# Jumbo Hotfix Accumulator for R82

# R82 Jumbo Hotfix Take 36

|     |     |     |
| --- | --- | --- |
| [Download Jumbo Hotfix Accumulator Takes](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/R82_Downloads.htm) |  | [Download Previous Recommended Takes](https://support.checkpoint.com/results/sk/sk174185) |

|     |     |
| --- | --- |
|  | Note \- This Take contains all fixes from all earlier Takes. |

Download CSV

| ID | Product | Description |
| --- | --- | --- |
| **Take 36**<br>Released on 31 July 2025 |
| **Take 36** \- **New Functionality** |
| PRJ-60966,<br>PMTR-90911 | Security Management | NEW: In SmartConsole, the CSV export file of Access Control Policy NAT rules now contains the hit count data: "Hits", "First Hits" and "Last Hits" columns.<br>- Requires [R82 SmartConsole](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82_SC/Default.htm) Build 1056 or higher. |
| PRJ-60497,<br>PMTR-114492 | Security Management | **NEW**: Added statistics for Top Matched Access Control Rules and Top Log Types in the Logs view of SmartConsole and in the response of the " _show logs_" Management API command. This allows to identify the rules that generate a high volume of logs. |
| PRJ-62732,<br>SMBGWY-12611 | Security Management | **NEW**: Added support for the Quantum Spark 2500 appliances (2530, 2550, 2560, 2570, and 2580) in the EA (Early Availability) program.<br>- Requires [R82 SmartConsole](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82_SC/Default.htm) Build 1057 or higher. |
| **Take 36** \- **Improvements and Resolved Issues** |
| PRJ-60718,<br>PMTR-114504 | Logging | **UPDATE**: Resolved [CVE-2025-2028](https://www.cve.org/CVERecord?id=CVE-2025-2028). Lack of TLS validation when downloading a visualization support data file. Refer to [sk183349](https://support.checkpoint.com/results/sk/sk183349). |
| PRJ-59425,<br>PMTR-112077 | Mobile Access | **UPDATE**: Resolved [CVE-2024-52885](https://www.cve.org/CVERecord?id=CVE-2024-52885). Mobile Access File Share applications are vulnerable to directory traversal attacks. Refer to [sk183137](https://support.checkpoint.com/results/sk/sk183137). |
| PRJ-59537,<br>MGMTPROD-1385 | Security Management | **UPDATE**: In SmartConsole and Management API, Access and NAT Policies now support Rule Base search for hitcount values. |
| PRJ-62283,<br>PMTR-114192 | Security Management | **UPDATE**: Updated the " _show asset_" command output with the correct details for the X7 4-port card (CPAC-4-10/25F-DA model). |
| PRJ-61388,<br>PRHF-39859 | Security Management | **UPDATE**: On Security Management Servers, environment variables set using the _override_server_setting.sh_ script now apply to all processes. Refer to [sk165938](https://support.checkpoint.com/results/sk/sk165938). |
| PRJ-60245,<br>PMTR-110297 | Logging | **UPDATE**: Log Exporter is now delivered as an autoupdatable package, replacing the maintrain-based deployment. This approach shifts from version-based to component-level updates, enabling a more granular and agile update mechanism. Refer to [sk182866](https://support.checkpoint.com/results/sk/sk182866). |
| PRJ-60790 | Logging | **UPDATE**: In SmartConsole > Logs & Monitor > Logs, added information to the "Per Session" logs:<br>- NAT fields<br>  <br>- Dynamic object name<br>  <br>- Updatable object name<br>   <br>  <br>- Network feed object name<br>  <br>- Destination Domain Name field |
| PRJ-59881,<br>PRHF-38023 | Security Gateway | **UPDATE**: Improved processing of ICMP packets in the Security Gateway. |
| PRJ-61680 | Security Gateway | **UPDATE**: Quantum Force 9400 and 9300 appliances with Standalone configuration now run in User Space Firewall (USFW) Mode by default. |
