From 51aa74d4613c8fb9afa609eb31c44abaff868f8d Mon Sep 17 00:00:00 2001 From: Aaron Axvig Date: Thu, 18 Jun 2026 08:30:30 -0500 Subject: [PATCH] Processed new reference files --- .../issues/GlobalProtect/addressed/6.2.1.md | 32 +-- .../issues/GlobalProtect/addressed/6.2.2.md | 2 +- .../issues/GlobalProtect/addressed/6.2.3.md | 4 +- .../issues/GlobalProtect/addressed/6.2.4.md | 2 +- .../issues/GlobalProtect/addressed/6.2.5.md | 2 +- .../issues/GlobalProtect/addressed/6.2.6.md | 12 +- .../issues/GlobalProtect/addressed/6.2.7.md | 45 ++++ .../GlobalProtect/addressed/6.2.8-h11.md | 37 +++ .../GlobalProtect/addressed/6.2.8-h2.md | 9 +- .../GlobalProtect/addressed/6.2.8-h3.md | 12 +- .../GlobalProtect/addressed/6.2.8-h4.md | 10 +- .../GlobalProtect/addressed/6.2.8-h5.md | 8 +- .../GlobalProtect/addressed/6.2.8-h7.md | 2 +- .../issues/GlobalProtect/addressed/6.2.8.md | 7 +- .../issues/GlobalProtect/addressed/6.3.1.md | 8 +- .../issues/GlobalProtect/addressed/6.3.2.md | 12 +- .../GlobalProtect/addressed/6.3.3-h12.md | 89 +++++++ .../issues/PAN-OS/addressed/11.1.10-h27.md | 9 + .../issues/PAN-OS/addressed/11.1.10-h28.md | 142 +++++++++++ .../issues/PAN-OS/addressed/11.1.13-h7.md | 9 + .../issues/PAN-OS/addressed/11.1.13-h8.md | 157 ++++++++++++ .../issues/PAN-OS/addressed/11.1.6-h33.md | 9 + .../issues/PAN-OS/addressed/11.1.6-h34.md | 49 ++++ .../issues/PAN-OS/addressed/11.2.10-h10.md | 79 ++++++ web/data/issues/PAN-OS/addressed/12.1.7.md | 226 ++++++++++++++++++ web/data/products.json | 18 +- 26 files changed, 925 insertions(+), 66 deletions(-) create mode 100644 web/data/issues/GlobalProtect/addressed/6.2.7.md create mode 100644 web/data/issues/GlobalProtect/addressed/6.2.8-h11.md create mode 100644 web/data/issues/GlobalProtect/addressed/6.3.3-h12.md create mode 100644 web/data/issues/PAN-OS/addressed/11.1.10-h27.md create mode 100644 web/data/issues/PAN-OS/addressed/11.1.10-h28.md create mode 100644 web/data/issues/PAN-OS/addressed/11.1.13-h7.md create mode 100644 web/data/issues/PAN-OS/addressed/11.1.13-h8.md create mode 100644 web/data/issues/PAN-OS/addressed/11.1.6-h33.md create mode 100644 web/data/issues/PAN-OS/addressed/11.1.6-h34.md create mode 100644 web/data/issues/PAN-OS/addressed/11.2.10-h10.md create mode 100644 web/data/issues/PAN-OS/addressed/12.1.7.md diff --git a/web/data/issues/GlobalProtect/addressed/6.2.1.md b/web/data/issues/GlobalProtect/addressed/6.2.1.md index 3823ddc..9bdb2b1 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.1.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.1.md @@ -34,15 +34,15 @@ Fixed an issue where, when the GlobalProtect app was installed on Windows device ## GPC-18426 -Fixed an issue where when the GlobalProtect app was configured with the Disable GlobalProtect set to Allow with Ticket, the app did not display the correct Disable Duration time. +Fixed an issue where when the GlobalProtect app was configured with the **Disable GlobalProtect** set to **Allow with Ticket**, the app did not display the correct Disable Duration time. ## GPC-18336 -Fixed an issue where the GlobalProtect app got automatically connected after a system reboot even though the connection method configured was On-Demand. +Fixed an issue where the GlobalProtect app got automatically connected after a system reboot even though the connection method configured was **On-Demand**. ## GPC-18318 -Fixed an issue where, when the GlobalProtect app was connected to the internal gateway, the app displayed the message as Connected - Inter.... instead of Connected - Internal. +Fixed an issue where, when the GlobalProtect app was connected to the internal gateway, the app displayed the message as **Connected - Inter....** instead of **Connected - Internal**. ## GPC-18281 @@ -54,7 +54,7 @@ Fixed an issue where the GlobalProtect HIP check did not detect McAfee LiveSafe ## GPC-18230 -Fixed an issue where, when the user entered credentials during SAML authentication after the set internal login timer, the app displayed an authentication failed message without providing the reason. The Retry button on the app web interface did not work properly when using an embedded browser for authentication. The Retry button was not fully visible on the embedded browser. +Fixed an issue where, when the user entered credentials during SAML authentication after the set internal login timer, the app displayed an authentication failed message without providing the reason. The **Retry** button on the app web interface did not work properly when using an embedded browser for authentication. The **Retry** button was not fully visible on the embedded browser. ## GPC-18175 @@ -98,7 +98,7 @@ Fixed an issue where the GlobalProtect HIP check did not detect McAfee Total Pro ## GPC-18036 -Fixed an issue where, when the No direct access to local network option was enabled on the GlobalProtect app with access routes excluded from the GlobalProtect VPN tunnel, the feature did not work as expected when Endpoint Traffic Policy Enforcement was enabled. +Fixed an issue where, when the **No direct access to local network** option was enabled on the GlobalProtect app with access routes excluded from the GlobalProtect VPN tunnel, the feature did not work as expected when Endpoint Traffic Policy Enforcement was enabled. ## GPC-17936 @@ -106,15 +106,15 @@ Fixed an issue where the Conditional Connect method did not work as expected and ## GPC-17921 -Fixed an issue where, when the language was set to Japanese, the time to connect was not displayed properly when Disconnect Timeout for the app was configured. +Fixed an issue where, when the language was set to Japanese, the time to connect was not displayed properly when **Disconnect Timeout** for the app was configured. ## GPC-17896 -Fixed an issue where users were unable to connect to GlobalProtect gateway when only one external gateway was added due to the following error: Cannot Verify Server Certificate of Gateway. +Fixed an issue where users were unable to connect to GlobalProtect gateway when only one external gateway was added due to the following error: **Cannot Verify Server Certificate of Gateway**. ## GPC-17816 -Fixed an issue ehere after entering CIE SAML authentication credentials to refresh an expired explicit proxy token or cookie when connected in Tunnel and Proxy mode or proxy mode, the GlobalProtect app got stuck while retrieving the portal configuration. +Fixed an issue ehere after entering CIE SAML authentication credentials to refresh an expired explicit proxy token or cookie when connected in [Tunnel and Proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-tunnel-and-proxy-mode) or [proxy mode](https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/agent-based-proxy-globalprotect-proxy-mode), the GlobalProtect app got stuck while retrieving the portal configuration. ## GPC-17795 @@ -126,7 +126,7 @@ Fixed an issue where, when the GlobalProtect app was installed on devices runnin ## GPC-17762 -Fixed an issue when the GlobalProtect app was configured with the option Allow User to Disable GlobalProtect App with comment, the option did not work as expected. +Fixed an issue when the GlobalProtect app was configured with the option **Allow User to Disable GlobalProtect App** with comment, the option did not work as expected. ## GPC-17748 @@ -138,15 +138,15 @@ Fixed an issue where, when the GlobalProtect app was connected through the Prism ## GPC-17728 -Fixed an issue where users were unable to connect to GlobalProtect gateway when only one external gateway was added due to the following error: Cannot Verify Server Certificate of Gateway. +Fixed an issue where users were unable to connect to GlobalProtect gateway when only one external gateway was added due to the following error: **Cannot Verify Server Certificate of Gateway**. ## GPC-17460 -Fixed an issue where, when the GlobalProtect app was installed on Windows 10 or 11 devices, and when the user tried to authenticate using SAML authentication, the app did not display the Term of Use pop-up on the Welcome page properly. +Fixed an issue where, when the GlobalProtect app was installed on Windows 10 or 11 devices, and when the user tried to authenticate using SAML authentication, the app did not display the **Term of Use** pop-up on the **Welcome** page properly. ## GPC-17398 -Fixed an issue where the GlobalProtect app SettingsConnection tab did not display the Assigned IP Address(es) and Gateway IP Address properly. +Fixed an issue where the GlobalProtect app **Settings** > **Connection** tab did not display the **Assigned IP Address(es)** and **Gateway IP Address** properly. ## GPC-17206 @@ -154,7 +154,7 @@ Fixed an issue where, when Internal Host Detection (IHD) was enabled but failed ## GPC-17161 -Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the GlobalProtect app failed to reconnect and continued to stay in the Connecting state after the device woke up from Modern Standby mode. +Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the GlobalProtect app failed to reconnect and continued to stay in the **Connecting** state after the device woke up from Modern Standby mode. ## GPC-17099 @@ -162,7 +162,7 @@ When the GlobalProtect app for Windows is upgraded to version 6.0.5, devices wit ## GPC-17001 -Fixed an issue where, when the GlobalProtect app was installed on devices running on macOS, the app did not display the Connect button and Refresh Connection button properly. +Fixed an issue where, when the GlobalProtect app was installed on devices running on macOS, the app did not display the **Connect** button and **Refresh Connection** button properly. ## GPC-16978 @@ -170,7 +170,7 @@ Fixed an issue where the GlobalProtect app took a long time to establish a conne ## GPC-16851 -Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the app did not try to auto-connect to the gateway after exceeding the Disable Timeout Value. +Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the app did not try to auto-connect to the gateway after exceeding the **Disable Timeout Value**. ## GPC-16397 @@ -186,7 +186,7 @@ Fixed an issue where, when the GlobalProtect app was installed on devices runnin ## GPC-15968 -Fixed an issue where the GlobalProtect app was stuck in Connecting state when users failed to authenticate with SAML and using an embedded browser. Users were unable to disconnect the app and had to reboot the device. +Fixed an issue where the GlobalProtect app was stuck in **Connecting** state when users failed to authenticate with SAML and using an embedded browser. Users were unable to disconnect the app and had to reboot the device. ## GPC-15262 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.2.md b/web/data/issues/GlobalProtect/addressed/6.2.2.md index 88dbadc..82ebf4f 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.2.