Add 8.1 issues data

This commit is contained in:
2026-03-20 16:44:27 -05:00
parent c562392486
commit 77b13aa7ca
27 changed files with 5272 additions and 1 deletions
@@ -0,0 +1,130 @@
---
type: Addressed
product: PAN-OS
version: 8.1.0
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-92893
Fixed an issue that occurred during the reboot process and caused some firewalls to go in to maintenance mode.
## PAN-92268
```caveat
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls only
```
Fixed an issue where one or more dataplanes did not pass traffic when you ran several operational commands (from any firewall user interface or from the Panorama™ management server) while committing changes to device or network settings or while installing a content update.
## PAN-91774
Fixed an issue on Panorama virtual appliances for AWS in a high availability (HA) configuration where the primary peer did not synchronize template changes to the secondary peer.
## PAN-91429
Fixed an issue where PA-5200 Series firewalls rebooted when you ran the set ssh service-restart mgmt CLI command multiple times.
## PAN-91361
Fixed an issue where client connections initiated with HTTP/2 failed during SSL Inbound Inspection decryption because the firewall removed the Application-Layer Protocol Negotiation (ALPN) extension within the server hello packet instead of forwarding the extension to the client.
## PAN-91236
Fixed an issue where the Panorama management server did not display new logs collected on M-Series Log Collectors because the logging search engine did not register during system startup when logging disk checks and RAID mounting took longer than two hours to complete.
## PAN-90954
A security-related fix was made to prevent a local privilege escalation vulnerability that could potentially result in the deletion of files (CVE-2018-9242).
## PAN-90842
Fixed an issue where commits failed after you changed the default **Size Limit** to a custom value for MacOSX files that the firewall forwarded to WildFire® (**Device** > **Setup** > **WildFire**).
## PAN-90835
A security-related fix was made to prevent a Cross-Site Scripting (XSS) attack through the PAN-OS® session browser (CVE-2018-7636).
## PAN-90521
Fixed an issue on the Panorama management server where Device Group and Template administrators could not display or edit the **Device** > **Log Settings** in a template.
## PAN-90168
Fixed an issue where, after you downgraded a firewall from PAN-OS 8.1 to a previous PAN-OS release and then clicked **Revert Content** on the Panorama management server (**Panorama** > **Device Deployment** > **Dynamic Updates**) the Current Version column displayed the content release version of the firewall when it ran PAN-OS 8.1 regardless of the content version currently installed on the firewall.
## PAN-89471
Fixed an issue where firewalls rebooted because the userid process restarted too often due to a socket binding failure that caused a memory leak.
## PAN-89030
Fixed an issue where the firewall could not authenticate to a hardware security module (HSM) partition when the partition password contained special characters.
## PAN-88292
Fixed an issue on Panorama management servers in an HA configuration where the Log Collector that ran locally on the passive peer did not forward logs to syslog servers.
## PAN-88200
Fixed an issue where firewalls with multiple virtual systems did not import external dynamic lists that you assigned to policy rules.
## PAN-88018
Fixed an issue on Panorama M-Series and virtual appliances where the firewall was not able to override the local device configuration and failed to apply Dynamic Updates with an interval set to none.
## PAN-86873
Fixed an issue where the firewall advertised the OSPF not-so-stubby area (NSSA) link-state advertisement (LSA) type 7 default route to NSSA neighbors even when the OSPF backbone area was down.
## PAN-85410
Fixed two issues on a firewall configured for GlobalProtect™ Clientless VPN:
- The firewall dataplane restarted when client cookies contained a path that did not start with a forward slash (/).
- The firewall did not properly reinitialize client cookies that had a missing path and domain and instead used values from previously received cookies.
## PAN-84836
A security-related fix was made to address a Cross-Site Scripting (XSS) vulnerability in the PAN-OS response to a GlobalProtect gateway (CVE-2018-10139).
## PAN-84045
Fixed an issue where VM-Series firewalls in a high availability (HA) configuration with Data Plane Development Kit (DPDK) enabled experienced HA path monitoring failures and (in active/passive deployments) HA failover.
## PAN-83900
Fixed an issue where the Panorama management server did not run **ACC** reports or custom reports because the reportd process stopped responding when an administrator tried to access a device group to which that administrator did not have access.
