sk183506 - Check Point Quantum R82.10 Release

Check Point Quantum R82.10 Release

Solution

Click Here to Show the Entire Article

Check Point Recommended version for all deployments is R82 with its Recommended Jumbo Hotfix Accumulator Take. For more info about all Check Point releases, refer to Release map and Release Terminology articles.

## Introduction
Enterprises are rapidly adopting AI to achieve impressive productivity gains. However, AI systems also introduce unprecedented new security challenges. Traditional detection and response frameworks are no longer enough to protect today’s distributed, hybrid mesh networks. It is imperative that enterprises shift left to prevention-first security. R82.10 enables security for the AI transformation, Hybrid Mesh Network, and advanced threats.
R82.10 delivers stronger threat prevention, higher scalability & performance, and greater operational simplicity.
Architectural Updates: R82.10 features an upgraded OS based on Linux kernel 5.14 versus 4.xx in previous releases. This release runs exclusively in UPPAK mode (User Space Performance Pack).
Stronger Threat Prevention
- Threat Prevention Insights: Provides administrators with clear insights into the effectiveness and coverage of Threat Prevention and IPS, featuring visualizations, metrics, and recommendations to refine rules and profiles.
- Advanced Zero Phishing: Zero Phishing Software Blade now protects encrypted traffic from phishing attacks at the domain level - enabling domain analysis by ThreatCloud AI without requiring SSL Inspection or decryption.
- Protection from HTML Smuggling: Zero Phishing Software Blade introduces a powerful new capability to detect and block HTML smuggling, an advanced cyberattack technique that avoids firewall detection by building malware locally within a target's web browser.
- Expanded DNS Protection: Introduces DNS-over-TLS threat prevention to block malicious DNS activity over encrypted channels.
- Hardened Encryption: HTTPS Inspection now supports Hardware Security Module (HSM) for TLS 1.3, making it considerably harder for attackers to compromise encrypted traffic. 
- MCP Detection and Visibility: Introduces MCP (Model Context Protocol) detection and visibility to ensure that only authorized MCP communications are allowed across the network.
- Enhanced Drop Templates: New drop templates improve resilience by reducing CPU

usage to enable blocking a much higher volume of denial of service (DoS) attacks while

maintaining maximum throughput for permitted traffic.
- 4 New ThreatCloud AI Engines: PDF security with advanced image and text analysis, malicious GitHub-hosted account and repository detection, automatic creation of file and IPS protection rules, and a new web security model with enhanced decision-making capabilities.
- Adaptive IPS: A new optimized IPS defense profile is tailored to fit an organization’s

exact requirements. This enables IPS to be turned on with minimal CPU performance

impact, for improved resiliency and threat detection. 
Scalability & Performance
- **Scalable Identity Management:**Improved identity awareness across the enterprise for unified policy enforcement and scalable identity sharing.

