is set to "inspect" with "X-Forward-For header", video playback on YouTube fails.
PRJ-65227,
PRA-5005
Security Gateway In a rare scenario, the FWK process may restart unexpectedly when the Security Gateway processes accelerated connections.
PRJ-64850,
PRJ-64783
Security Gateway The FWK core dumps may be generated when the Security Gateway is processing HTTP traffic.
PRJ-64079,
PRHF-41256
Security Gateway In scenarios where a network connection is closed before the Anti-Virus ThreatCloud emulation or scanning response is received, the affected session may experience connectivity instability.
PRJ-65781,
PRHF-40380
Security Gateway When configuring NAT64 rules for specific targets, the rules may fail to apply. Return traffic may be dropped.
PRJ-65924,
PMTR-122717
Threat Prevention In some scenarios, External Risk Management (ERM) enrichment for SSH connections may be incomplete, resulting in only partial contextual data or risk insights associated with the SSH session.
PRJ-66297,
PMTR-123479
Threat Prevention In a rare scenario, the Threat Prevention Rule Base may fail to match traffic to any rule.
PRJ-66142,
PMTR-122910
Threat Prevention File downloads may get stuck at 100% completion when either the Anti-Virus or Threat Emulation Software Blade is actively scanning the file.
PRJ-65834,
PRHF-42534
Identity Awareness In a rare scenario, a Policy Decision Point (PDP) Security Gateway that acts as both an Identity Broker Subscriber and a sharing identity with a Policy Enforcement Point (PEP) may become unresponsive.
PRJ-64695,
PRHF-42522
Identity Awareness When the Packet Tagging feature is enabled on the Full Identity Agent, new user and machine identity sessions reported to the Identity Awareness Gateway may not be assigned the correct Access Roles. As a result, traffic from these sessions may not match Access Control Policy rules that use Access Roles with Packet Tagging enabled.
PRJ-65900,
PRHF-41176
Identity Awareness In a rare scenario, there may be no access to resources for identities received from the Remote Access identity source.
PRJ-64765,
PRJ-60821
Anti-Virus False threat alerts may appear in Anti-Virus logs for benign traffic (action: accept). This is a cosmetic issue with no security impact.
PRJ-64114,
PRHF-41553
HTTPS Inspection In some traffic flows, packets containing certain headers may be dropped regardless of how the non-compliant HTTP Inspection is configured.
PRJ-64497,
PRHF-42513
SSL Inspection Running the " show cp-trusted-ca-certificate" Management API with invalid validFrom/ validTo values in the database causes an error and blocks the Trusted Certificates view.
PRJ-64021,
PRHF-39978
Mobile Access Mobile Access Software Blade may incorrectly terminate Guacamole-based clientless RDP/SSH sessions due to client idleness.
PRJ-64023,
PRHF-41229
Mobile Access In rare scenarios, Mobile Access SmartConsole Logs may not match views/queries, including the "MAC address" or "Methods" field names.
PRJ-66156,
PRJ-58737
Mobile Access After an upgrade, the Mobile Access Software Blade's CVPND process fails to load and the Mobile Access Portal becomes inaccessible when adding new Virtual Systems (VSs) or converting to a VSX Gateway, due to improper updates to the gateway-side configuration file cvpnd.C. Refer to sk183293.
PRJ-65452,
PMTR-121744
SecureXL Permanently disabling the " cphwd_enable_ecmp" global parameter on a VSX Gateway using the " -f" option of the " fwl ctl set" command may fail.
PRJ-64959,
PRHF-38461
SecureXL In an asymmetric UDP traffic scenario (Client-to-Site VPN and Site-to-Site VPN distributed to different members), the connection may not get accelerated.
PRJ-64796,
PMTR-121309,
PMTR-121673
SecureXL The CX4 firmware does not update automatically as expected, and there is no error message indicating that the firmware is not the latest version.
PRJ-65602,
PMTR-122439
SecureXL When SecureXL works in User Mode (UPPAK) on Security Gateways with CPAC-4-10F-C interface modules, invalid Ethernet frames permanently shut down the port's transmit queue, causing complete connectivity loss.
PRJ-65221,
PRHF-42915
Gaia OS SNMP monitoring systems may report format errors related to the structure of the chkpnt.mib file.
PRJ-65527,