## PAN-82942
Fixed an issue where the firewall rebooted because the User-ID™ process (useridd) restarted several times when endpoints, while requesting services that could not process HTTP 302 responses (such as Microsoft update services), authenticated to Captive Portal through NT LAN Manager (NTLM) and immediately disconnected.
## PAN-81417
Fixed an issue on the Panorama management server where, after an administrator selected **Force Template Values** when editing Push Scope selections (**Commit** > **Push to Devices**), the setting persisted as enabled for that administrator in all subsequent push operations instead of defaulting to disabled. With this fix, **Force Template Values** is disabled by default for every push operation until, and only if, the administrator manually enables the setting.
## PAN-80794
A protocol-related fix was made to address a bug in the OSPF protocol.
## PAN-80569
Fixed an issue where firewalls could not connect to M-500 or M-600 appliances in PAN-DB mode due to certificate validation failures. With this fix, the appliances add an IP address to the Subject Alternative Name (SAN) field when generating the certificates used for firewall connections.
## PAN-80505
Fixed an issue where a firewall was able connect to Panorama using an expired certificate.
## PAN-75775
Fixed an issue where SNMP managers indicated syntax errors in PAN-OS MIBs, such as forward slash (/) characters not used within quotation marks (“”). You can find the updated MIBs at [https://docs.paloaltonetworks.com/resources/snmp-mib-files](https://docs.paloaltonetworks.com/resources/snmp-mib-files).
## PAN-73316
Fixed an issue where a GlobalProtect user first logged in with a RADIUS authentication profile, the Domain-UserName appeared as user@domain (instead of domain\user) in the PAN-OS web interface.
## PAN-73154
Fixed an issue on the Panorama management server where commit operations stopped progressing after reaching 99 per cent completion.
@@ -0,0 +1,363 @@
---
type: Addressed
product: PAN-OS
version: 8.1.10
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-120548
Fixed an issue where the Captive Portal request limit was ignored when you configured the Captive Portal authentication method to browser-challenge.
## PAN-120409
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where firewalls running a 20G Network Processing Card (NPC) or a 20GQ NPC dropped stream control transmission protocol (SCTP) connections due to incorrect session handling.
## PAN-119257
Fixed an issue where the firewall could not establish an IKEv2 connection with SHA256 certificates.
## PAN-119030
Fixed an issue on Panorama™ M-Series and virtual appliances where bootstrapped managed firewalls were disconnected after you performed a partial revert if you did not first perform a manual commit. With this fix, the manual commit is not required.
## PAN-118656
Fixed an issue where the ifAdminStatus object identifier (OID) for dedicated high availability (HA) interfaces incorrectly displayed as up when interfaces were not used in an HA configuration.
## PAN-118423
Fixed an intermittent issue with local HA status changes where the mprelay process failed to commit changes to the HA state.
## PAN-118411
Fixed an issue where ARP entries took longer than expected to age out in a single run.
## PAN-118351
```caveat
PAN-OS 8.1.7, 8.1.8, and 8.1.9 only
```
Fixed an issue where log forwarding stopped responding when you configured a second log collector to the collector group.
## PAN-118008
```caveat
PA-3000 Series firewalls only
```
Fixed an intermittent issue where a low memory condition prevented decoders from loading, which led to traffic inspection issues related to the impacted decoder(s).
## PAN-117921
Fixed an issue where you were unable to create GTP inner sessions, which caused the firewall to drop GTP-U data packets when the firewall was deployed on S1-U and S-11 interfaces.
## PAN-117916
Fixed an issue where the dataplane stopped responding when you pushed permitted IP addresses from Panorama to managed firewalls.
## PAN-117818
```caveat
PA-5200 Series firewalls only
```
Fixed a rare issue where an initialization delay with a process (brdagent) caused the dataplane to stop responding.
## PAN-116969
Fixed an issue where authentication failed when you configured a User Principal Name (UPN) and included a group in the profile.
## PAN-116807
```caveat
PA-7000, PA-5200, and PA-3200 Series firewalls only
```
Fixed an issue where the firewall dropped ICMP error messages when the security policy was configured to allow ICMP
## PAN-116218
Fixed an issue where test routing bgp virtual-router default restart peer <peer-ID> CLI command did not execute the operational request and returned the following error message: op command for client routed timed out as client is not available.
## PAN-115856
Fixed an issue where Dynamic IP and Port (DIPP) NAT pools did not release used ports after all sessions were removed.
## PAN-115852
Fixed an issue on VM-Series firewalls on AWS where you could not change maximum transmission unit (MTU) values from the web interface and displayed the following error message: Malformed Request.