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.2.md @@ -18,7 +18,7 @@ Fixed an issue where users were unable to connect to the GlobalProtect portal an ## GPC-19002 -Fixed an issue where the GlobalProtect app did not display the Connect button when the user clicked the Get Started button after the app installation through Jamf. +Fixed an issue where the GlobalProtect app did not display the **Connect** button when the user clicked the **Get Started** button after the app installation through Jamf. ## GPC-18991 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.3.md b/web/data/issues/GlobalProtect/addressed/6.2.3.md index 72de69d..d30bd5e 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.3.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.3.md @@ -62,7 +62,7 @@ Fixed an issue where the prelogon connect method failed on the gateway prelogin ## GPC-19587 -Fixed an issue where the user could not login with Okta on macOS when Endpoint Traffic Policy Enforcement was set to All traffic . +Fixed an issue where the user could not login with Okta on macOS when Endpoint Traffic Policy Enforcement was set to **All traffic**. ## GPC-19581 @@ -186,7 +186,7 @@ Fixed an issue where Login Lifetime was incorrectly translated on the French ver ## GPC-19060 -Fixed an issue where the app Settings -> Connection tab did not display the connection status when the app was changed from a non-tunneled gateway to a tunneled gateway. +Fixed an issue where the app Settings -> Connection tab did not display the connection status when the app was changed from a non-tunneled gateway to a tunneled gateway. ## GPC-19044 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.4.md b/web/data/issues/GlobalProtect/addressed/6.2.4.md index 88b076a..2c12bab 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.4.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.4.md @@ -130,7 +130,7 @@ Fixed an issue where pre-logon failed when the computer was rebooted, when the m ## GPC-20080 -Fixed an issue where the GlobalProtect logs displayed different event messages for Windows and macOS devices when the Allow User to Disable GlobalProtect App was set to Allow with Passcode for the GlobalProtect app. +Fixed an issue where the GlobalProtect logs displayed different event messages for Windows and macOS devices when the **Allow User to Disable GlobalProtect App** was set to **Allow with Passcode** for the GlobalProtect app. ## GPC-20060 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.5.md b/web/data/issues/GlobalProtect/addressed/6.2.5.md index 606aa0d..bc49977 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.5.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.5.md @@ -122,7 +122,7 @@ Fixed an issue where the HIP report generation was taking longer than the 'Max W ## GPC-20771 -Fixed an issue where GlobalProtect 6.2 users on Windows 11(ARM & Intel) devices cannot connect to GlobalProtect due to "The Parameter is incorrect" error. +Fixed an issue where GlobalProtect 6.2 users on Windows 11(ARM & Intel) devices cannot connect to GlobalProtect due to "The Parameter is incorrect" error. ## GPC-20770 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.6.md b/web/data/issues/GlobalProtect/addressed/6.2.6.md index 1b84e2a..adfe898 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.6.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.6.md @@ -6,7 +6,7 @@ version: 6.2.6 ## GPC-21774 -Fixed an issue where the GlobalProtect ARM64 installers for 6.2.5 version did not display Digital Signatures tab. +Fixed an issue where the GlobalProtect ARM64 installers for 6.2.5 version did not display **Digital Signatures** tab. ## GPC-21721 @@ -18,15 +18,15 @@ Fixed an issue where the GlobalProtect app is stuck in the Connecting status whe ## GPC-21665 -Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and the app was used with Trellix Proxy Agent, the web browser displayed the following error, ERR_SOCKET_NOT_CONNECTED. +Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and the app was used with Trellix Proxy Agent, the web browser displayed the following error, **ERR_SOCKET_NOT_CONNECTED**. ## GPC-21636 -Fixed an issue where the users were unable to login Windows 11 using the User Principal Name (UPN) when GPCP was selected with GlobalProtect app version 6.2.4 and Interactive logon: Don't display last signed-in was enabled in their Entra ID - group policy. +Fixed an issue where the users were unable to login Windows 11 using the User Principal Name (UPN) when GPCP was selected with GlobalProtect app version 6.2.4 and **Interactive logon: Don't display last signed-in** was enabled in their Entra ID - group policy. ## GPC-21604 -Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and were connected to the internal gateway, the app did not display the Disconnect option under Settings. +Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and were connected to the internal gateway, the app did not display the **Disconnect** option under **Settings**. ## GPC-21413 @@ -74,7 +74,7 @@ Fixed an issue where the GlobalProtect HIP check did not detect Real time protec ## GPC-21131 -Fixed an issue where the users were unable to access the Advanced Logging Settings screen of the GlobalProtect app using the ctrl + tab key combination on the keyboard. The screen reader did not announce the keyboard options correctly. +Fixed an issue where the users were unable to access the Advanced Logging Settings screen of the GlobalProtect app using the **ctrl + tab** key combination on the keyboard. The screen reader did not announce the keyboard options correctly. ## GPC-21106 @@ -94,4 +94,4 @@ Fixed an issue where all GlobalProtect portals except for the currently connecte ## GPC-18647 -Fixed an issue with GlobalProtect App Log Collection feature where the user reported an issue using Report an Issue option on the GlobalProtect app and the issue was not reported as expected. +Fixed an issue with GlobalProtect App Log Collection feature where the user reported an issue using **Report an Issue** option on the GlobalProtect app and the issue was not reported as expected. diff --git a/web/data/issues/GlobalProtect/addressed/6.2.7.md b/web/data/issues/GlobalProtect/addressed/6.2.7.md new file mode 100644 index 0000000..745c0b2 --- /dev/null +++ b/web/data/issues/GlobalProtect/addressed/6.2.7.md @@ -0,0 +1,45 @@ +--- +type: Addressed +product: GlobalProtect +version: 6.2.7 +--- + +## GPC-22107 + +Fixed an issue where the GlobalProtect agent was unable to validate the server certificate after the CVE-2024-5921 remediation was applied. + +## GPC-22104 + +Fixed an issue where the GlobalProtect HIP report failed to detect the Seqrite Endpoint Protection application, when the application was upgraded to a higher version 18.00 (14.0.0.1) + +## GPC-22082 + +Fixed an issue where GlobaProtect did not validate certificates with 3rd parties or PKI and displayed a FIPS error. + +## GPC-22079 + +Fixed an issue where users were unable to connect to the GlobalProtect app due to Captive Portal connectivity issues. + +## GPC-22046 + +Fixed an issue where when the GlobalProtect app was installed on devices running macOS and the app version was upgraded to 6.2.5, end users were unable to connect the app. The app got stuck in the Connecting state and displayed the following message, “You are redirected to an embedded browser to authenticate and connect.” + +## GPC-22010 + +Fixed an issue where loopback connection did not work when Endpoint Traffic Policy Enforcement was enabled. + +## GPC-21950 + +Fixed an issue where the GlobalProtect connection on MacOS Sequoia 15+ was unstable. + +## GPC-21778 + +Fixed an issue where the GlobalProtect IPSec tunnel got disconnected on GlobalProtect app version 6.2.5 when the gpupdate /force command was used to update a policy. + +## GPC-21284 + +Fixed an issue where the GlobalProtect gateway did not receive the HIP reports from the user correctly due to which the end users were unable to access the resources even when the sessions were active. + +## GPC-20592 + +Fixed an issue where the GlobalProtect app could not establish the tunnel and the app got stuck in the tunnel creation stage. The app displayed the following error, “ The virtual adapter was not set up correctly due to a delay.” diff --git a/web/data/issues/GlobalProtect/addressed/6.2.8-h11.md b/web/data/issues/GlobalProtect/addressed/6.2.8-h11.md new file mode 100644 index 0000000..be8b203 --- /dev/null +++ b/web/data/issues/GlobalProtect/addressed/6.2.8-h11.md @@ -0,0 +1,37 @@ +--- +type: Addressed +product: GlobalProtect +version: 6.2.8-h11 +--- + +## GPC-26311 + +Fixed an issue where GlobalProtect users were unable to submit Host Information Profile (HIP) reports, which