- Each Policy Decision Point (PDP) can now manage up to 1M identities, reducing the number of required PDPs by up to 5X.
- A single PDP can share identities with up to 300 Policy Enforcement Point (PEP) gateways, even across multiple domains.
- Direct PDP to PEP sharing works across Multi-Domain Security Management without an Identity Broker, simplifying configuration.
- Support for SD-WAN in Maestro Security Groups: Enables higher scalability in branch office networks while providing the highest system reliability and redundancy.
- Quantum Security Management Scalability: Increases the maximum number of managed Security Gateways to 1,500 per management domain. Users can further scale to 10,000 gateways in a Multi-Domain Security Management Server configuration.
Operational Simplicity
- Centralized Identity Management: Infinity Identity is a cloud service that integrates with Quantum network security, provides the option of integrating with multiple identity providers, and eliminates the need for separate management portals. It integrates endpoint device and device security posture data from Microsoft Intune, Microsoft Defender, CrowdStrike Falcon, Harmony Endpoint, and more for consistent and unified zero-trust access control.
- New Access Policy Log Generation Modes: New logging mode enables streamlined control over daily log output, with improved granularity into log levels and analytics on high-volume rules. The Aggregated mode greatly reduces daily log volume by up to 70%, reducing storage needs accordingly.
- Simplified Route-Based VPN: Automatically configures Site to Site VPN based on network topology, enabling one-click setup and dynamic routing with BGP.
- Enhanced Web-based UI: New web-based UI allows users to manage common security use cases from the web for more flexibility.
Effective March 31, 2026, the GA version was updated to Take 467, which includes the certificates and CRL fix ( sk184766).
## What's New in R82.10
Threat Prevention
> ### Threat Prevention Insights
>
> - Provides clear insight into Threat Prevention and IPS effectiveness and coverage, with visualizations, metrics, and recommendations to refine policy and profiles. A tuned policy enhances coverage, reduces noise, and maintains Security Gateway performance predictable and manageable.
>
>
>
> Key Features:
>
>
>
>
> - Misconfigurations & Optimizations:
> - Detects misconfigured IPS profile for example, disabled protections, conflicting exceptions, and outdated profiles).
> - Surfaces overly permissive settings and hitless items, with guidance to remediate safely.
> - Prioritizes changes by security impact and performance benefit
> - IPS Profile Tuning:
> - Highlights noisy signatures, false-positive candidates, and protections generating excessive logs.
> - Suggests severity-aware tuning (move to Detect/Prevent, adjust performance impact, add targeted exceptions) to cut noise while preserving critical coverage.
>
> ### Zero Phishing
>
> - Zero Phishing Software Blade provides prevention for customers without HTTPS
>
> Inspection, utilizing Server Name Indication (SNI) in TLS handshake.
> - Zero Phishing Software Blade introduces a powerful new capability to detect and block HTML Smuggling, a technique used by threat actors to bypass traditional Network Threat Prevention systems.
>
> ### ThreatCloud AI Engines
>
> - Threat Emulation PDF Engine The updated PDF engines combine advanced image and text analysis. 
> - Image analysis: QR code extraction, page-layout parsing, brand misuse detection resilient to adversarial obfuscation, and adult-content heuristics.
> - Text analysis: an SLM (Small Language Model) flags social-engineering patterns in forms, lures, and conversational tone.
> - Brand detection: adversarial image obfuscation techniques.
> - GitHub Abuse Engine - Designed to detect malicious GitHub-hosted accounts and repositories used for credential theft and drive-by malware downloads. The engine uses advanced algorithms and AI to analyze user behavior, repository structure, key files, and JavaScript content through deep code inspection.
> - AI Web Security (New model)- The latest version of the AI web security engine features enhanced decision-making capabilities across web traffic by combining DNS metadata, certificate attributes, and behavioral signals.
> - Generative AI Protections Engine - Automates the creation of File and IPS protection rules by processing open-source intelligence and ThreatCloud traffic. It generates protection rules automatically, eliminating manual effort and accelerating the protection delivery. By reducing analysis time from days to hours, it enhances threat response and expands coverage with minimal human intervention.
>
> ### DNS Security
>
> - Introducing DoT (DNS over TLS) - Threat Prevention capabilities for malicious DNS activity over the TLS protocol.
>
> ### HTTPS Inspection
>
> - Added support for the hybrid PQC-safe key exchange group "X25519MLKEM768" (combining X25519 and ML-KEM768 algorithms) within HTTPS Inspection.
> - HTTPS Inspection now supports Hardware Security Module (HSM) integration for TLS 1.3, ensuring secure storage and management of private keys during encrypted traffic inspection.
> - Rule Base Hit Count is now available for HTTPS Inspection policies, improving visibility and administrative control.
>
> ### IPS
>
> - New capability that automatically detects and remediates CPU-intensive IPS protections with a dedicated SmartView dashboard displaying IPS bypass statistics and CPU-intensive protection insights.
* *
    Quantum Security Gateway
> ### Identity Awareness
>
> - Introducing Scalable Identity Sharing that allows more flexible and efficient identity distribution with two major enhancements:
>
> - Scalable Identity management: A single Policy Decision Point (PDP) gateway can now distribute identities to up to 300 Policy Enforcement Point (PEP) gateways, significantly improving scalability and performance.
> - Cross-Management Domain Support: Identities can now be seamlessly shared across multiple Domain Management Servers (CMAs), enabling unified and consistent identity-based policy enforcement throughout large and distributed environments.
> - Improved PDP Performance - Policy Decision Point (PDP) gateways can now handle up to 1 million identities each, leveraging a new multi-process architecture that optimizes hardware utilization and boosts overall performance.
> - Quantum Security Gateway integration with Infinity Identity - Seamless integration with Infinity Identity, delivering centralized and unified Identity Awareness policy enforcement throughout the entire network infrastructure, and supports new identity integrations such as Microsoft Intune, Microsoft Defender, and Harmony Endpoint.
>
> ### URL Filtering
>
> - The URL Filtering Software Blade now supports automatic categorization of websites listed in the "Terrorism" category of the CTIRU (Counter-Terrorism Internet Referral Unit) list.
>
> ### Site to Site VPN
>
> - Added support for standard ML-KEM as required by the FIPS 203 standard to address Post-Quantum Cryptography (PQC). See sk184080 - Post-Quantum Cryptography (PQC) algorithms in R82.10 and higher.
> - Simplified Route-based VPN - Automatically configures route-based VPNs on Check Point Security Gateways based on network topology, providing easy, one-click setup and saving configuration time. It also includes support for dynamic routing using BGP.
>
> ### SD-WAN
>
> - Added support for SD-WAN in Maestro Security Groups. See sk180605 - Quantum SD-WAN.
>
> ### Security Gateway Enhancement
>
> - New MCP Detection and Visibility feature designed to monitor and manage Model Context Protocol (MCP) traffic within your network. You can now instantly access detailed information about MCP traffic, including server names, versions, and tools in use.
>
> In addition to enhanced visibility, this feature empowers you to accept or drop MCP connections based on your organization's security policies. This gives you greater control over your network traffic and helps ensure only authorized MCP communications are allowed.
> - Redesigned the Drop Optimization feature in Access Control policy. The new design supports more acceleration use cases, such as rules with Dynamic Objects and future offloads the traffic to ASIC-powered network cards. See sk184356 - Firewall Drop Optimization in R82.10 and higher. 
>
> ### Dynamic Routing
>
> Added support for these Dynamic Routing features: 
>
> - Support for up to 256 PIM interfaces, which allows greater flexibility and scalability in network configurations.
> - Support for up to 500 BGP peers, ensuring robust and efficient routing capabilities.
> - Support for BGP Large Communities, which provides enhanced control and management of routing policies across multiple networks.
>
> ### Cluster and Scalability
>
> - The ElasticXL clustering and Maestro Security Group now support SecureXL in the User Mode (UPPAK).
>
> ### Internal CA
>
> - Increased RSA Key Size for Internal CA – The default RSA key size for the Root CA has been increased from 2048 bits to 3072 bits, enhancing cryptographic security for Internal CA, SIC, Site to Site VPN, Remote Access VPN clients, user certificates, and MultiPortal certificates.
> - In the clean installation, this is the default.
> - In the upgraded installation, this is the new default if you remove the current Internal CA and create the new Internal CA.
>
> ### Gaia OS Security
>
> - In Gaia Clish, you can configure the number of hashing rounds for new passwords.
>
> Hashing rounds determine the number of iterations a hashing algorithm performs on a password before storing it. This process is used to enhance security by making it more computationally expensive for attackers to crack passwords through brute force attacks.
> - Added the Bcrypt hash for password encryption of local users in the Gaia OS.
> - External RADIUS authentication servers can now be configured to use CHAP (Challenge-Handshake Authentication Protocol) or PAP (Password Authentication Protocol).
*
    Quantum Security Management
> ### Logging and Monitoring
>
> - New Access Policy Log Generation Modes: Standard and Aggregated. The Aggregated mode significantly reduces the daily log volume.
> - The Log Forwarding feature is now easier to use. It now forwards locally stored logs to the primary Log Server without requiring a specific Log Server to be selected. The feature is enabled by default for new Gateways, making sure that locally stored logs will automatically upload to the Log Server.
> - Additional logging enhancements in SmartConsole:
> - View the rules log level by hovering over the Track column in the Access Control rule.
> - Added the ability to customize the default Track value for new Access Control rules.
> - Enhanced the session log content with additional fields, including NAT details.
> - Introducing the per-session log level control for Implied Rules.
>
> ### Compliance
>
> - Added support for new regulations:
> - CSA CCoP 2.0
> - DORA 2023
> - ISO 27002 2022
> - NIST800-82r3
> - Added new Management API commands for initiating new scans, showing Best Practices data, Compliance settings, and more.
> - Update existing Best Practices for Firewall, IPS, Anti-Bot, and VPN Software Blades.
* *
    Cloud Firewall (formerly CloudGuard Network)
> ### CloudGuard Controller
>
> - New CloudGuard Controller scanner for Proxmox Virtual Environment data center.
---
## Documentation