## PAN-115812
Fixed an issue where the child session did not inherit policy-base forwarding information when the parent session is allocated to separate dataplanes.
## PAN-115748
Fixed an intermittent issue on Panorama M-Series and virtual appliances where a memory issue caused the firewall to reboot.
## PAN-115695
Fixed an intermittent issue where a large number of packets were received before acknowledgments were complete, which depleted descriptor queue entries and resulted in high latency during data transfers even though CPU usage looked normal.
## PAN-115354
Fixed an issue on Panorama M-Series and virtual appliances where renaming a device group followed by a partial commit did not change the device group hierarchy as expected.
## PAN-115219
Fixed an issue on Panorama M-Series and virtual appliances where Global Find caused the web interface to stop responding when you searched for common English words.
## PAN-115186
Fixed an issue where SaaS reports were not generated due to report definitions not getting pushed to the log collector.
## PAN-115160
Fixed an issue where a UDP packet without a payload did not trigger the multi-factor authentication (MFA) and was not discarded based on the authentication policy.
## PAN-115012
Fixed an issue where a process (appweb) stopped responding, which caused the web interface to stop responding.
## PAN-114958
Fixed an issue where the User-ID™ (useridd) process consumed more CPU cycles than expected when you configured User-ID redistribution.
## PAN-114855
Fixed an issue where the firewall dropped syslog packets after you upgraded to PAN-OS® 8.1.6.
## PAN-114844
Fixed an issue on Panorama M-Series and virtual appliances where malformed API calls caused the appliance to reboot.
## PAN-114779
Fixed an issue where log purging took longer than expected, which prevented the firewall from capturing traffic logs.
## PAN-114695
Fixed an issue where a daemon (authd) stopped responding when you configured a GlobalProtect™ portal and gateway with Security Assertion Markup Language (SAML) authentication.
## PAN-114567
Fixed an issue where a system query (Eventideq globalprotectportal-config-succ) caused the management server (mgmtsrvr) process to stop responding.
## PAN-114533
Fixed an issue where traffic was blocked by safe search enforcement before matching the intended allow rule.
## PAN-114526
Fixed an issue where larger than expected number of packets sent over a GTP-U tunnel caused packet captures to fill the files faster than expected. With this fix, you can run the debug dataplane packet-diag set capture gtpu-lvl[1-30] command to ensure GTP-U traffic are captured.
## PAN-114475
Fixed an issue where Panorama in FIPS mode defaulted to FIPS-CC mode instead of Normal mode.
## PAN-114395
Fixed an issue on a VM-Series firewall where a process (all_task) stopped responding, which caused the firewall to reboot.
## PAN-114264
Fixed an issue where sessions were offloaded as the application identification was performed when you configured a custom application with **Continue scanning for other application**.
## PAN-114222
Fixed an issue where the firewall dropped traffic logs due to a negative log counter reading.
## PAN-114160
Fixed an issue where you were unable to download ZIP files greater than 3GB through a GlobalProtect Clientless VPN application.
## PAN-114105
Fixed an issue on a Panorama M-Series appliance where the Summary (**Panorama** > **Managed Devices** > **Summary**) web interface refreshes every 10 seconds when set to manually refresh.
## PAN-114090
Fixed an issue on a Panorama virtual appliance in Legacy mode and in an HA active/passive configuration where logs were forwarded only to the active HA peer.
## PAN-114002
Fixed an issue where you were unable to import variable CSV files when variable names contained a character space.
## PAN-113930
Fixed an issue on VM-Series firewalls where CPU loads were uneven across cores when more than 8 cores were allocated to the dataplane.
## PAN-113912
Fixed an issue where a process (ikemgr) stopped responding and caused the firewall to reboot.
## PAN-113887
Fixed an issue where loading custom app tags did not complete successfully, which prevented subsequent requests (such as commits, content installs, and FQDN refreshes) from executing as expected.
## PAN-113870
Fixed an issue where Security policies were not evaluated in sequential order when the policy was based on URL categories.
## PAN-113796
Fixed an issue where GlobalProtect configured with the **pre-logon then on-demand** connect method was unable to authenticate during pre-logon when you configured the portal and gateway with an Authentication Override and without a certification profile.
## PAN-113767
Fixed an issue where the firewall silently dropped packets when Security profiles were attached and FPGA enabled AHO and DFA.