prevented security rules requiring a HIP match from applying. This occurred when you connected to an NGPA gateway using a dual-stack network, such as a mobile hotspot. With this fix, GlobalProtect successfully submits HIP reports regardless of your network configuration. + +## GPC-25946 + +Fixed an issue where your GlobalProtect client did not send Host Information Profile (HIP) check and report messages after you established a connection to the gateway. This occurred even when a HIP report was generated shortly before the connection, which could have impacted security posture assessment. With this fix, your GlobalProtect client now correctly sends HIP check and report messages after establishing a connection. + +## GPC-25776 + +Fixed an issue where GlobalProtect clients displayed an incorrect "Connecting" status after a GlobalProtect Portal or Gateway authentication failure, specifically when "Portal auth failed but SAML/CAS auth is successful". This misleading status persisted even though the connection had actually failed, preventing users from understanding the true connection state. + +## GPC-25541 + +Fixed an issue where MacOS GlobalProtect client version 6.2.8-416 was unable to connect to the GlobalProtect gateway, getting stuck in a connecting state. + +## GPC-25490 + +(MacBook devices) Fixed an issue where your GlobalProtect enabled device lost internet access after returning from hibernation. This occurred when your computer completely lost network connectivity, requiring a restart to restore internet access. With this fix, your device maintains network connectivity after resuming from hibernation. + +## GPC-25394 + +Fixed an issue where your traffic continued to pass through the GlobalProtect tunnel interface after you disconnected GobalProtect, preventing it from reverting to your local interface. With this fix, your traffic properly reverts to the local interface after GlobalProtect disconnects. + +## GPC-25320 + +Fixed an issue where GlobalProtect intermittently appeared in the foreground of your user session. This occurred even when you configured GlobalProtect for on-demand connections and were not actively trying to connect, causing it to overshadow other applications. With this fix, GlobalProtect remains in the background until you actively initiate a connection. + +## GPC-25280 + +Fixed an issue where GlobalProtect clients on macOS devices would intermittently get stuck in a "Connecting" state for several minutes after waking from modern standby. This occurred due to a race condition between DNS proxy reconfiguration and the VPN connection process during wake from sleep, where the macOS DNS proxy would temporarily stop and restart, causing the PanGPS service to time out when attempting to send DNS configuration commands. This led to repeated connection failures until the DNS proxy fully stabilized, a condition that was exacerbated by the presence of multiple network extensions on the macOS device. diff --git a/web/data/issues/GlobalProtect/addressed/6.2.8-h2.md b/web/data/issues/GlobalProtect/addressed/6.2.8-h2.md index e5cdc0f..d6c75b3 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.8-h2.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.8-h2.md @@ -30,13 +30,12 @@ Fixed an issue where GlobalProtect prompted for credentials instead of using aut ## GPC-22522 -Fixed an issue where, after upgrading from GlobalProtect app version 6.1.2 to 6.2.6, external users on Windows 11 computers with multiple Azure Entra accounts were unable to authenticate to the portal using SAML with Azure Entra as the Identity Provider (IdP). The new WebView2 embedded browser automatically used the user's default Windows credential for Single Sign-On (SSO), preventing them from selecting the correct account for authentication.To resolve this issue a new registry key 'entra-sso' has been introduced. You can add the registry key using two methods and set it to no to disable SSO.For pre-deployment, use msiexec.exe /i globalprotect64.msi ENTRASSO="no"Add key entra-sso and set it to nounder HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings. +Fixed an issue where, after upgrading from GlobalProtect app version 6.1.2 to 6.2.6, external users on Windows 11 computers with multiple Azure Entra accounts were unable to authenticate to the portal using SAML with Azure Entra as the Identity Provider (IdP). The new WebView2 embedded browser automatically used the user's default Windows credential for Single Sign-On (SSO), preventing them from selecting the correct account for authentication.To resolve this issue a new registry key 'entra-sso' has been introduced. You can add the registry key using two methods and set it to no to disable SSO. -For pre-deployment, use msiexec.exe /i globalprotect64.msi ENTRASSO="no" +- For pre-deployment, use **msiexec.exe /i globalprotect64.msi ENTRASSO="no"** +- Add key **entra-sso** and set it to **no**under **HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings**. -Add key entra-sso and set it to nounder HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings. - -If the entra-sso key does not exist under the above path, the GlobalProtect app's default behavior is to Allow Entra SSO. +If the **entra-sso** key does not exist under the above path, the GlobalProtect app's default behavior is to **Allow** Entra SSO. ## GPC-22066 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.8-h3.md b/web/data/issues/GlobalProtect/addressed/6.2.8-h3.md index 431f013..6fb50dc 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.8-h3.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.8-h3.md @@ -10,11 +10,11 @@ Fixed an issue where GlobalProtect users were not automatically prompted for aut ## GPC-23520 -Fixed an issue where new GlobalProtect users were unable to connect to the GlobalProtect app. The app got stuck in Connecting stage and stopped working when redirected to the embedded browser. +Fixed an issue where new GlobalProtect users were unable to connect to the GlobalProtect app. The app got stuck in **Connecting** stage and stopped working when redirected to the embedded browser. ## GPC-23496 -Fixed an issue where the GlobalProtect app's Connect button did not work as expected preventing users from connecting or changing gateways. +Fixed an issue where the GlobalProtect app's **Connect** button did not work as expected preventing users from connecting or changing gateways. ## GPC-23440 @@ -26,11 +26,11 @@ Fixed an issue where, when the GlobalProtect app was installed on devices runnin ## GPC-23432 -Fixed an issue where the GlobalProtect app version 6.3.3 intermittently got stuck on the finding best gateway status +Fixed an issue where the GlobalProtect app version 6.3.3 intermittently got stuck on the **finding best gateway** status ## GPC-23365 -Fixed an issue where, when the GlobalProtect app was installed on Windows machines, the app intermittently disconnected and then reconnected with the error message Failed to create exclude route. +Fixed an issue where, when the GlobalProtect app was installed on Windows machines, the app intermittently disconnected and then reconnected with the error message **Failed to create exclude route**. ## GPC-23301 @@ -38,7 +38,7 @@ Fixed an issue where, when the GlobalProtect app 6.2.7 and later, was installed ## GPC-23263 -Fixed an issue where after upgrading to GlobalProtect app version 6.3.3, the app did not save the username in the embedded browser when "Save Username was enabled. +Fixed an issue where after upgrading to GlobalProtect app version 6.3.3, the app did not save the username in the embedded browser when "**Save Username** was enabled. ## GPC-23218 @@ -54,7 +54,7 @@ Fixed an issue where the GlobalProtect app intermittently stopped sending HIP re ## GPC-22979 -Fixed an issue where, after upgrading to GlobalProtect app version 6.2.6, the PanGPA application got stuck in Connecting 'state and then got terminated unexpectedly. +Fixed an issue where, after upgrading to GlobalProtect app version 6.2.6, the PanGPA application got stuck in **Connecting** 'state and then got terminated unexpectedly. ## GPC-22541 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.8-h4.md b/web/data/issues/GlobalProtect/addressed/6.2.8-h4.md index 5cdd866..52dad39 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.8-h4.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.8-h4.md @@ -6,11 +6,11 @@ version: 6.2.8-h4 ## GPC-23839 -Fixed an issue that caused the GlobalProtect 6.3.3 HIP report to fail with the error Method: WAAPI_MID_GET_AGENT_STATE. +Fixed an issue that caused the GlobalProtect 6.3.3 HIP report to fail with the error Method: **WAAPI_MID_GET_AGENT_STATE**. ## GPC-23786 -Fixed an issue where the agent-msg log (PanoramaMonitorGlobalProtect) was not generated when a user disabled the GlobalProtect app and logged out of the gateway. +Fixed an issue where the agent-msg log (**Panorama** > **Monitor** > **GlobalProtect**) was not generated when a user disabled the GlobalProtect app and logged out of the gateway. ## GPC-23760 @@ -30,7 +30,7 @@ Fixed an issue where the GlobalProtect app ignores the new gateway-generated aut ## GPC-23616 -Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the following error TransparentProxy: openWithLocalEndpoint failed occurred in PanNExt.log when using an IPv6 address. +Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the following error **TransparentProxy: openWithLocalEndpoint failed** occurred in PanNExt.log when using an IPv6 address. ## GPC-23583 @@ -42,11 +42,11 @@ Fixed an issue where GlobalProtect clients using SAML with Ping Federate did not ## GPC-23519 -Fixed an issue where GlobalProtect HIP reports on MacBooks intermittently failed with an Invalid client IP error, preventing users from accessing resources over the GlobalProtect tunnel. This issue occurred after a system network change when GlobalProtect attempted to send the HIP report to an external gateway while the tunnel was disconnected. This issue affected MacBooks running GlobalProtect version 6.2.5. +Fixed an issue where GlobalProtect HIP reports on MacBooks intermittently failed with an **Invalid client IP** error, preventing users from accessing resources over the GlobalProtect tunnel. This issue occurred after a system network change when GlobalProtect attempted to send the HIP report to an external gateway while the tunnel was disconnected. This issue affected MacBooks running GlobalProtect version 6.2.5. ## GPC-23514 -Fixed an issue where, when using a screen reader on Windows or macOS, the GlobalProtect app's Settings button did not announce the available options for the end users. +Fixed an issue where, when using a screen reader on Windows or macOS, the GlobalProtect app's **Settings** button did not announce the available options for the end users. ## GPC-23488 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.8-h5.md b/web/data/issues/GlobalProtect/addressed/6.2.8-h5.md index 1329523..de272cd 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.8-h5.