| PRJ-60047,<br>PMTR-110330 | Security Gateway | **UPDATE**: Added an out-of-the-box package for updatable objects that is included with clean installations or Jumbo Accumulator Hotfix Takes (when no other package exists). If the out-of-the-box package is present during policy installation, an update is now initiated in addition to the automatic update. |
| PRJ-61470,<br>PMTR-116355 | VPN | **UPDATE**: Added the "inclusions" feature to the Split Tunnel Remote Access functionality. Refer to the [R82 Remote Access VPN Admin Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RemoteAccessVPN_AdminGuide/Default.htm) \> Dynamic Split Tunneling for SaaS Using Updatable Objects. |
| PRJ-61795,<br>PRHF-40060 | Scalable Platforms | **UPDATE**: The " _fwha_allow_different_corexl_instances_" kernel parameter is now added to prevent cluster members from entering a Down state because of firewall instance count mismatches. |
| PRJ-60352,<br>PMTR-114300 | Diagnostics | An FD (file descriptor) memory leak may occur when creating a new object in SmartConsole. |
| PRJ-60500,<br>PMTR-114274 | Security Management | VPN certificate renewal may generate certificates with 2K key sizes instead of the 3K size specified in Global Properties. |
| PRJ-61469,<br>PRHF-109056 | Security Management | The " _Management rejected fetch for this module - version matching problem_" error is displayed when running the " _fw vsx fetch_" command on an R81.x Scalable Platform (Maestro and Chassis) in VSX mode with an R82 Security Management Server. Refer to [sk183298](https://support.checkpoint.com/results/sk/sk183298). |
| PRJ-61359,<br>PRHF-39806 | Security Management | In some scenarios, a cluster object may not be listed in the "Uninstall Threat Prevention Policy" window. |
| PRJ-61318,<br>PRHF-39827 | Security Management | Fetching branches from an LDAP Server fails with " _Failed to connect to LDAP Server. Please ensure that the administrator's credentials are correct and try again_" when the LDAP Server does not support anonymous bind (when a client connects to an LDAP server without providing any credentials).<br>To enable the ability, refer to [sk183461](https://support.checkpoint.com/results/sk/sk183461). |
| PRJ-61477,<br>PRHF-40016 | Security Management | In rare scenarios, the CPRLIC process may exit with core files generated to the _/var/log/dump/usermode/_ directory on the Security Management Server. |
| PRJ-60470,<br>PRHF-38859 | Security Management | Deleting a user that is used in a user group with more than 1000 users may cause SmartConsole to time out. |
| PRJ-60433,<br>PRHF-38563 | Security Management | Virtual System routes and interfaces may not be synchronized to the Standby Security Management Servers. |
| PRJ-59100,<br>PRHF-33411 | Security Management | In some scenarios, when exporting the Gateways and Servers View to CSV, the resulting file may contain an extra empty column.<br>Refer to [sk182233](https://support.checkpoint.com/results/sk/sk182233). |
| PRJ-60961,<br>PRHF-38808 | Security Management | In rare scenarios, in multi-site Multi-Domain Security Management environments, operations across two or more Servers, such as Global Domain Assignment, IPS and Application Control update may fail. |
| PRJ-58352,<br>PRHF-37197 | Security Management | In some scenarios, policy installation fails with the " _/opt/<xxxxx>-R81.20/conf/Policy-name.pf" line N: ERROR: syntax error Error compiling IPv6 flavor. Operation ended with errors." |
| PRJ-60699,<br>PRHF-39297 | Security Management | The Management API command " _set simple-gateway name 'XXX' usercheck-portal-settings.enabled {false|true}_" fails to properly enable or disable User Check for Security Gateway objects. When running this command, the change is not applied to the Security Gateway configuration, and the "Enable UserCheck for active blades" setting in SmartConsole remains unchanged. |