## PAN-113501
Fixed an issue where the Panorama management server returned a Security Copy (SCP) server connection error after you created an SCP Scheduled Config Export profile (**Panorama** > **Scheduled Config Export**) due to the SCP server password exceeding 15 characters in length.
## PAN-113356
Fixed an issue where the web interface did not populate the Virtual System Name column (**Monitor** > **Manage Custom Reports <monitor-name>** > **Run Now**) when you generated reports from the application statistics database.
## PAN-113229
Fixed an issue on Panorama M-Series and virtual appliances in an HA active/passive configuration where the passive HA peer displayed an out-of-sync shared policy status when you edited the Device Group.
## PAN-113185
Fixed an issue where the passive firewall in an HA active/passive configuration was processing traffic.
## PAN-113096
Fixed an issue where incorrect serial numbers were generated when you created VM-Series firewalls on AWS and swapped the interface with the mgmt-interface-swap=enable CLI command.
## PAN-112988
Fixed an issue where a process (useridd) leaked memory, which caused the firewall to drop traffic and display the following error message: Out-of-memory condition detected, kill process.
## PAN-112972
Fixed an issue where scheduled reports were not generated as expected when you added groups in a query builder.
## PAN-112566
Fixed an issue where the GlobalProtect Client was unable to download files from a web interface and sessions went into DISCARD state and displayed the following message: Packet dropped, control plane service not allowed.
## PAN-112529
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall incorrectly received several alerts.
## PAN-112467
Fixed an issue where obsolete IPv6 Neighbor Discovery (ND) entries did not clear as expected, which caused the IPv6 table to reach full capacity and caused new IPv6 ND entries to fail.
## PAN-112308
Fixed an issue where hardware security module (HSM) accounts were locked out after three attempts when you ran the show hsm ha-status CLI command.
## PAN-112293
Fixed an issue where the connection between the firewall and Log Collector flapped.
## PAN-112016
Fixed an issue on VM-Series firewalls where the physical port counters on the dataplane interfaces did not increase on KVM when you disabled DPDK.
## PAN-111660
Fixed an issue where an incorrect SSH key initialization caused a process (pan_comm) to stop responding every 15 minutes when you configured an SSH proxy on the firewall.
## PAN-111380
```caveat
PA-3200, PA-5200, and PA-7000 Series firewalls with 100Gbps cards only
```
Fixed an issue where the show qos interface ae1 throughput 0 CLI command incorrectly displayed the active data stream only and QoS was not working as expected on the first subinterface.
## PAN-110990
Fixed an issue where a logical operation not configured with receive_time in the traffic log filter did not respond as expected.
## PAN-110960
Fixed an issue on Panorama M-Series and virtual appliances where commits failed when you configured an address group object in the Include List (**Network** > **Zone** > **<zone-name>** > **Include List**).
## PAN-110839
Fixed a rare issue where a commit pushed from Panorama failed, which caused a process (routed) to stop responding.
## PAN-110304
Fixed an issue where the dataplane restarted due to a callback function, which caused a deadlock condition.
## PAN-110234
Fixed an issue where administrators with a Superuser (read-only) role was able to initiate a commit through the CLI.
## PAN-109861
Fixed an issue where BGP route attributes were processed from BGP updates, which caused the firewall to stop responding.
## PAN-109457
Fixed an issue where the firewall duplicated address objects when you imported a configuration to Panorama.
## PAN-109270
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall processed a high rate of packets.
## PAN-107786
Fixed an issue where you were unable to import variable CSV files when the external gateway was configured with a source region of **Any**.
## PAN-107779
Fixed an issue where Wildfire® signature version information was no longer displayed after you activated a GlobalProtect client.
## PAN-106628
Fixed an issue where the firewall did not generate a system log when the firewall detected a RAM issue.
## PAN-106449
Fixed an issue when you connected to an internal GlobalProtect gateway on a firewall in an HA active/passive configuration and authenticated with multi-factor authentication (MFA) to access a resource where the first and second authentication factors succeeded but you would not be redirected to the actual resource.
## PAN-105286
Fixed an issue where the firewall did not record email header information in Data Filtering logs when you triggered a test mail that contained a data leak prevention (DLP) pattern.
## PAN-104808
Fixed an issue where scheduled SaaS reports generated and emailed empty PDF reports.
## PAN-104454
Fixed a memory leak issue with the User-ID (useridd) process when you enabled VM Monitoring.