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.8-h5.md @@ -26,11 +26,11 @@ Fixed an issue where the GlobalProtect app experienced a continuous connect-disc ## GPC-24103 -Fixed an issue where the GlobalProtect app running on macOS allowed users to modify or add a new portal address after each device reboot, even when the Allow users to change portal setting was configured as No in the GlobalProtect app. +Fixed an issue where the GlobalProtect app running on macOS allowed users to modify or add a new portal address after each device reboot, even when the **Allow users to change portal** setting was configured as **No** in the GlobalProtect app. ## GPC-24048 -Fixed an issue where GlobalProtect apps installed on on Dell Vostro 15 3515 laptops were unable to connect to the GlobalProtect service with the following error: Could not connect to the GlobalProtect service. If the issue persists, contact your administrator. +Fixed an issue where GlobalProtect apps installed on on Dell Vostro 15 3515 laptops were unable to connect to the GlobalProtect service with the following error: **Could not connect to the GlobalProtect service. If the issue persists, contact your administrator**. ## GPC-24037 @@ -62,7 +62,7 @@ Fixed an issue where the GlobalProtect enforcer blocked network traffic on Windo ## GPC-23525 -Fixed an issue where on macOS Ventura and Sequoia, GlobalProtect app versions 6.2.6-838, 6.2.7-1047, 6.2.8, and 6.3.3, manually changing the portal address using the GlobalProtect app UI would fail and revert back to the last connected portal. This issue occurred even when Allow User to Change Portal Address was enabled in the agent configuration. +Fixed an issue where on macOS Ventura and Sequoia, GlobalProtect app versions 6.2.6-838, 6.2.7-1047, 6.2.8, and 6.3.3, manually changing the portal address using the GlobalProtect app UI would fail and revert back to the last connected portal. This issue occurred even when **Allow User to Change Portal Address** was enabled in the agent configuration. ## GPC-23394 @@ -74,7 +74,7 @@ Fixed an issue where agent disable logs were not being logged to Gateway System ## GPC-22683 -Fixed an issue where tool tips were not available for the Add, Edit, and Delete buttons on the GlobalProtect application's settings page on Windows devices. +Fixed an issue where tool tips were not available for the **Add**, **Edit**, and **Delete** buttons on the GlobalProtect application's settings page on Windows devices. ## GPC-22572 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.8-h7.md b/web/data/issues/GlobalProtect/addressed/6.2.8-h7.md index f11926f..b63252d 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.8-h7.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.8-h7.md @@ -26,7 +26,7 @@ Fixed an issue where GlobalProtect clients, after upgrading to versions 6.2.8-26 ## GPC-24842 -(macOS only) GlobalProtect crashed when you clicked Change Portal on setups that included two or more portal entries and had a preferred gateway marked. +(macOS only) GlobalProtect crashed when you clicked **Change Portal** on setups that included two or more portal entries and had a preferred gateway marked. ## GPC-24835 diff --git a/web/data/issues/GlobalProtect/addressed/6.2.8.md b/web/data/issues/GlobalProtect/addressed/6.2.8.md index c7f9d87..62b2c2e 100644 --- a/web/data/issues/GlobalProtect/addressed/6.2.8.md +++ b/web/data/issues/GlobalProtect/addressed/6.2.8.md @@ -62,11 +62,10 @@ Fixed an error where virtual adapter is not set correctly during tunnel creation ## GPC-22297 -Fixed an issue where the Customer was getting "A valid client certificate is required for authentication" even though they had a valid client certificate installed. In order to access the fix, you must do one of the following:uninstall the previous release (to remove all registry entries).manually delete the registry value "ext-key-usage-oid-for-client-cert" under "HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings" as it may contain a corrupted value. +Fixed an issue where the Customer was getting "A valid client certificate is required for authentication" even though they had a valid client certificate installed. In order to access the fix, you must do one of the following: -uninstall the previous release (to remove all registry entries). - -manually delete the registry value "ext-key-usage-oid-for-client-cert" under "HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings" as it may contain a corrupted value. +- uninstall the previous release (to remove all registry entries). +- manually delete the registry value "ext-key-usage-oid-for-client-cert" under "HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings" as it may contain a corrupted value. ## GPC-22264 diff --git a/web/data/issues/GlobalProtect/addressed/6.3.1.md b/web/data/issues/GlobalProtect/addressed/6.3.1.md index 549221f..7392309 100644 --- a/web/data/issues/GlobalProtect/addressed/6.3.1.md +++ b/web/data/issues/GlobalProtect/addressed/6.3.1.md @@ -10,7 +10,7 @@ Fixed an issue where the GlobalProtect re-authentication prompt appeared in the ## GPC-20895 -Fixed an issue where a macOS GlobalProtect app user was able to modify or add a new portal even though the portal agent configuration specified Allow User to Change Portal Address = NO and Allow user to Sign Out from GlobalProtect App = No . +Fixed an issue where a macOS GlobalProtect app user was able to modify or add a new portal even though the portal agent configuration specified **Allow User to Change Portal Address = NO** and **Allow user to Sign Out from GlobalProtect App = No**. ## GPC-20864 @@ -34,7 +34,7 @@ Fixed an issue where users unable to connect to GlobalProtect after upgrading fr ## GPC-20595 -Fixed an issue where GlobalProtect users were unable to connect after upgrading to 6.2.3-270 and received a Y our internet access is blocked error during SAML authentication using the embedded browser. +Fixed an issue where GlobalProtect users were unable to connect after upgrading to 6.2.3-270 and received a Y**our internet access is blocked** error during SAML authentication using the embedded browser. ## GPC-20527 @@ -42,7 +42,7 @@ Fixed an issue where the Conditional Connect method configured for the GlobalPro ## GPC-20463 -Fixed an issue where the GlobalProtect status panel is not disabled at startup when the Display Status Panel at Startup parameter is set to no. +Fixed an issue where the GlobalProtect status panel is not disabled at startup when the **Display Status Panel at Startup parameter**is set to no. ## GPC-20442 @@ -158,7 +158,7 @@ Fixed an issue where, when the GlobalProtect app was installed on Windows device ## GPC-18647 -Fixed an issue where the user reported an issue using the Report an Issue option on the GlobalProtect app and the issue was not reported as expected. +Fixed an issue where the user reported an issue using the **Report an Issue** option on the GlobalProtect app and the issue was not reported as expected. ## GPC-17820 diff --git a/web/data/issues/GlobalProtect/addressed/6.3.2.md b/web/data/issues/GlobalProtect/addressed/6.3.2.md index a2a2c1b..9221b79 100644 --- a/web/data/issues/GlobalProtect/addressed/6.3.2.md +++ b/web/data/issues/GlobalProtect/addressed/6.3.2.md @@ -34,7 +34,7 @@ Fixed an issue where the GlobalProtect IPSec tunnel got disconnected on GlobalPr ## GPC-21774 -Fixed an issue where the GlobalProtect ARM64 installers for 6.2.5 version did not display the Digital Signatures tab. +Fixed an issue where the GlobalProtect ARM64 installers for 6.2.5 version did not display the **Digital Signatures** tab. ## GPC-21771 @@ -46,7 +46,7 @@ Fixed an issue where all the added portals got deleted from the portal list exce ## GPC-21604 -Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and were connected to the internal gateway, the app did not display the Disconnect option under Settings. +Fixed an issue where, when the GlobalProtect app was installed on devices running macOS and were connected to the internal gateway, the app did not display the **Disconnect** option under **Settings**. ## GPC-21571 @@ -54,7 +54,7 @@ Fixed an issue where the hyperlink in HIP notification opened up in Webview2 ins ## GPC-21565 -Fixed an issue where the SAML embedded browser did not remember the username after sign-out, even when the user had selected the check box Remember Me on the SAML embedded browser. +Fixed an issue where the SAML embedded browser did not remember the username after sign-out, even when the user