sk181842 - CloudGuard Controller Release Updates
CloudGuard Controller Release Updates
Introduction
CloudGuard Controller manages security in public and on-premises environments with one unified management solution.
The CloudGuard Controller dynamically learns about objects and attributes in Data Centers, such as changes in subnets, security groups, virtual machines, IP addresses and tags.
After using the vendor’s API to establish a trust relationship with a Data Center, CloudGuard Controller regularly checks the connected environments for changes in objects and object attributes used in the Security Policy and automatically push the changes to the Security Gateway.
202511030923001.png)
The CloudGuard Controller package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see sk175504, section 2-B).
If Automatic Updates are disabled, you must first manually install the latest AutoUpdater Take and then install CloudGuard Controller package manually using the steps below.
Prerequisites
CloudGuard Controller self-updatable package requires Jumbo Hotfix Accumulator installed with the minimum version:
| Version | Required |
| R82 and higher | No requirements |
| R81.20 | R81.20 Jumbo Hotfix Accumulator Take 99 or higher |
Manual Installation (Offline)
Transfer the offline package to the CloudGuard Controller server.
Connect to the command line on the CloudGuard Controller server.
Log in to the Expert mode.
Install the offline package:
autoupdatercli install <full path to the .tar file>Example:
autoupdatercli install /home/admin/Check_Point_CloudGuard_Controller_R81_20_AutoUpdate_T7_AutoUpdate.tarMake sure the installation completed successfully:
Examine this log file:
/opt/CPInstLog/AutoUpdateLogs/CloudGuard_ControllerRun:
cpinfo -y CPUpdates 2>&1 | grep CLOUDGUARD_CONTROLLERThe take number in the output must be the Take that you installed.Note - The installation does not require
cpstop; cpstartor a reboot. Once installed, no further action is required, the update will be applied immediately.Important Notes for Security Management / Multi-Domain Security Server (MDS) in the High Availability mode:
We recommend installing the CloudGuard Controller package on all servers in the Management High Availability environment in the same session - one after the other, so that all servers use the same package Take.
At the end of the installation, we recommend to make sure that all servers in the Management High Availability environment use the same package Take. Run this command on each server with CloudGuard Controller package installed:
cpinfo -y CPUpdates 2>&1 | grep CLOUDGUARD_CONTROLLER
Availability
| Version | Release | Take | Release Date | Download |
| R82.10 | Recommended | 9 | 07 Jun 2026 | (TAR) |
| R82 | Recommended | 32 | 07 Jun 2026 | (TAR) |
| R81.20 | Recommended | 37 | 26 Apr 2026 | (TAR) |
| R82.10 | Latest | 10 | 19 Jul 2026 | (TAR) |
| R82 | Latest | 33 | 19 Jul 2026 | (TAR) |
| R81.20 | Latest | 38 | 19 Jul 2026 | (TAR) |
Documentation
List of Resolved Issues and New Features per CloudGuard Controller Update
R82.10 Release
| ID | Description |
| Take 10 - Gradual deployment from 19 Jul 2026 | |
| CGNSIS-2375 | In rare scenarios, Cisco ACI Data Center scans may receive an empty response from the Cisco APIC, causing Data Center objects to be temporarily removed. |
| CGNSIS-2136 | Enhancement: CloudGuard Controller now supports the Nozomi, ServiceNow CMDB and Akamai Guardicore Data Centers. Refer to the R82 CloudGuard Controller Administration Guide. |
| CGNSIS-960 | Added CloudGuard Controller integration with AIOps in Check Point Portal to provide centralized visibility of CloudGuard Controller alerts. |
| CGNSIS-2049, CGNSIS-2094, CGNSIS-758 |
Additional improvements. |
| Take 9 - Gradual deployment from 07 Jun 2026 | |
| CGNSIS-1907 | Enhancement: CloudGuard Controller now supports the Claroty Continuous Threat Detection (CTD) Data Center. |
| CGNSIS-1729 | Minor fix. |
| Take 8 - Gradual deployment from 26 Apr 2026 | |
| VSECC-3008 | Enhancement: Added support for new IoT tags for third-party vendor discovery. |
| CGNSIS-1242 | Memory issue is caused when the VPN Cloud monitor (VCM) feature is disabled in Azure Data Centers. |
| CGNSIS-1240 | In rare scenarios, the scanner process gets stuck, as a result, the Data Center may not be scanned. |
| CGNSIS-1130 | Minor fix. |
| Take 7 - Gradual deployment from 05 Apr 2026 | |
| CGNSIS-1182 | Enhancement: CloudGuard Controller now supports the Illumio Data Center. Refer to the R82.10 CloudGuard Controller Administration Guide. |