## PAN-103865
Fixed an issue where the firewall did not detect user credentials when the number of users exceeded 60,000. To leverage this fix, you must upgrade Windows agents to User-ID agent 8.1.11 or a later User-ID agent 8.1 release.
## PAN-104251
Fixed an issue where the syslog server TCP keep-alive parameter caused the connection to unexpectedly age out.
## PAN-101613
```caveat
PA-800 Series firewalls only
```
Fixed an intermittent congestion condition caused by paused frames on firewalls where flow control was enabled on adjacent firewalls. To leverage this fix, run the set system setting hol-system enable CLI command to enable head-of-line (HOL) system mode.
## PAN-98974
Fixed an issue where the export function (**Panorama** > **Managed Devices** > **Summary** > **Manage**) was not available for managed devices.
## PAN-50031
Fixed an issue where the show wildfire local statistics CLI command incorrectly returned samples pending analysis when there were no actual samples pending.
@@ -0,0 +1,515 @@
---
type: Addressed
product: PAN-OS
version: 8.1.12
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-133443
Fixed an issue where an XML API call incorrectly masked the response, which prevented role based administrators from running the response.
## PAN-132501
Fixed an issue where after you switched the **Context** from Panorama™ to a firewall, the DESTINATION ZONE (**Policies** > **Security** > **<policy-name>** > **Destination**) incorrectly displayed none.
## PAN-132104
Fixed an issue on Panorama M-Series and virtual appliances where the <show><object><registered-ip></registered-ip></object></show> XML API call did not retrieve more than 500 entries.
## PAN-131054
Fixed an issue where the DNS packet parser incorrectly processed DNS packet headers when the QD count was 0. With this fix, the DNS packet parser aborts processing when QD!= 1.
## PAN-130073
Fixed an issue where a large number (65,000) of GlobalProtect™ user connections caused a process (sslvpn) to stop responding after you upgraded from PAN-OS® 8.1.10 to PAN-OS 8.1.11.
## PAN-129504
Fixed an issue where an incorrect commit job in the queue caused the FQDN to display Not resolved after you performed a commit.
## PAN-128324
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where internal path monitoring failures occurred due to either a buffer leak or buffer corruption.
## PAN-128269
```caveat
PA-5250, PA-5260, and PA-5280 firewalls with 100GB AOC cables only
```
Fixed an issue where after you upgraded the first peer in a high availability (HA) configuration to PAN-OS 8.1.9-h4 or a later] release, the High Speed Chassis Interconnect (HSCI) port did not come up due to an FEC mismatch until after you finished upgrading the second peer.
## PAN-127649
Fixed an issue where a purge script stopped responding, which caused a process (logrcvr) to discard incoming logs.
## PAN-127089
Fixed an intermittent issue where the default route did not redistribute to an OSPF Not-So-Stubby Area (NSSA).
## PAN-127055
Fixed an issue on a VM-Series firewall deployed in Microsoft Azure where the CPU ID and serial number changed after you upgraded from PAN-OS 8.0.13 to PAN-OS 8.1.9-h4.
## PAN-126921
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where internal path monitoring failed when the firewall processed corrupt packets.
## PAN-126627
Fixed an issue where a process (all_pktproc) stopped responding due to a NULL pointer exception while cleaning up SSL proxy sessions previously configured for GlobalProtect.
## PAN-126534
```caveat
PAN-OS 8.1.10 and later releases only
```
Fixed an issue where the data from Security policies did not export as expected.
## PAN-126283
Fixed an intermittent issue where after you configured **Cache EDNS Responses** (**Network** > **DNS Proxy** > **<DNS Proxy-name>** > **Advanced**) a process (dnsproxy) stopped responding.
## PAN-126159
Fixed an issue where the firewall did not match the Security policy when you configured the match condition to a shared local group.
## PAN-125898
Fixed an issue where a process (openssl) caused higher than expected management CPU usage due to the incompletion of the Online Certificate Status Protocol (OCSP) during the logging service certificate validation.
## PAN-125833
Fixed an issue on a firewall in an HA active/passive configuration where a daemon (routed) did not receive the updated interface status after an HA failover, which caused routes to remain in the routing and FIB tables.
## PAN-125793
Fixed an issue where multiple No valid URL filtering license warning messages were generated during a commit due to an expired URL filtering license. With this fix, the warning messages are grouped into a single message per virtual system (vsys).