had selected the check box **Remember Me** on the SAML embedded browser. ## GPC-21542 @@ -108,7 +108,7 @@ Fixed an issue where the GlobalProtect HIP check did not detect Real time protec ## GPC-21130 -Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the GlobalProtect app failed to reconnect and continued to stay in the Connecting state after the device woke up from Modern Standby mode. +Fixed an issue where, when the GlobalProtect app was installed on devices running macOS, the GlobalProtect app failed to reconnect and continued to stay in the Connecting state after the device woke up from **Modern Standby** mode. ## GPC-21106 @@ -124,7 +124,7 @@ Fixed an issue where the GlobalProtect app was installed on devices running macO ## GPC-20967 -Fixed an issue where, when the GlobalProtect app was installed with the Conditional Connect method, users had to click the Connect button twice to connect to an external gateway after a system reboot. +Fixed an issue where, when the GlobalProtect app was installed with the **Conditional Connect** method, users had to click the **Connect** button twice to connect to an external gateway after a system reboot. ## GPC-20943 @@ -180,7 +180,7 @@ Fixed an issue where when Endpoint Traffic enforcement feature was enabled, cert ## GPC-18695 -Fixed an issue where, when the GlobalProtect app version 6.0.7 was installed on devices running macOS, the "Allow with Passcode option did not work as expected when the user tried to disable the GlobalProtect app with the configured passcode. +Fixed an issue where, when the GlobalProtect app version 6.0.7 was installed on devices running macOS, the "**Allow with Passcode** option did not work as expected when the user tried to disable the GlobalProtect app with the configured passcode. ## GPC-18671 diff --git a/web/data/issues/GlobalProtect/addressed/6.3.3-h12.md b/web/data/issues/GlobalProtect/addressed/6.3.3-h12.md new file mode 100644 index 0000000..d4d2d07 --- /dev/null +++ b/web/data/issues/GlobalProtect/addressed/6.3.3-h12.md @@ -0,0 +1,89 @@ +--- +type: Addressed +product: GlobalProtect +version: 6.3.3-h12 +--- + +## GPC-26563 + +Fixed an issue where your GlobalProtect client deleted the pre-defined Proxy Auto-Configuration file configuration from your client machine when it refreshed its connection. This occurred on GlobalProtect client versions 6.3.3-h9 and 6.3.3-h10. With this fix, your GlobalProtect client no longer deletes the pre-defined PAC file configuration upon connection refresh. + +## GPC-26311 + +Fixed an issue where GlobalProtect users were unable to submit Host Information Profile (HIP) reports, which prevented security rules requiring a HIP match from applying. This occurred when you connected to an NGPA gateway using a dual-stack network, such as a mobile hotspot. With this fix, GlobalProtect successfully submits HIP reports regardless of your network configuration. + +## GPC-26305 + +Fixed an issue where the GlobalProtect portal change option was not visible when you were in internal host detection mode. With this fix, you can now properly view and use the portal change option. + +## GPC-26227 + +Fixed an issue where your GlobalProtect client connected to a geographically distant GlobalProtect gateway even when a closer, preferred gateway was available. This occurred when your network connection became temporarily unavailable during the GlobalProtect client's attempt to connect to the preferred gateway. With this fix, your GlobalProtect client correctly prioritizes and connects to the optimal gateway after network connectivity is restored. + +## GPC-26119 + +Fixed an issue where, on your macOS device, you were unable to authenticate to captive portals on public Wi-Fi networks when GlobalProtect's Network Enforcer was enabled. This occurred because GlobalProtect exempted the primary Captive Network Assistant process but did not dynamically exempt the associated WebKit eXtensible Process Communication (XPC) subprocesses responsible for rendering the captive portal page, which prevented the captive portal page from loading. With this fix, GlobalProtect now correctly exempts these subprocesses, ensuring captive portals load successfully. + +## GPC-25967 + +Fixed an issue where your GlobalProtect client experienced a significant delay in establishing a connection after your device woke up from a sleep event, preventing timely network access. With this fix, your GlobalProtect client now connects promptly after a sleep event, ensuring a smoother user experience. + +## GPC-25946 + +Fixed an issue where your GlobalProtect client did not send Host Information Profile (HIP) check and report messages after you established a connection to the gateway. This occurred even when a HIP report was generated shortly before the connection, which could have impacted security posture assessment. With this fix, your GlobalProtect client now correctly sends HIP check and report messages after establishing a connection. + +## GPC-25776 + +Fixed an issue where GlobalProtect clients displayed an incorrect "Connecting" status after a GlobalProtect Portal or Gateway authentication failure, specifically when "Portal auth failed but SAML/CAS auth is successful". This misleading status persisted even though the connection had actually failed, preventing users from understanding the true connection state. + +## GPC-25563 + +Fixed an issue where the GlobalProtect proxy agent intermittently initiated proxy connections using a GET request instead of the required CONNECT request, which resulted in failures to establish connections to target websites. + +## GPC-25541 + +Fixed an issue where MacOS GlobalProtect client version 6.2.8-416 was unable to connect to the GlobalProtect gateway, getting stuck in a connecting state. + +## GPC-25490 + +(MacBook devices) Fixed an issue where your GlobalProtect enabled device lost internet access after returning from hibernation. This occurred when your computer completely lost network connectivity, requiring a restart to restore internet access. With this fix, your device maintains network connectivity after resuming from hibernation. + +## GPC-25446 + +Fixed an issue where Host Information Profile (HIP) matching did not function as expected after your device resumed from modern standby. This occurred intermittently, requiring you to manually refresh to restore proper HIP matching. With this fix, HIP matching now functions correctly after your device resumes from modern standby. + +## GPC-25394 + +Fixed an issue where your traffic continued to pass through the GlobalProtect tunnel interface after you disconnected GobalProtect, preventing it from reverting to your local interface. With this fix, your traffic properly reverts to the local interface after GlobalProtect disconnects. + +## GPC-25383 + +Fixed an issue where GlobalProtect clients on Windows machines experienced intermittent disconnections, which self-resolved within 1-2 minutes. + +## GPC-25359 + +Fixed an issue where the GlobalProtect client, when using the embedded browser for SAML authentication with the Cloud Authentication Service, failed to retrieve configuration from the GlobalProtect Portal. This occurred because the GlobalProtect Agent incorrectly passed the username with an additional backslash character, leading to improper encoding and subsequent failure. + +## GPC-25320 + +Fixed an issue where GlobalProtect intermittently appeared in the foreground of your user session. This occurred even when you configured GlobalProtect for on-demand connections and were not actively trying to connect, causing it to overshadow other applications. With this fix, GlobalProtect remains in the background until you actively initiate a connection. + +## GPC-25280 + +Fixed an issue where GlobalProtect clients on macOS devices would intermittently get stuck in a "Connecting" state for several minutes after waking from modern standby. This occurred due to a race condition between DNS proxy reconfiguration and the VPN connection process during wake from sleep, where the macOS DNS proxy would temporarily stop and restart, causing the PanGPS service to time out when attempting to send DNS configuration commands. This led to repeated connection failures until the DNS proxy fully stabilized, a condition that was exacerbated by the presence of multiple network extensions on the macOS device. + +## GPC-25019 + +Fixed an issue where GlobalProtect App version 6.2.8-223, when configured in a non-tunnel setup with internal gateways, would stop sending Host Information Profile (HIP) reports, leading to policy drops on the firewall. This occurred because of a time alignment problem in the HIP report thread scheduler, which caused the app to incorrectly skip sending reports when the `tNextHipReportCheckSendTime` became stale, especially with longer HIP check intervals. + +## GPC-24845 + +Fixed an issue where GlobalProtect users on Prisma Access intermittently experienced "No user mapping" issues across multiple gateways. + +## GPC-24825 + +Fixed an issue where GlobalProtect client version 6.2.8-263 failed to transition from the pre-logon tunnel to the user tunnel after successful Windows credential entry, causing the client to remain in a 'Connecting' state and requiring a force reboot or sign-out to clear. + +## GPC-24006 + +Fixed an issue where MacOS GlobalProtect clients, when configured for Okta authentication with Prisma Access, intermittently failed to log in after a previous log-off. This failure manifested as an "Okta device not on-line" error, caused by the GlobalProtect client's log-off process not completing gracefully, which resulted in the client service not starting correctly on subsequent login attempts. diff --git a/web/data/issues/PAN-OS/addressed/11.1.10-h27.md