| CGNSIS-968 | Enhancement: Enhanced reliability of vCenter Data Center scanner connections. Refer to sk184856. |
| CGNSIS-535 | Enhancement: Added partial-success support for Google Cloud Platform data center scans, consistent with existing Azure support. When a scan covers multiple GCP projects, and some fail, the successfully scanned projects are now updated instead of the entire scan being blocked. |
| CGNSIS-979 | The cprid_util_debug.sh script fails. |
R82 Release
| ID | Description |
| Take 33 - Gradual deployment from 19 Jul 2026 | |
| CGNSIS-2376 | In rare scenarios, Cisco ACI Data Center scans may receive an empty response from the Cisco APIC, causing Data Center objects to be temporarily removed. |
| CGNSIS-2135 | Enhancement: CloudGuard Controller now supports the Nozomi, ServiceNow CMDB and Akamai Guardicore Data Centers. Refer to the R82 CloudGuard Controller Administration Guide. |
| CGNSIS-1828, CGNSIS-2093 |
Additional improvements. |
| Take 32 - Gradual deployment from 07 Jun 2026 | |
| CGNSIS-1906 | Enhancement: CloudGuard Controller now supports the Claroty Continuous Threat Detection (CTD) Data Center. |
| CGNSIS-1730 | Minor fix. |
| Take 31 - Gradual deployment from 26 Apr 2026 | |
| VSECC-3008 | Enhancement: Added support new IoT tags for third-party vendor discovery. |
| CGNSIS-1241 | Memory issue is caused when the VPN Cloud monitor (VCM) feature is disabled in Azure Data Centers. |
| CGNSIS-1130 | In rare scenarios, the scanner process gets stuck, as a result, the Data Center may not be scanned. |
| CGNSIS-1230 | Minor fix. |
Installation Troubleshooting
These issues can rise when running the installation package:
- Issue 1: "A version of CloudGuard Controller bundle is already installed via AutoUpdater."
Solution: CloudGuard Controller bundle has already been installed for the first time and is configured to receive updates automatically. If you have no Internet access, follow the instructions for "Offline Package Installation Procedure" in the Installation Instructions section above.
- Issue 2: How to return to previous version of CloudGuard Controller package.
Solution: We highly recommend to use the latest take of CloudGuard Controller package. If you still want to revert to the previous Take:
- Connect to the command line on the CloudGuard Controller server.
- Log in to the Expert mode.
- Revert the package to the previous Take:
autoupdatercli revert CloudGuard_ControllerThe revert takes up to 1 minute.- Make sure CloudGuard Controller Bundle was reverted to the previous Take:
- Run:
cpinfo -y CPUpdates 2>&1 | grep CLOUDGUARD_CONTROLLERThe Take number in the output must be the one to which you reverted.- Examine this log file:
/opt/CPInstLog/AutoUpdateLogs/CloudGuard_ControllerNotes:
- CloudGuard Controller package is upgraded automatically each time a new take is released.
- You can safely revert to the previous Take. However, if you attempt to revert to any Take older than the previous one, the CloudGuard Controller server will reset completely to its initial installation state.
- Issue 3: How to totally remove CloudGuard Controller package
Solution:
- Connect to the command line on the CloudGuard Controller server.
- Log in to the Expert mode.
- Remove the package:
autoupdatercli revert-completely CloudGuard_ControllerThe revert takes up to one minute.- Make sure the CloudGuard Controller package was removed:
- Run:
cpinfo -y CPUpdates 2>&1 | grep CLOUDGUARD_CONTROLLER- Examine this log file:
/opt/CPInstLog/AutoUpdateLogs/CloudGuard_Controller
- Issue 4: How to stop receiving future updates of CloudGuard Controller package
Solution:
- Connect to the command line on the CloudGuard Controller server.
- Log in to the Expert mode.
- Run:
autoupdatercli disable CloudGuard_Controller
- Issue 5: R81.10 Management Server does not get the latest CloudGuard Controller package
Symptoms:
- This error shows in the /opt/CPInstLog/Autoupdater.log file:
Problem with local certificate Error code: 10...Abandoned file removed from the system...Failed to download metadata package for component auto_updaterSolution: Refer to sk184474.
For additional troubleshooting instructions, refer to the sk115657 - ATRG: CloudGuard Controller.
If your issue is not resolved by one of the above solutions, contact Check Point Support and attach the /opt/CPInstLog/AutoUpdateLogs/CloudGuard_Controller log file.
Article Properties
Access Level: General
Status: Approved
Date Created: 2023-12-26
Last Modified: 2026-07-19