## PAN-125746
Fixed an issue where commits failed and displayed the following error message: priority is invalid when you configured the GlobalProtect priority to **None**.
## PAN-125515
Fixed an issue on VM-Series firewalls where the firewall dropped all traffic traversing from the dataplane to the management plane.
## PAN-125478
Fixed an issue on a firewall in an HA active/passive configuration where the route to the passive firewall dropped during a failover.
## PAN-125302
Fixed an issue where the real-time clock (RTC) battery voltage exceeded the maximum threshold and triggered alerts in the system log.
## PAN-125018
Fixed an issue on Panorama M-Series and virtual appliances where after you configure the firewall with an API call commits took longer than expected.
## PAN-124890
Fixed a configuration lock issue where you were unable to log in after you upgraded from PAN-OS 8.1.6 to PAN-OS 8.1.9.
## PAN-124882
Fixed an issue where traffic logs that contained incorrect Security policies were generated during an active commit process when the Security policies were being added or removed.
## PAN-124630
Fixed an issue where new logs were not ingested due to a buffer exhaustion condition caused by invalid messages incorrectly handled by elastic search.
## PAN-124593
A fix was made to address a missing XML validation vulnerability in the PAN-OS web interface ([CVE-2020-1975](https://security.paloaltonetworks.com/CVE-2020-1975)).
## PAN-124435
Fixed an issue where the firewall dropped pre-VLAN spanning tree (PVST+) packets from the virtual wire interface when you executed the set session rewrite-pvst-pvid yes CLI command.
## PAN-123661
A fix was made to address an authentication bypass vulnerability in the Panorama context switching feature ([CVE-2020-2018](https://security.paloaltonetworks.com/CVE-2020-2018)).
## PAN-123322
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls running PAN-OS 8.1.11 only
```
Fixed an intermittent issue where a process (all_pktproc) stopped responding due to a Work Query Entry (WQE) corruption that was caused by duplicate child sessions.
## PAN-123306
Fixed an issue where the **Dashboard** did not display the release dates for Application Version, Threat Version, and Antivirus Version.
## PAN-123220
Fixed an issue on a firewall running snmpwalk where 100GB interfaces were incorrectly displayed as 1GB.
## PAN-123190
Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) restarted multiple times and caused the firewall to reboot.
## PAN-123167
Fixed an issue where a process (mprelay) stopped responding.
## PAN-122804
Fixed an issue on Panorama M-Series and virtual appliances where the firewall stopped forwarding logs to Cortex Data Lake after you upgraded the cloud services plugin to 1.4.
## PAN-122788
Fixed an issue where the firewall incorrectly logged target filenames when an antivirus signature was triggered over a Server Message Block (SMB) protocol.
## PAN-122779
Fixed an issue where the firewall did not respond to TCP DNS requests when the firewall acted as a DNS proxy.
## PAN-122455
Fixed an issue where the DHCP server incorrectly processed bootp unicast flag requests.
## PAN-122311
Fixed an issue where parent sessions were dropped while installing a duplicate predict session.
## PAN-122181
```caveat
PA-3200 Series and PA-5200 Series firewalls only
```
Fixed an issue where the firewall did not capture inbound Encapsulating Security Payload (ESP) protocol 50 packets at the receive stage.
## PAN-121917
```caveat
PA-800 Series and PA-220 firewalls only
```
Fixed an issue where the hrProcessorLoad.2 OID displayed incorrect values.
## PAN-121609
```caveat
PA-7000 Series firewalls using PA-7000-20G-NPC cards only
```
Fixed an issue where the firewall restarted due to an internal path monitoring heartbeat failure during periods of more than expected traffic load.
## PAN-121484
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
Fixed an issue where the dataplane sent positive acknowledgments to predict-status checks from FPP when the corresponding predict was deleted, which caused SIP and RTSP applications to perform less than the expected achievable performance.
## PAN-121481
Fixed an issue where downloading the GlobalProtect app software on your GlobalProtect portal took longer than expected.
## PAN-121472
Fixed an intermittent issue where the dataplane stopped responding when processing compressed traffic.
## PAN-120986
Fixed an issue where a process (routed) stopped responding when you configured virtual interfaces.
## PAN-120965
Fixed an issue where certificate revocation list (CRL) and Online Certificate Status Protocol (OCSP) checks did not respond as expected when you configured **Block session if certificate status is unknown**.