b/web/data/issues/PAN-OS/addressed/11.1.10-h27.md new file mode 100644 index 0000000..bfe3330 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/11.1.10-h27.md @@ -0,0 +1,9 @@ +--- +type: Addressed +product: PAN-OS +version: 11.1.10-h27 +--- + +## BLANK-000000 + +Fixes were made to address [CVE-2026-0273](https://security-stg.paloaltonetworks.com/CVE-2026-0273) and [CVE-2026-0272](https://security-stg.paloaltonetworks.com/CVE-2026-0272). diff --git a/web/data/issues/PAN-OS/addressed/11.1.10-h28.md b/web/data/issues/PAN-OS/addressed/11.1.10-h28.md new file mode 100644 index 0000000..da9c0e6 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/11.1.10-h28.md @@ -0,0 +1,142 @@ +--- +type: Addressed +product: PAN-OS +version: 11.1.10-h28 +--- + +## PAN-321340 + +```caveat +Firewalls in FIPS mode only +``` + +Fixed an issue where GlobalProtect unexpectedly prompted for RADIUS authentication instead of client certificate authentication due to an OSCP validation error and subsequent CRL verification failure, which led to certificates being marked as invalid. + +## PAN-319288 + +Fixed an issue where a DPC in Slot 4 restarted repeatedly, which caused internal path monitoring failures and a failover event. + +## PAN-318580 + +Fixed an issue where processes restarted and the firewall unexpectedly rebooted when you configured a Security policy rule with **Source Device > quarantine**. + +## PAN-317755 + +Fixed an issue on Panorama where selective push operations failed when plugin configurations included access-domain or log-collector references. + +## PAN-317466 + +Fixed an issue where SIP sessions stopped progressing after the firewall received fragmented packets, fragmented at header field. + +## PAN-316556 + +Fixed an issue where a race condition between the session ager and packet processing resulted in memory corruption and caused the pan_task process to stop responding, which resulted in the firewall becoming unresponsive + +## PAN-315337 + +Fixed an issue where GlobalProtect throughput was reduced after an upgrade. + +## PAN-315314 + +Fixed an issue where, when a push operation from Panorama to the firewall failed, accounting logs stopped forwarding. + +## PAN-315160 + +```caveat +PA-7500 firewalls only +``` + +Fixed an issue where internal path monitoring logs incorrectly reported internal path monitoring failures when they did not occur. + +## PAN-314623 + +```caveat +Firewalls in active/passive HA configurations only +``` + +Fixed an issue where, after a failover, routing information within OSPF protocol was not correctly translated or propagated, which affected network path convergence and FRR capabilities. + +## PAN-313827 + +Fixed an issue where a memory leak occurred related to the reportd process when custom reports were run via API. + +## PAN-313606 + +Fixed an issue where Panorama pushed commits took longer than expected to complete without displaying an error message when committing due to slow cloud-app compilation. + +## PAN-311658 + +Fixed an issue where the reportd process stopped responding, which caused the firewall to reboot. + +## PAN-311248 + +Fixed an issue where the ABR failed to translate and advertise the default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF backbone area as a Type-5 LSA. + +## PAN-310240 + +Fixed an issue where software packet buffers were completely utilized when performing a Data Loss Prevention longevity test. + +## PAN-309853 + +```caveat +Firewalls with FIPS-CC enabled only +``` + +Fixed an issue where, when attempting to make changes to the GlobalProtect portal, an error message was displayed and configuration updates failed. + +## PAN-308775 + +```caveat +Firewalls in active/passive configurations only +``` + +Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time. + +## PAN-308668 + +Fixed an issue on Prisma Access Remote Network firewalls where high CPU utilization caused slowness and command timeouts. + +## PAN-297819 + +Fixed an issue where the firewall was unable to send device telemetry files to Cortex Data Lake due to the firewall receiving an invalid upload token. + +## PAN-293142 + +Fixed an issue where firewall components became unresponsive during sustained operation. + +## PAN-291660 + +Fixed an issue where the firewall incorrectly reported the speed of 25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID. + +## PAN-289460 + +Fixed an issue where the timestamp value in SNMPv3 trap headers was incorrect. + +To use this fix, run the CLI command debug log-receiver enginetime-from-snmptime yes. + +## PAN-282335 + +Fixed an issue where firewalls in a cluster experienced approximately 50% packet loss on IPSec NATT tunnels when tunnel acceleration was enabled. + +## PAN-280536 + +Fixed an issue where firewalls that were connected to the same Cloud Identity Engine displayed inconsistent group membership information, with some firewalls showing only a subset of users belonging to a group. This occurred due to a full or incremental group sync failure. + +This fix introduces a retry mechanism for failed group queries to the Cloud Identity Engine. To use this feature, run the following CLI commands. + +To enable the retry mechanism: debug user-id dscd retry-enable on. + +To set the retry time: debug user-id dscd retry-time set-time <1-10>. The default value is 5 seconds. + +To set the number of retry attempts: debug user-id dscd retry attempts set-attempts <3-10>. The default value is 5 attempts. + +To disable the retry mechanism: debug user-id dscd retry-enable off. + +Additionally, a system log is now generated when a group sync fails, and you are able to monitor the group sync status with the following CLI commands: + +- show user group count list cloud-identity-engine +- show user group count name + +## PAN-213491 + +Fixed an issue where the management CPU was high, which caused the web interface to be slower than expected. diff --git a/web/data/issues/PAN-OS/addressed/11.1.13-h7.md b/web/data/issues/PAN-OS/addressed/11.1.13-h7.md new file mode 100644 index 0000000..ac132be --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/11.1.13-h7.md @@ -0,0 +1,9 @@ +--- +type: Addressed +product: PAN-OS +version: 11.1.13-h7 +--- + +## BLANK-000000 + +Fixes were made to address [CVE-2026-0273](https://security-stg.paloaltonetworks.com/CVE-2026-0273) and [CVE-2026-0272](https://security-stg.paloaltonetworks.com/CVE-2026-0272). diff --git a/web/data/issues/PAN-OS/addressed/11.1.13-h8.md b/web/data/issues/PAN-OS/addressed/11.1.13-h8.md new file mode 100644 index 0000000..293e0ca --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/11.1.13-h8.md @@ -0,0 +1,157 @@ +--- +type: Addressed +product: PAN-OS +version: 11.1.13-h8 +--- + +## PAN-321340 + +```caveat +Firewalls in FIPS mode only +``` + +Fixed an issue where GlobalProtect unexpectedly prompted for RADIUS authentication instead of client certificate authentication due to an OSCP validation error and subsequent CRL verification failure, which led to certificates being marked as invalid. + +## PAN-320598 + +Fixed an issue where internal and external DNS names did not resolve when connected to a GlobalProtect gateway. + +## PAN-319288 + +Fixed an issue where a DPC in Slot 4 restarted repeatedly, which caused internal path monitoring failures and a failover event. + +## PAN-318580 + +Fixed an issue where processes restarted and the firewall unexpectedly rebooted when you configured a Security policy rule with **Source Device > quarantine**. + +## PAN-317755 + +Fixed an issue on Panorama where selective push operations failed when plugin configurations included access-domain or log-collector references. + +## PAN-316556 + +Fixed an issue where a race condition between the session ager and packet processing resulted in memory corruption and caused the pan_task process to stop responding, which resulted in the firewall becoming unresponsive + +## PAN-316120 + +Fixed an issue where, after Advanced Routing was enabled, the firewall advertised routes to internal BGP neighbors with the original external BGP next-hop address. + +## PAN-315337 + +Fixed an issue where GlobalProtect throughput was reduced after an upgrade. + +## PAN-315314 + +Fixed an issue where, when a push operation from Panorama to the firewall failed, accounting logs stopped forwarding. + +## PAN-315160 + +```caveat +PA-7500 firewalls only +``` + +Fixed an issue where internal path monitoring logs incorrectly reported internal path monitoring failures when they did not occur. + +## PAN-314752 + +Fixed an issue on Panorama where, after removing a scheduled configuration push, Panorama still initiated the push at its previously scheduled time. + +## PAN-314623 + +```caveat +Firewalls in active/passive HA configurations only +``` + +Fixed an issue where, after a failover, routing information within OSPF protocol was not correctly translated or propagated, which affected network path convergence and FRR capabilities. + +## PAN-314385 + +```caveat +Firewalls in active/passive HA clusters only +``` + +Fixed an issue where high dataplane CPU usage occurred and traffic offloading decreased when a failover occurred from the active firewall to the passive firewall, and then back to the active firewall. + +## PAN-313827 + +Fixed an issue where a memory leak occurred related to the reportd process when custom reports were run via API. + +## PAN-313700 + +Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile. + +## PAN-313606 + +Fixed an issue where Panorama pushed commits took longer than expected to complete without displaying an error message when committing due to slow cloud-app compilation. + +## PAN-313443 + +Fixed an issue where firewalls acting as an accumulation proxy sent a server hello with an earlier TCP timestamp value than a