| PRJ-61043,<br>PRHF-39465 | Security Management | In rare scenarios, accelerated policy installation fails to initialize, the full Access Control Policy installation is executed instead and it may take up to 20 minutes. |
| PRJ-56522,<br>PRHF-35230 | Security Management | In rare scenarios, the first packet of a connection is incorrectly dropped when a non-FQDN object is used in the Rule Base. |
| PRJ-58202,<br>PRHF-34401 | Security Management | The " _vsx-run-operation_" Management API command may fail on the Multi-Domain Security Management Server. Refer to [sk182524](https://support.checkpoint.com/results/sk/sk182524). |
| PRJ-60762,<br>PRHF-39098 | Security Management | In rare scenarios, after deleting Data Center objects:<br>- Login to the Security Management Server may fail with timeout.<br>  <br>- Publish operations may take a long time. |
| PRJ-57975,<br>PRHF-36695 | Security Management | In some scenarios, the Postgres database on the Standby Security Management Server is growing after every High Availability synchronization. Refer to [sk182868](https://support.checkpoint.com/results/sk/sk182868). |
| PRJ-61585,<br>PRHF-37905 | Security Management | Access Control policy installation may take a long time when updatable objects are used in the policy. |
| PRJ-59370,<br>PMTR-110008 | Security Management | The " _show lsm-gateway_" and _"show lsm-gateways_" Management API commands may return an empty "version" field. |
| PRJ-60013,<br>PMTR-114030 | Security Management | In rare scenarios, policy installation may get stuck at 99%. |
| PRJ-59625,<br>PRHF-38414 | Multi-Domain Security Management | In rare scenarios, Domain creation fails with " _Failed to create Domain server '<Domain Server Name>'. The connected administrator has no permission to create a Domain-Server on the specified Domain_". |
| PRJ-60660,<br>PMTR-114305 | SmartProvisioning | In SmartProvisioning application:<br>- Performing "push policy" on a Gaia LSM Cluster fails with the " _local failure of CPRID_" error. <br>  <br>- The "Get Gateway Data" operation fails with " _Execution error Error: Unspecified error_".<br>  <br>- The " _cphaprob stat_" command returns a core dump file. |
| PRJ-61987,<br>PMTR-116260 | CPView | CPView history may be corrupted. |
| PRJ-61489,<br>PRHF-39983 | Security Gateway | In a rare scenario, the FWK process may restart unexpectedly. |
| PRJ-60129,<br>PRHF-38666 | Security Gateway | When the Mirror and Decrypt feature is enabled, the SKB memory leak may occur. |
| PRJ-60126,<br>PRHF-38574 | Security Gateway | When Mirror and Decrypt features are enabled, the Security Gateway may experience unexpected reboots. The crashes are caused by " _put_cred_rcu()_" errors with negative usage values and memory leaks in the ARP cache. |
| PRJ-60949,<br>PRHF-39471 | Security Gateway | In a rare scenario, the CPD daemon may exit on the Security Gateway. |
| PRJ-61309,<br>PMTR-115595,<br>HEC-371 | Security Gateway | ElasticXL members communicating with the pivot cluster member may transition to DOWN state when synchronization between the pivot and other members is lost. Refer to [sk183434](https://support.checkpoint.com/results/sk/sk183434). |
| PRJ-60579,<br>PRHF-38995 | Security Gateway | In rare cases, failovers may occur because the FWK process unexpectedly exits. |
| PRJ-59157,<br>PRHF-37774 | Security Gateway | Security Gateways with default MDPS task settings using proxy can fetch CPUSE updates and licenses successfully. On MPLANE updatable objects are not updated while everything works on DPLANE. |
| PRJ-61449,<br>PRHF-39840 | Security Gateway | When handling interface statistics, the CPD or FWK processes may unexpectedly restart with an error related to IOCTL printed in logs. Refer to [sk183544](https://support.checkpoint.com/results/sk/sk183544). |