## PAN-120900
Fixed an issue on a firewall in an HA active/passive configuration where after you submitted a host information profile (HIP) report a duplicate User-ID™ log was generated on the passive firewall.
## PAN-120893
Fixed an issue where the Security Parameter Index (SPI) size was incorrectly set in the IKE Phase 2 packet when you configured **commit-bit** on the neighboring device, which caused IKE negotiations to fail on the neighboring device.
## PAN-120701
Fixed an issue where URL filtering blocked web traffic by the security policy that did not have URL filtering enabled.
## PAN-120545
Fixed an issue on VM-Series firewalls where the ager ran faster than expected, which prematurely caused the master key to expire.
## PAN-120397
A fix was made to address an external control of path and data vulnerability in the Palo Alto Networks Panorama XSLT processing logic ([CVE-2020-2001](https://security.paloaltonetworks.com/CVE-2020-2001)).
## PAN-120351
Fixed an issue where the firewall caused unnecessary fragmentation when traffic and tunnel were content inspected, which caused retransmission and slowed response time.
## PAN-120300
Fixed an issue where you were unable to view DHCP leases from the web interface or through the show dhcp server lease interface all CLI command due to the request taking longer than expected, which resulted in a time out.
## PAN-120106
Fixed an issue where Panorama did not send correlation events and logs to the syslog server after you upgraded the firewall from PAN-OS 8.0.9 to PAN-OS 8.1.7.
## PAN-120005
Fixed an issue where the firewall incorrectly forwarded incomplete and corrupted files through the Server Message Block (SMB) protocol to WildFire.
## PAN-119950
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where a process (flow_ctrl) received and restarted due to a malformed ICMPv6 neighbor advertisement packet.
## PAN-119822
Fixed an issue where you were not redirected to the application URL after authentication.
## PAN-119820
Fixed an issue where the firewall incorrectly calculated the TCP segment size when performing forward proxy decryption.
## PAN-119819
Fixed an issue where **Discover** (**Device** > **User Identification** > **User Mapping** > **Server Monitoring**) stopped responding after you configured a DNS proxy.
## PAN-119818
Fixed an issue where corrupt logs caused buffered log forwarding to stop responding.
## PAN-119550
Fixed an issue on Panorama M-Series and virtual appliances where communication between two processes (mgmtsrvr and logd) stopped responding.
## PAN-119452
An enhancement was made to improve subsequent loading times of device groups after the first load.
## PAN-119349
Fixed an issue on Panorama M-Series and virtual appliances where custom reports from the User-ID log displayed the incorrect receive date.
## PAN-119343
Fixed an issue where a daemon (dnsproxy) incorrectly handled TCP requests, which caused the daemon (dnsproxy) to stop responding.
## PAN-119185
Fixed an issue where a process (panio) caused more than expected CPU consumption.
## PAN-119047
Fixed an issue where local user group names that contained upper case characters were not converted to lower case characters prior to encoding, which caused the firewall not to load user groups names with upper case characters.
## PAN-118851
Fixed an issue where the BGP Conditional Advertisement suppress condition was not met, which caused the **Conditional Adv** (**Network** > **Virtual Routers** > **<router-name>** > **BGP**) not to apply the NEXT HOPS prefix range.
## PAN-118777
Fixed an issue on a firewall in a high availability (HA) active/active configuration where larger than expected packets sizes were silently dropped when traversing through an HA3 link in an asymmetric network.
## PAN-118762
Fixed an issue where the GlobalProtect portal used an outdated jQuery library.
## PAN-118436
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where applications using the GlobalProtect Clientless VPN did not respond when the Clientless VPN used a VLAN interface.
## PAN-118430
Fixed an issue where pushed template configurations were overridden when you made a configuration change in the Master Key **Lifetime** (**Device** > **Master Key and Diagnostic** > **Edit**) field.
## PAN-118413
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the show system logd-quota CLI command did not display the Session log storage Quotas as expected.
## PAN-118259
Fixed an issue where you were unable to generate WildFire analysis reports in the WildFire Submissions log when you configured **Proxy Server** (**Device** > **Setup** > **Services** > **Global**).
## PAN-118249
Fixed an issue where traffic logs and URL Filtering logs did not display the URL for decrypted traffic.
## PAN-118207
Fixed an issue where the Security Assertion Markup Language (SAML) for GlobalProtect did not respond as expected when you configured the IdP certificate as **None** on the SAML IdP server profile.