Release Notes
View
Quantum Security Management / Security Gateway Quantum Security Gateway
R82.10 Installation and Upgrade Guide R82.10 Quantum Security Gateway Guide
R82.10 Carrier Security Administration Guide R82.10 ClusterXL Administration Guide
R82.10 CLI Reference Guide R82.10 Threat Prevention Administration Guide
R82.10 Gaia Administration Guide R82.10 Data Loss Prevention Administration Guide
Quantum Security Management R82.10 Gaia Advanced Routing Administration Guide
R82.10 Quantum Security Management Administration Guide R82.10 Identity Awareness Administration Guide
R82.10 Multi-Domain Security Management Admin Guide R82.10 Performance Tuning Administration Guide
R82.10 SmartProvisioning Administration Guide R82.10 QoS Administration Guide
R82.10 CloudGuard Controller Administration Guide R82.10 Remote Access VPN Administration Guide
Cloud Management Extension (CME) Administration Guide R82.10 Mobile Access Administration Guide
R82.10 Logging and Monitoring Administration Guide R82.10 Site to Site VPN Administration Guide
Harmony Endpoint SSL Network Extender (SNX) Administration Guide
R82.10 Harmony Endpoint Web Management Admin Guide R82.10 VoIP Administration Guide
R82.10 Harmony Endpoint Server Administration Guide R82.10 VSX Administration Guide
SmartConsole Scalable Platforms
R82.10 SmartConsole Help R82.10 Scalable Platforms Administration Guide
Quantum Maestro Getting Started Guide
## Downloads and Installation
--- ---
Check Point R82.10 including Jumbo Hotfix Accumulator R82.10 + Jumbo Take 24
R82.10 SmartConsole Release Build 424
Upgrading Quantum Security Management and Multi-Domain Security Management
> If your Security Management Server / Multi-Domain Security Management is connected to the Internet (the common case):
>
> > 1. Connect to Gaia Portal.
> > 2. In the left navigation tree, click Software Updates > Available Updates.
> > 3. Expand the section Major Versions.
> > 4. In the applicable row, click Upgrade.
>
> If your Security Management Server / Multi-Domain Security Management is not connected to the Internet, click to see instructions:
>
> > 1. Download and install the latest Upgrade Tools package and Gaia Deployment Agent (CPUSE).
> > 2. Download the Fast Deployment Package (TGZ)
> >
> >
> > Note: On Multi-Domain Security Management, upgrade using Fast Deployment is supported starting from R81.10.
> >
> >
> >
> > OR
> >
> >
> >
> > Download the CPUSE Offline Upgrade Package (TAR)
> >
> >
> >
> >
> >
> > 3. Connect to Gaia Portal.
> > 4. In the left navigation tree, click Software Updates > Available Updates.
> > 5. Import the Fast Deployment or the CPUSE Offline Package.
> > 6. Expand the section Major Versions.
> > 7. In the applicable row, click Upgrade.
>
> For more information and other upgrade methods, see the R82.10 Installation and Upgrade Guide.
* * *
Upgrading Quantum Security Gateway
> Best Practice:
>
> > Use Central Deployment in SmartConsole to upgrade one or more Security Gateways:
> >
> > SmartConsole > Gateways & Servers > right-click a Security Gateway or Cluster object > click Actions
> >
> > For more information, see the R82.10 Security Management Administration Guide - Chapter "Managing Gateways" > Section "Central Deployment of Hotfixes and Version Upgrades".
>
> If your Security Gateway is connected to the Internet (the common case):
>
> > 1. Connect to Gaia Portal.
> > 2. In the left navigation tree, click Software Updates > Available Updates.
> > 3. Expand the section Major Versions.
> > 4. In the applicable row, click Upgrade.
>
> For large scale fully automated Security Gateway upgrade using CDT, click to see instructions:
>
> > Upgrade your Security Gateway using Central Deployment Tool (CDT).
>
> > Central Deployment Tool (CDT) is a utility that lets you manage a deployment of software packages from your Management Server to the multiple managed Security Gateways and cluster members at the same time.
>
> * This upgrade method is not supported on Check Point Firewall 3900 Appliances
>
> If your Security Gateway is not connected to the Internet, click to see instructions:
>
> > 1. Download the Fast Deployment Package (TGZ)
> >
> >
> >
> >
> > OR
> >
> >
> >