| PRJ-60455,<br>PMTR-114419 | Security Gateway | Enabling debugging in Quick UDP Internet Connections (QUIC) flows may cause an FWK process crash. |
| PRJ-62174,<br>PRJ-59649 | Security Gateway | In rare scenarios, the FWK process may unexpectedly exit when stopping the Security Gateway using the " _cpstop_" command while a packet capture tool is running. |
| PRJ-60669,<br>PMTR-114653 | Security Gateway | In rare scenarios, downloading large files over HTTPS may get stuck. |
| PRJ-60427,<br>PMTR-114342 | Security Gateway | In rare scenarios, the FWK process may unexpectedly exit when the IPS Software Blade logs triggered protections. |
| PRJ-60539,<br>PRHF-38647 | Security Gateway | In a rare scenario, after an upgrade, the Security Gateway may crash with a vmcore. |
| PRJ-59895,<br>PRHF-38438 | Security Gateway | The VSX Security Gateway may crash when an external interface connected to the Virtual Router or Virtual Switch starts flapping. |
| PRJ-60446,<br>PRHF-38975 | Security Gateway | RADIUS authentication fails when a response packet contains the Message-Authenticator attribute. Refer to [sk183244](https://support.checkpoint.com/results/sk/sk183244). |
| PRJ-60216,<br>PRHF-34528 | Threat Prevention | In some scenarios, external IoC feeds are not correctly fetched in VSX environments after a reboot. |
| PRJ-57978,<br>PRHF-36739 | Threat Extraction | In a rare scenario, a script related to CPView may take a long time to execute and the SCRUBD process becomes unresponsive. |
| PRJ-58005,<br>PRHF-36322 | Anti-Virus | In rare scenarios, Security Gateways with the Content Awareness Software Blade enabled may fail to properly process certain .zip file formats, resulting in " _Failed to process files_" errors during the Anti-Virus inspection. |
| PRJ-59857,<br>PRHF-38565 | Anti-Virus | In some failure scenarios, the Anti-Virus Software Blade does not report the failure in a SmartConsole log. |
| PRJ-60663,<br>PMTR-114734 | Anti-Bot | In rare scenarios, the RAD process may unexpectedly exit. |
| PRJ-60616,<br>PRHF-39184 | Mobile Access | The Mobile Access Portal hosted on a Security Gateway R81.20 or lower becomes unresponsive, and CVPND core files are generated after the Security Management Server is upgraded to version R82. |
| PRJ-60700,<br>PMTR-108872 | SSL Inspection | The "HTTPS Inspection Statistics" view in Demo Mode of SmartView in SmartConsole shows " No data found". The issue is cosmetic only. |
| PRJ-59766,<br>PRHF-38539 | ClusterXL | If both bond subordinate interfaces are down, the output of " _cphaprob show_bond bond_" command is corrupted. |
| PRJ-60780,<br>PMTR-110618 | ClusterXL | The ROUTED daemon may incorrectly initialize as Subordinate rather than Master after a " _cpstop;cpstart_" command when executed on the sole Active member in a cluster configuration. |
| PRJ-58336,<br>PRHF-36801 | ClusterXL | A Multi-Version Cluster (MVC) member with VPN enabled may crash when performing an upgrade from R80.40. |
| PRJ-59213,<br>HEC-1195 | ClusterXL | In High Availability Bridge Mode ClusterXL environments, the management interface of a Standby member becomes inaccessible. Refer to [sk183124](https://support.checkpoint.com/results/sk/sk183124). |
| PRJ-57369,<br>PRHF-36165 | ClusterXL | In VSX environments, deleting a Virtual System interface through SmartConsole fails to remove certain bindings, causing the interface to be automatically re-added. |
| PRJ-60378,<br>PMTR-114234 | SecureXL | When printing the Deny list on a Security Gateway during Threat Prevention policy installation after deleting a large IoC feed from Security Management, an uninformative IOCTL error is displayed instead of a proper error message. The issue is cosmetic only. |