preceding ACK packet, which prevented successful session establishment. This occurred when the client hello messages were split across multiple network segments. + +To use this fix, run the CLI command debug dataplane set ssl-decrypt accumulate-client-hello ts-relay yes. + +## PAN-313036 + +Fixed an issue where the firewall dataplane continuously accumulated packets in the ctd_pkt_queue and packet buffers, which caused resource exhaustion and prematurely terminated sessions. + +## PAN-311658 + +Fixed an issue where the reportd process stopped responding, which caused the firewall to reboot. + +## PAN-311098 + +Fixed an issue where firewalls entered a nonfunctional state due to L7 running out of resources due to a high volume of traffic. + +## PAN-309853 + +```caveat +Firewalls with FIPS-CC enabled only +``` + +Fixed an issue where, when attempting to make changes to the GlobalProtect portal, an error message was displayed and configuration updates failed. + +## PAN-308775 + +```caveat +Firewalls in active/passive configurations only +``` + +Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time. + +## PAN-308668 + +Fixed an issue on Prisma Access Remote Network firewalls where high CPU utilization caused slowness and command timeouts. + +## PAN-308444 + +Fixed an issue where pushing multiple policy rules failed when the policy rules contained a large number of dynamic address object groups or user groups. + +## PAN-297819 + +Fixed an issue where the firewall was unable to send device telemetry files to Cortex Data Lake due to the firewall receiving an invalid upload token. + +## PAN-295082 + +Fixed an issue on the Panorama web interface where you were unable to delete or change a logical router for tunnel, SD-WAN, VLAN, or loopback interfaces under a template. + +## PAN-293142 + +Fixed an issue where firewall components became unresponsive during sustained operation. + +## PAN-289460 + +Fixed an issue where the timestamp value in SNMPv3 trap headers was incorrect. + +To use this fix, run the CLI command debug log-receiver enginetime-from-snmptime yes. + +## PAN-282335 + +Fixed an issue where firewalls in a cluster experienced approximately 50% packet loss on IPSec NATT tunnels when tunnel acceleration was enabled. + +## PAN-240066 + +Fixed a duplicate MAC address issue where an ethernet interface sent out Gratuitous ARP (GARP) messages for an IP address that was not configured on it. + +## PAN-213491 + +Fixed an issue where the management CPU was high, which caused the web interface to be slower than expected. diff --git a/web/data/issues/PAN-OS/addressed/11.1.6-h33.md b/web/data/issues/PAN-OS/addressed/11.1.6-h33.md new file mode 100644 index 0000000..403f4d3 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/11.1.6-h33.md @@ -0,0 +1,9 @@ +--- +type: Addressed +product: PAN-OS +version: 11.1.6-h33 +--- + +## BLANK-000000 + +Fixes were made to address [CVE-2026-0273](https://security-stg.paloaltonetworks.com/CVE-2026-0273) and [CVE-2026-0272](https://security-stg.paloaltonetworks.com/CVE-2026-0272). diff --git a/web/data/issues/PAN-OS/addressed/11.1.6-h34.md b/web/data/issues/PAN-OS/addressed/11.1.6-h34.md new file mode 100644 index 0000000..5ec32e3 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/11.1.6-h34.md @@ -0,0 +1,49 @@ +--- +type: Addressed +product: PAN-OS +version: 11.1.6-h34 +--- + +## PAN-321340 + +```caveat +Firewalls in FIPS mode only +``` + +Fixed an issue where GlobalProtect unexpectedly prompted for RADIUS authentication instead of client certificate authentication due to an OSCP validation error and subsequent CRL verification failure, which led to certificates being marked as invalid. + +## PAN-319288 + +Fixed an issue where a DPC in Slot 4 restarted repeatedly, which caused internal path monitoring failures and a failover event. + +## PAN-318580 + +Fixed an issue where processes restarted and the firewall unexpectedly rebooted when you configured a Security policy rule with **Source Device > quarantine**. + +## PAN-316556 + +Fixed an issue where a race condition between the session ager and packet processing resulted in memory corruption and caused the pan_task process to stop responding, which resulted in the firewall becoming unresponsive + +## PAN-315314 + +Fixed an issue where, when a push operation from Panorama to the firewall failed, accounting logs stopped forwarding. + +## PAN-308775 + +```caveat +Firewalls in active/passive configurations only +``` + +Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time. + +## PAN-308668 + +Fixed an issue on Prisma Access Remote Network firewalls where high CPU utilization caused slowness and command timeouts. + +## PAN-291660 + +Fixed an issue where the firewall incorrectly reported the speed of 25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID. + +## PAN-213491 + +Fixed an issue where the management CPU was high, which caused the web interface to be slower than expected. diff --git a/web/data/issues/PAN-OS/addressed/11.2.10-h10.md b/web/data/issues/PAN-OS/addressed/11.2.10-h10.md new file mode 100644 index 0000000..8b8c747 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/11.2.10-h10.md @@ -0,0 +1,79 @@ +--- +type: Addressed +product: PAN-OS +version: 11.2.10-h10 +--- + +## PAN-321150 + +Fixed an issue where the interface remained down after an upgrade. + +## PAN-320598 + +Fixed an issue where internal and external DNS names did not resolve when connected to a GlobalProtect gateway. + +## PAN-319266 + +```caveat +Cloud IPS only +``` + +Increased scale limit for zone mappings. + +## PAN-317755 + +Fixed an issue on Panorama where selective push operations failed when plugin configurations included access-domain or log-collector references. + +## PAN-315337 + +Fixed an issue where GlobalProtect throughput was reduced after an upgrade. + +## PAN-315314 + +Fixed an issue where, when a push operation from Panorama to the firewall failed, accounting logs stopped forwarding. + +## PAN-314319 + +Added a CLI command to enable and disable AHO software offload optimization. + +## PAN-313828 + +Fixed an issue where the firewall did not forward traffic due to memory issues on a forwarding component. + +## PAN-313606 + +Fixed an issue where Panorama pushed commits took longer than expected to complete without displaying an error message when committing due to slow cloud-app compilation. + +## PAN-310263 + +```caveat +VM-Series firewalls only +``` + +Fixed an issue where enabling TLS1.3 in a decryption profile prevented access to websites. + +## PAN-310240 + +Fixed an issue where software packet buffers were completely utilized when performing a Data Loss Prevention longevity test. + +## PAN-307976 + +```caveat +Firewalls in active/active HA configurations only +``` + +Fixed an issue where tunnels failed to come up with the error message failed to find a socket for transmission. + +## PAN-307618 + +Added a debug CLI command to address where remote networks for Prisma Access tenants randomly dropped monitoring packets from peer devices, which caused tunnels to be marked as down. This occurred when a CPU core suddenly experienced high utilization. + +To utilize this fix, run debug dataplane set ssl-decrypt use-new-peek-window yes. + +## PAN-292306 + +Fixed an issue where the authd process stopped handling RADIUS authentication requests and required a restart. + +## PAN-234302 + +Fixed an issue where commit operations took longer than expected to complete due to EDL timeouts occurring on passive nodes when a service route was enabled. diff --git a/web/data/issues/PAN-OS/addressed/12.1.7.md b/web/data/issues/PAN-OS/addressed/12.1.7.md new file mode 100644 index 0000000..50117f0 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/12.1.7.md @@ -0,0 +1,226 @@ +--- +type: Addressed +product: PAN-OS +version: 12.1.7 +--- + +## BLANK-000000 + +Fixes were made to address the following CVEs: + +- [CVE-2026-0265](https://security.paloaltonetworks.com/CVE-2026-0265) +- [CVE-2026-0264](https://security.paloaltonetworks.com/CVE-2026-0264) +- [CVE-2026-0263](https://security.paloaltonetworks.com/CVE-2026-0263) +- [CVE-2026-0262](https://security.paloaltonetworks.com/CVE-2026-0262) +- [CVE-2026-0261](https://security.paloaltonetworks.com/CVE-2026-0261) +- [CVE-2026-0258](https://security.paloaltonetworks.com/CVE-2026-0258) +- [CVE-2026-0257](https://security.paloaltonetworks.com/CVE-2026-0257) +- [CVE-2026-0256](https://security.paloaltonetworks.com/CVE-2026-0256) +- [CVE-2026-0259](https://security.paloaltonetworks.com/CVE-2026-0259) +- [CVE-2026-0300](https://security.paloaltonetworks.com/CVE-2026-0300) + +## PAN-322815 + +```caveat +VM-Series firewalls on Microsoft Azure environments only +``` + +Fixed an issue where the firewall entered maintenance mode after enabling FIPS-CC mode and rebooted. + +## PAN-322681 + +Fixed an issue where the PDF Summary Reports were not generated correctly after upgrading to an affected release. + +## PAN-322630 + +Fixed an issue where IKE gateways were not visible within Panorama Templates under **Network Profiles** from a custom administrator role after upgrading to an affected PAN-OS release. + +## PAN-320897 + +Fixed an issue where the firewall did not detect evasions due to TCP checksum offloading not being enabled. + +## PAN-318288 + +Fixed an issue where traffic initiated from Microsoft Azure to an on-premises firewall was not decrypted, which caused the firewall to drop the traffic. This occurred due to the firewall incorrectly identifying SPI values. + +## PAN-318275 + +```caveat +VM-Series firewalls only +``` + +Fixed an issue where the firewall became unresponsive and did not automatically reboot, which led to prolonged outages. With this fix, the Linux kernel configuration will trigger a system