PRHF-43016
Gaia OS Upon logging in to the Gaia Portal, the login page accepts the credentials, briefly displays the homepage, and then automatically redirects back to the login screen.
PRJ-65224,
PRHF-42944
Gaia OS When integrating SNMP monitoring systems with Gaia OS, compilation of the GaiaTrapsMIB.mib file with the CHECKPOINT-MIB (chkpnt.mib) may fail. SNMP management stations or MIB browsers (such as HP OpenView, CA Spectrum, or HP Network Node Manager) return errors like " File GaiaTrapsMIB.mib failed to parse" or " ERROR : Cannot find symbol file://GaiaTrapsMIB.mib:Line XX:Column XX:multiDiskName".
PRJ-65858,
PMTR-122180
Gaia OS Users cannot create read-only roles, cannot modify roles by removing permissions, or assign roles with all features to specific virtual servers, and all operations fail silently without warnings.
PRJ-65301,
PMTR-122146
Gaia OS If multiple snapshots are stored on the Gateway server, creating a new snapshot fails with the " Cannot create snapshot, insufficient space in /boot" error, even though there is enough unpartitioned space.
PRJ-66998,
PRJ-67000,
PRJ-67034,
PMTR-124920,
PRHF-44366
VPN, Internal CA Starting March 1st, 2026, newly created certificates and newly generated CRL may fail validation. Refer to sk184766.
PRJ-65904,
PMTR-122006
VSX During interface reallocation between Virtual Systems (VSs) on a VSX Gateway, Management access (SSH/Gaia Portal) to VS0 may be disrupted after the interface move. Returning the interface to its original VS does not recover connectivity.
PRJ-65675,
PMTR-122185
VSX When attempting to create a new Virtual System (VS) with management connectivity enabled, the operation may fail. This prevents the successful provisioning of the Virtual System in the environment.
PRJ-66176,
PMTR-122234
VSX Creating a large number of Virtual Systems (VSs) simultaneously may intermittently fail.
PRJ-65243,
PMTR-121780
VSNext After adding a virtual link between a Virtual System (VS) and a Virtual Switch (VSW), policy installation may fail with the " Installation failed. Reason: TCP connectivity failure [ error no. 10 ]" error.
PRJ-65484,
PRHF-43055
VSNext Three out of four Virtual Systems (VS) on a single site may show a "Problem" Health status in the output of the " asg stat vs all" test. This is a cosmetic issue.
PRJ-65480,
PMTR-122468
Cloud Firewall The Cloud Firewall Central License utility fails to distribute a single license using CLI.
PRJ-65593,
PMTR-122597
Cloud Firewall When a new Cloud Firewall Gateway is added to the Security Management Server, and a security policy is installed, the Security Gateway may not appear in the Central License Tool (vsec_lic_cli). As a result, the Security Gateway fails to receive a central license.
PRJ-64443,
PRHF-42470
Scalable Platforms Maestro Orchestrator fails to add a new Security Appliance to a Security Group when the Maestro Fastforward feature is enabled in the Security Group. Refer to sk184233.
PRJ-64394,
PMTR-119685
Scalable Platforms When adding a subordinate to an LACP bond, a member may go down, which triggers a site failover.
PRJ-65637,
PMTR-122661
Scalable Platforms After an upgrade in the Maestro and Chassis environment with multiple Virtual Systems (VSs), the disk may reach full capacity.
PRJ-65501,
PMTR-122485
Scalable Platforms These actions applied through the Gaia Portal are not applied to all Security Group members, but only to the SMO:
- create/delete/edit scheduled backup

- edit mail-address/notification-level for mailing

- delete backup
PRJ-65970,
PMTR-92125
Scalable Platforms After creating a bridge interface using Gaia Portal and rebooting, the Security Gateway state is down.
PRJ-66016,
PMTR-123154
Scalable Platforms Using a unique IP address with the Same VMAC feature enabled may cause connections to the Standby unique IP address to fail.
PRJ-65965,
PMTR-120383
Scalable Platforms Link-local per-member address calculation between ElasticXL members may not be correct.
PRJ-64505,
CST-399
Carrier Security Policy installation fails with an internal error when the Security Gateway policy includes rules that match a specific Access Point Name (APN) for GTPv0 or GTPv1 traffic.

22 July 2026

© 2026Check Point Software Technologies Ltd.