| PRJ-61467,<br>PMTR-111760 | SecureXL | The USIM process to exit during error logging. |
| PRJ-60592,<br>PMTR-113834 | SecureXL | In a rare scenario, no traffic is passed in the 6in4 tunnel and the two hosts cannot reach each other. The output for the " _tcpdump_" command in the tunnel shows " _ip: unknown ip 0_". |
| PRJ-61966,<br>PRJ-61915 | SecureXL | The USIM process may crash during route updates when the Hardware Acceleration offloading connection is active. |
| PRJ-61021,<br>PMTR-115089 | SecureXL | In rare scenarios, when SecureXL works in User Mode, running the " _reset_gw_" or " _vsx_util reconfigure_" commands may cause the Security Gateway to crash. |
| PRJ-59503,<br>PRHF-38095 | ClusterXL | In rare scenarios, after enabling Bridge Mode, a cluster member may stuck in a boot loop. |
| PRJ-61182,<br>PRHF-39695 | SecureXL | Multicast traffic is dropped when the Packet-Broker operates in Monitor Mode with Promiscuous Mode disabled. |
| PRJ-60722,<br>PMTR-114790 | SecureXL | The Security Gateway may crash when connected to the Smart-1 Cloud Management Server and a maas_tunnel interface is repeatedly added and deleted. |
| PRJ-60999,<br>PMTR-115074 | SecureXL | After MTU for Jumbo Frames is configured on a physical interface for the first time, until the Security Gateway is rebooted, there may be potential packet drops. |
| PRJ-59988,<br>PRHF-38501 | Gaia OS | Multiple SNMP OIDs return incorrect data types. Refer to [sk183166](https://support.checkpoint.com/results/sk/sk183166). |
| PRJ-62065,<br>PRHF-40577 | Gaia OS | Stability issue on Quantum Force appliances 9300 and 9400. Refer to [sk183438](https://support.checkpoint.com/results/sk/sk183438). |
| PRJ-58413,<br>PRHF-37416 | Gaia OS | Exporting logs using the " _backup -l_" command may fail. |
| PRJ-58040,<br>PRHF-36803 | Gaia OS | SNMP OID .1.3.6.1.4.1.2620.1.6.7.5.1.5.X falsely reports high CPU due to malformed calculation. Refer to [sk182784](https://support.checkpoint.com/results/sk/sk182784). |
| PRJ-59922,<br>PRHF-38669 | Gaia OS | In rare scenarios, users may be disconnected from SmartConsole, and an FWM process core dump is generated. |
| PRJ-60162,<br>PRHF-38736 | Routing | The ROUTED daemon core dump file may be generated because of an assertion failure in the OSPF code. |
| PRJ-61331,<br>PMTR-115613 | Routing | When working in User Mode (UPPAK), SecureXL may crash when multiple SND cores perform simultaneous next hop lookup for the same next hop. |
| PRJ-60813,<br>PMTR-114871 | Routing | In a rare scenario, a Security Gateway crash and temporary loss of routing adjacency occur when the cluster messaging system attempts to process a deletion request for a BFD session that no longer exists. |
| PRJ-59742,<br>PRHF-37444 | Routing | The ROUTED daemon may exit when processing OSPF network updates in a cluster environment. This occurs because of a timing issue in the routing protocol synchronization process. |
| PRJ-61214,<br>PMTR-115308 | Routing | If BFD (Bidirectional Forwarding Detection) timing parameters, such as "min-rx-interval", are modified during an active BFD session deletion process, and a new BFD session is established before the deletion fully completes (deletion typically requires up to 2 hours), the newly created session inherits the previous timing configuration rather than applying the updated timing settings. |
| PRJ-60776,<br>PMTR-114870 | Routing | In some scenarios, the ROUTED daemon may exit with a core dump file. |
| PRJ-60745,<br>PMTR-114835 | Routing | In some scenarios, BGP routing updates may not be processed properly. |
| PRJ-62111,<br>PRHF-40540 | Routing | A memory leak occurs in the ROUTED daemon when CoreXL is running OSPF and handling large numbers of LSAs combined with frequent route flaps. |
| PRJ-58688,<br>PMTR-110631 | Gaia OS | NFS mount does not support hyphen "-". |