> > Download the CPUSE Offline Upgrade package (TAR)
> >
> >
> >
> >
> >
> > 2. Connect to Gaia Portal.
> > 3. In the left navigation tree, click Software Updates > Available Updates.
> > 4. Import the downloaded Fast Deployment or the CPUSE Offline Package.
> > 5. Expand the section Major Versions.
> > 6. In the applicable row, click Upgrade.
>
> For Check Point Firewall 3900 Appliances, click to see instructions:
>
> > 1. Install the Hotfix for Check Point Firewall 3900 Appliances Take 22.
> > 2. Download the Fast Deployment Package (TGZ)
> >
> >
> >
> > OR
> >
> >
> > Download the CPUSE Offline Upgrade Package (TAR)
> >
> >
> >
> >
> >
> > 3. Connect to Gaia Portal.
> > 4. In the left navigation tree, click Software Updates > Available Updates.
> > 5. Import the downloaded Fast Deployment or the CPUSE Offline Package.
> > 6. Expand the section Major Versions.
> > 7. In the applicable row, click Upgrade.
>
> For more information and other upgrade methods, see the R82.10 Installation and Upgrade Guide.
* * *
Clean Install of Security Gateway and Management Server
> Effective March 31, 2026, the GA version was updated to Take 467, which includes the certificates and CRL fix ( sk184766).
>
> For Security Gateway, Security Management, or Multi-Domain Management Server
>
> > 1. Download the Fast Deployment Package (TGZ):
> >
> >
> >
> >
> >
> > OR
> >
> >
> >
> > Download this CPUSE Offline Upgrade Package (TAR):
> >
> >
> >
> > 2. Connect to Gaia Portal.
> > 3. In the left navigation tree, click Software Updates > Available Updates.
> > 4. Import the downloaded Fast Deployment or the CPUSE Offline Package.
> > 5. Expand the section Major Versions.
> > 6. Click the three dots on the right and select Clean Install.
>
> If you use Bootable USB device:
>
> > 1. Download the Gaia OS Clean Install ISO file:
> >
> >
> > 2. See sk65205 to create a bootable USB device.
> >
> > 3. Run the Gaia First Time Configuration Wizard.
>
> > For more information, see the R82.10 Installation and Upgrade Guide.
>
> For Check Point Firewall 3900 Appliances
>
> > Effective March 31, 2026, the GA version was updated to Take 467, which includes the certificates and CRL fix ( sk184766).
> >
> > 1. Download the Fast Deployment Package (TGZ)
> >
> >
> >
> > OR
> >
> > Download this Offline Upgrade Package (TAR):
> >
> >
> >
> > 2. Connect to Gaia Portal.
> > 3. In the left navigation tree, click Software Updates > Available Updates.
> > 4. Import the downloaded Fast Deployment or the CPUSE Offline Package.
> > 5. Expand the section Major Versions.
> > 6. Click the three dots on the right and select Clean Install.
> >
> > If you use Bootable USB device on Check Point Firewall 3900 Appliances:
> >
> > 1. Download the Gaia OS Clean Install ISO file:
> >
> >
> > 2. See sk65205 to create a bootable USB device.
> >
> > 3. Run the Gaia First Time Configuration Wizard.
>
> > For more information, see the R82.10 Installation and Upgrade Guide.
* * *
ElasticXL and Quantum Maestro 
> Important: Scalable Chassis 44000 / 64000 do not support R82.10
>
> To upgrade your Maestro Orchestrator from R82:
>
> 1. Connect to Gaia Portal.
> 2. In the left navigation tree, click Software Updates > Available Updates
> 3. Expand the section Major Versions.
> 4. In the applicable row, click Upgrade.
>
> To upgrade ElasticXL, Maestro Security Groups and Maestro Orchestrator from R81.10, R81.20, or R82:
>
> 1. Install the required Jumbo Hotfix Accumulator:
> - On R82 for Scalable Platforms - install the R82 Jumbo Hotfix Accumulator Take 60 or higher
> - On R81.20 for Scalable Platforms - install the R81.20 Jumbo Hotfix Accumulator Take 120 or higher
> - On R81.10 for Scalable Platforms - install the R81.10 Jumbo Hotfix Accumulator Take 183 or higher
> 2. Install the CPUSE Deployment Agent 2691 or higher from sk92449.
>
> 3. Download and import this Offline Upgrade Package (TAR):
>
>
>
>
> For more information and other upgrade options, see R82.10 Scalable Platforms Administration Guide.
>
>
> Clean install
>
> - Download and import this Installation Image (ISO):
>
>
>
>
>
>
>
> For more information and other upgrade options, see the R82.10 Scalable Platforms Administration Guide.
* * *
Cloud Firewall (formerly CloudGuard Network)