panic and reboot. + +## PAN-317772 + +Added a fix to improve performance in lossy network conditions. + +## PAN-317583 + +Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state. + +## PAN-317548 + +Fixed an issue where an IMA violation occurred when Panorama accessed GRUB during the installation process, which caused upgrades from PAN-OS 12.1.4 to PAN-OS 12.1.5 to fail. + +## PAN-317466 + +Fixed an issue where SIP sessions stopped progressing after the firewall received fragmented packets, fragmented at header field. + +## PAN-317215 + +```caveat +VM-Series firewalls on ESXi with Intel E810 NICs using PCI passthrough +``` + +Fixed an issue where the brdagent process became unresponsive during data port initialization, which resulted in system instability, interface outages, HA split-brain conditions, and unexpected reboots during failover. + +## PAN-317177 + +Fixed an issue on firewalls in DHCP Client mode where, after upgrading to an affected release, the SNMP process unexpectedly restarted after a commit, which led to false interface flap notifications on SNMP managers. + +## PAN-317068 + +Fixed an issue on the Panorama web interface where you were able to enable IPv6 for IKE gateways and IPSec tunnels even when IPv6 WAN was disabled, which resulted in an invalid configuration. To utilize this fix, upgrade to the latest Panorama plugin. + +## PAN-316937 + +Fixed an issue where GlobalProtect users intermittently received incorrect private IP addresses after connecting to a gateway behind a Network Load Balancer (NLB). + +## PAN-316740 + +Fixed an issue where, after upgrading to an affected release, HCE profiles exceeded the maximum character length when generated automatically, which caused subsequent commit operations to fail with a validation error. This occurred when HIP objects were associated with HIP profiles prior to the upgrade. + +## PAN-316605 + +Fixed an issue where HIP redistribution to remote network nodes from external gateways resulted in a large amount of error messages in User-ID logs. + +## PAN-315965 + +Fixed an issue to address TCP proxy fast recovery behavior to follow RFC 5681. + +## PAN-315912 + +Fixed an issue where the Maximum Segment Size (MSS) rewrite functionality for packets ingressing through SD-WAN interfaces on firewalls was not optimized. + +## PAN-315134 + +Fixed an issue where, after an upgrade, **IoT Devices > Asset Inventory** did not display device data even though the system reported a total count of devices. + +## PAN-315005 + +Fixed an issue where configured RIPv2 timer parameters were not applied when the profile was configured with custom update, expire, and delete values, and the system continued to use the default timer settings, which caused unexpected route removal and network disconnections. + +## PAN-314823 + +Fixed an issue where the management interface became unresponsive when attempting to untag an IP address via the web interface. + +## PAN-314365 + +Fixed an issue where the logrcvr process stopped responding for traffic containing multiple XFF headers when URL XFF header logging was enabled along with additional XFF header logging, which caused subsequent commits to fail. + +## PAN-314319 + +Added a CLI command to enable and disable AHO software offload optimization. + +## PAN-314147 + +Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces with member having different MTU. + +## PAN-314020 + +Fixed an issue where the firewall did not decapsulate GENEVE packets when DNS Security retransmitted a DNS query after receiving a verdict from the cloud. + +## PAN-313623 + +Fixed an issue where the /opt/pancfg/mgmt/ssl/private/ directory on Palo Alto Networks devices with TPM support became 100% utilized due to an accumulation of undeleted .pub_pem files. This occurred because executing the show device-certificate status CLI command initiated a process that generated these files but failed to remove them, which prevented the fetching of new device certificates. + +## PAN-313606 + +Fixed an issue where Panorama pushed commits took longer than expected to complete without displaying an error message when committing due to slow cloud-app compilation. + +## PAN-312514 + +Fixed an issue where correlation logs were not forwarded via syslog or email. + +## PAN-312354 + +Fixed an issue where Captive Portal authentication redirects failed for HTTPS traffic when a user attempted to access internal HTTPS websites via URL, which led to **ERR_CONNECTION_RESET** error messages in the browser with SSL decryption and CTD handshake inspection enabled. + +## PAN-311938 + +Fixed an issue where autocommits failed after an upgrade due to configuration memory allocation issues and 100% policy rule cache usage when both DNS Rewrite and URL Custom Category Match were configured. + +## PAN-311040 + +Fixed an issue where the all_task process stopped responding and caused the firewall to reboot unexpectedly. + +## PAN-310851 + +Fixed an issue where firewalls experienced snmpd log flooding with messages such as update_ifTable_utilization_rates(pan_interfacecache.c:1720): Last time is 0 for dedicated-ha2., which caused the snmpd log to overflow and be cleared every five minutes. This occurred because the snmpd process attempted to calculate interface utilization rates without first verifying if the interface had valid sysd configuration data, as the code incorrectly assumed all interfaces in the MIB would possess valid sysd data. + +## PAN-308564 + +Fixed an issue where packets were dropped on SD-WAN interfaces when a proxy was enabled due to an MTU inconsistency where the firewall failed to rewrite the maximum segment size in SYN/ACK packets based on the SD-WAN virtual interface MTU. + +Note: This fix does not apply when the traffic egress interface is SD-WAN Direct Internet Access (DIA) interface and proxy is enabled. + +## PAN-308377 + +```caveat +PA-7000 Series firewalls with an LFC in HA configurations only +``` + +Fixed an issue where the firewall reached 100% disk utilization due to the logrcvr process repeatedly restarting and dumping core files due to a blocked hints processing thread, which caused a failover. + +## PAN-304360 + +Fixed an issue where the firewall did not redistribute its application routes to BGP peers. This occurred in multi-mesh deployments with the multi-cloud networking feature enabled. + +## PAN-302855 + +Fixed an issue where multiple processes restarted which caused the firewall to become unstable when processing traffic. + +## PAN-302512 + +```caveat +Log Collectors in HA configurations only +``` + +Fixed an issue where log collectors displayed a disconnected inter-log collector status. + +## PAN-300615 + +Fixed an issue where the pan_comm process stopped after multiple content versions were installed and the memory limits were reached. + +## PAN-296635 + +Fixed an issue where the reportd process on passive Panorama management servers leaked memory due to scheduled report handling from the Strata Logging Service (SLS). This memory leak occurred daily, consuming available memory until the process was restarted. + +## PAN-295806 + +Fixed an issue where memory leaks on the configd process occurred due to a hash insert operation failing during connection management and SSL connections. + +## PAN-294998 + +Fixed an issue where the LogDB incorrectly reported that the database quota for extpcap logs was reached. + +## PAN-289757 + +Fixed an issue where policy rule imports were blocked when **any** was in the source device column, which prevented the use of inbound policy rule recommendations. Additionally, when the source profile name was missing for inbound behaviors, a default policy rule name was not able to be generated. + +## PAN-282335 + +Fixed an issue where firewalls in a cluster experienced approximately 50% packet loss on IPSec NATT tunnels when tunnel acceleration was enabled. + +## PAN-273805 + +Fixed an issue where SAML authentication for GlobalProtect failed when the GlobalProtect portal was accessed externally on a non-standard port. + +## PAN-273028 + +Fixed an issue where manual SCP exports from firewalls in FIPS mode were successful to SCP servers that were not FIPS-compliant. This occurred because the manual SCP process did not enforce FIPS security checks. + +## PAN-260661 + +Fixed an issue where daily email reports generated from the custom report did not display the report details in PDF or CSV files. diff --git a/web/data/products.json b/web/data/products.json index b09d10b..6ade5e3 100644 --- a/web/data/products.json +++ b/web/data/products.json @@ -13,7 +13,8 @@ "12.1.4-h5.md", "12.1.4-h6.md", "12.1.5.md", - "12.1.6.md" + "12.1.6.md", + "12.1.7.md" ], "known": [ "12.1.2.md", @@ -79,6 +80,7 @@ "11.2.10-h6.md", "11.2.10-h7.md", "11.2.10-h8.md", + "11.2.10-h10.md", "11.2.11.md", "11.2.12.md" ], @@ -159,6 +161,8 @@ "11.1.6-h25.md", "11.1.6-h29.md", "11.1.6-h32.md", + "11.1.6-h33.md", + "11.1.6-h34.md", "11.1.7.md", "11.1.7-h1.md", "11.1.7-h2.md", @@ -177,6 +181,8 @@ "11.1.10-h21.md", "11.1.10-h25.md", "11.1.10-h26.md", + "11.1.10-h27.md", + "11.1.10-h28.md", "11.1.11.md", "11.1.12.md", "11.1.13.md", @@ -185,6 +191,8 @@ "11.1.13-h3.md", "11.1.13-h5.md", "11.1.13-h6.md", + "11.1.13-h7.md", + "11.1.13-h8.md", "11.1.14.md", "11.1.15.md" ], @@ -633,7 +641,8 @@ "6.3.3-h7.md", "6.3.3-h8.md", "6.3.3-h9.md", - "6.3.3-h11.md" + "6.3.3-h11.md", + "6.3.3-h12.md" ], "known": [ "6.3.1.md", @@ -651,13 +660,13 @@ "addressed": [ "6.2.3-c287.md", "6.2.6-c857.md", - "6.2.8-c223.md", "6.2.1.md", "6.2.2.md", "6.2.3.md", "6.2.4.md", "6.2.5.md", "6.2.6.md", + "6.2.7.md", "6.2.8.md", "6.2.8-h1.md", "6.2.8-h2.md", @@ -666,7 +675,8 @@ "6.2.8-h5.md", "6.2.8-h6.md", "6.2.8-h7.md", - "6.2.8-h9.md" + "6.2.8-h9.md", + "6.2.8-h11.md" ], "known": [ "6.2.3-c287.md",