| PRJ-59137,<br>PMTR-110490 | Gaia OS | When deleting a bond interface with slaves still attached while maintaining both Gaia Portal and SSH sessions, the deletion succeeds but generates " _unregister_netdevice_" syslog messages and terminates the Gaia Portal session. The issue occurs because local connections to the Gateway cause slow bond interface deletion, leading to Gaia Portal timeout. |
| PRJ-57175,<br>PRHF-36109 | Gaia OS | In rare scenarios, when using IP Aliasing, deleting an interface by IP address reference may incorrectly delete the wrong IP address because of incorrect error handling. |
| PRJ-61371,<br>PMTR-115542 | VPN | In rare scenarios, VPN traffic connectivity may be lost during policy installation. |
| PRJ-58955,<br>PMTR-111093 | VPN | VPN connection may be unstable because of packet fragmentation issues. |
| PRJ-61225,<br>PRHF-39785 | VPN | In a rare scenario, the FWK process may exit during VPN traffic decryption and routing when the PPPoE interface is enabled. |
| PRJ-58320,<br>PRHF-37066 | VSX | Virtual Router advanced routes may be assigned incorrect priorities in policy-based routing configurations. |
| PRJ-58334,<br>PRHF-37228 | VSX | The " _fw stat_" command output may not display the correct policy name for a Virtual System. |
| PRJ-58791,<br>PRJ-37719 | VSX | The " _vsx_util view_vs_conf_" command output may show " _N/A_" for a Gateway when an object in the Domain shares the same name as the Virtual System object. |
| PRJ-57350,<br>PRHF-36278 | VSX | A static route to 0.0.0.0, regardless of the subnet mask, is incorrectly treated as the default route (0.0.0.0/0) and does not appear in the VSX Gateway's routing table. Refer to [sk182742](https://support.checkpoint.com/results/sk/sk182742). |
| PRJ-59033,<br>PMTR-111124,<br>HEC-953 | VSNext | In a large scale VSNext environment, creating over 50 Virtual Systems (VSs) fails. |
| PRJ-60961,<br>PMTR-115016 | SD-WAN | SD-WAN fails to obtain next hop address automatically from the DHCP Server. |
| PRJ-59427,<br>PRHF-38271 | SD-WAN | SD-WAN policy installation may fail during the configuration of MDPS on the Security Gateway. |
| PRJ-60748,<br>PMTR-114442 | SD-WAN | In rare scenarios, SD-WAN policy installation hangs indefinitely. |
| PRJ-58304,<br>PRHF-37070 | Scalable Platforms | In a Maestro environment, migrating a Virtual System between Security Groups may cause a member to crash. |
| PRJ-56586,<br>PRHF-35421 | Scalable Platforms | Connections with fragmented packets drop with the " _Virt Defrag Timeout_" error. Refer to [sk182559](https://support.checkpoint.com/results/sk/sk182559). |
| PRJ-60448,<br>HEC-914 | Scalable Platforms | After a reboot, IPv6 addresses configured on data interfaces disappear from the " _ifconfig_" output when the Same VMAC feature is enabled in SmartConsole. |
| PRJ-59499,<br>FMW-3594 | Scalable Platforms | In rare scenarios, the connection between the Security Gateway (acting as a proxy) and the Security Management Server is not closed correctly. |
| PRJ-60672,<br>PRHF-38834 | Scalable Platforms | Running " _cpstop_" on a specific Virtual System may cause traffic interruption in dual site deployments. |
| PRJ-61502,<br>PRHF-39967 | Scalable Platforms | A cluster member may crash when performing a manual site failover and the deployment is using "Interface Active Check" with IPv6 enabled. |
| PRJ-60052,<br>PRHF-38689 | Scalable Platforms | One member in a Maestro Security Group may be reported as down and inaccessible, the _/var/log/messages_ and _fwk.elg_ logs indicate:<br>- " _State change: ACTIVE -> DOWN | Reason: VSX PNOTE due to problem in Virtual System X_",<br>  <br>- " _used greatest stack depth: 9544 bytes left_",<br>  <br>- Errors related to unknown/invalid parameters and kernel policy copy failures.