Deploying Cloud Firewall Gateway

Deployment Options

Platform Type Deployment
AWS (Amazon Web Services) Marketplace (CloudFormation) / Terraform
Microsoft Azure Marketplace / vWAN / Terraform
GCP (Google Cloud Platform) Marketplace / Terraform Registry
OCI (Oracle Cloud Infrastructure) CloudGuard Network Security for Oracle Cloud Infrastructure
Private Cloud VMware ESXi, KVM, OpenStack, Nutanix AHV
VMware Terraform templates
Nutanix Terraform templates

For the list of all CloudGuard Network Registry Modules, see sk183294.

Upgrading Cloud Firewall Gateway

  1. Download the relevant Fast Deployment Package from sk177714 - In-Place Upgrade packages for Cloud Firewall.
  2. Import it into the SmartConsole package repository.
  3. Right-click the Fast Deployment Package and click Upgrade.
## Additional Downloads and Products
Show / Hide
Product Download
Fast Deployment Package (Blink) See sk120193
Upgrade Tools package See sk135172
DLP Agent for Exchange Server For Windows (MSI)

Release map | Upgrade and Backward Compatibility maps | Releases Terminology

Check Point CheckMates Community Early Availability (EA) Programs Education and Training
## Revision History
Show / Hide
Date Description
21 Jun 2026 Fast Deployment Package: Security Gateway, Security Management, and Multi-Domain Security Management were updated to Jumbo Take 24.
26 May 2026 Fast Deployment Package: Security Gateway, Security Management, and Multi-Domain Security Management were updated to Jumbo Take 19.
26 May 2026 Updated SmartConsole package to Build 424.
20 Apr 2026 Quantum Force 3900 Appliances have been renamed to Check Point Firewall 3900 Appliances. No functional changes were made.
14 Apr 2026 CloudGuard Network has been renamed to Cloud Firewall. No functional changes were made.
09 Apr 2026 Fast Deployment Package: Security Gateway, Security Management, and Multi-Domain Security Management were updated to Jumbo Take 6.
09 Apr 2026 Added links to R82.10 Jumbo Hotfix Accumulator and R82.10 SmartConsole Releases.
06 Apr 2026 Updated SmartConsole package to Build 422.
31 Mar 2026 GA version was updated to Take 467.
1 Mar 2026 Added CloudGuard Network > Deployment Options for OCI (Oracle Cloud Infrastructure)
21 Jan 2026 Added CloudGuard Network > Deployment Options for Microsoft Azure
08 Jan 2026 - Added CloudGuard Network > Deployment Options for GCP (Google Cloud Platform)
- Updated the upgrade instructions for Maestro Security Groups and Maestro Orchestrator
05 Jan 2026 Added:
- Note that Scalable Chassis 44000 / 64000 do not support R82.10
- CloudGuard Network > Deployment Options for AWS and Private Cloud
29 Dec 2025 First release of this document.

Article Properties

Access LevelGeneral

StatusApproved

Date Created2025-05-28

Last Modified2026-06-21

Was this page helpful?YesNo

Haven't found what you're looking for?

Our customer support team is only a click away and ready to help you 24 hours a day.

Open a Service Request

reCAPTCHA

Recaptcha requires verification.

protected by reCAPTCHA