## PAN-118108
Fixed an issue where an API call against a Panorama management server, which triggered the request analyze-shared-policy command caused Panorama to reboot after you executed the command.
## PAN-118090
Fixed an issue on Panorama M-Series and virtual appliances where **User Activity Report** (**Monitor** > **PDF Reports**) did not generate reports as expected.
## PAN-118050
Fixed an issue where some packets had incorrect timestamps in the transmit stage during packet capture.
## PAN-117987
Fixed an issue where the firewall did not exclude video traffic from the GlobalProtect tunnel when you configured **Exclude video traffic from the tunnel (Windows and macOS only)** (**Network** > **GlobalProtect** > **Gateways** > **<gateway-name>** > **Agent** > **Video Traffic**).
## PAN-117969
An enhancement was made to enable administrators to select signature and digest algorithms for outgoing Security Assertion Markup Language (SAML) messages through a CLI command.
## PAN-117774
Fixed an Issue where the dataplane stopped responding due to an incorrect parsing of cookies for GlobalProtect Clientless VPN applications.
## PAN-117736
Fixed an issue on a firewall in an HA active/active configuration where virtual MAC addresses pushed from Panorama were overridden on the local firewall.
## PAN-117463
Fixed an issue where the firewall did not release the default DHCP route when a new IP address was obtained on a DHCP configured interface.
## PAN-117446
Fixed an issue where GlobalProtect authentication failed when you used the domain in the group mapping and a User Principle Name (UPN) format for authentication.
## PAN-117276
Fixed an issue on a firewall in a high availability (HA) active/active configuration where the names of the virtual routers were pushed from the active-primary firewall to the active-secondary firewall when you sync the configuration, which caused schema verification to stop responding when you do a local commit on the active-secondary firewall.
## PAN-117251
Fixed an issue where vsysadmins were unable to view the locks on all the virtual systems they were assigned to. To view the locks in CLI run the new show commit-locks vsys and show config-locks vsys CLI commands.
## PAN-117167
Fixed an issue where a process (configd) exceeded the memory limit and stopped responding.
## PAN-117068
Fixed an issue on Panorama M-Series and virtual appliances where memory utilization increased more than expected when you deleted several rules with an XML API delete command.
## PAN-116889
Fixed an issue where you were unable to establish an SSH session through a CLI command using a Diffie-Hellman (DH) algorithm.
## PAN-116634
Fixed an issue where the date in the GlobalProtect HTTP header was incorrectly set to a random date instead of a zero ( 0 ), which negatively and falsely impacted security scorecard ratings.
## PAN-116615
Fixed an issue where authentication failed for newly added groups in the authentication profile Allow List.
## PAN-116355
```caveat
PA-5200 Series firewalls only
```
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where an HA1 heartbeat backup connection flap occurred and displayed the following error message: ha_ping_send/No buffer space available.
## PAN-116173
```caveat
PA-7000 Series firewalls using PA-7000-20G-NPC or PA-7000-20GQ-NPC cards only
```
Fixed an intermittent issue on a firewall in an HA active/passive configuration where traffic interruptions occurred until you triggered a manual failover.
## PAN-116100
Fixed an issue where a process (mprelay) stopped responding and invoked an out-of-memory (OOM) killer condition and displayed the following error messages: tcam full and pan_plfm_fe_cp_arp_delete.
## PAN-116061
Fixed an issue where traffic traversing through an IPSec tunnel did not use the default maximum interface bandwidth, which caused the traffic to traverse through the IPSec tunnel with latency.
## PAN-115505
Fixed an issue where more than expected re-connection attempts to Cortex Data Lake caused the management plane CPU to spike and caused a process (mgmtsrvr) to stop responding.
## PAN-115238
Fixed an issue where SSL renegotiation sessions incorrectly identified URL categories.
## PAN-115110
An enhancement was made to enable you to configure syslog parameters through the CLI debug command. To view the available parameters and change the configurations, run the debug syslogng-params settings CLI command and perform a commit force to apply the edits.
## PAN-115018
Fixed an issue where the firewall was unable to access the CPU information and caused the CPU frequency to set to 0, which resulted in a divide by zero error and caused a process (devsrvr) to stop responding.
## PAN-114438
Fixed an issue where the system log incorrectly reported intermittent certificate revocation list (CRL) fetches as successful even though the fetches were not successful.
## PAN-112145
Fixed an intermittent issue where a process (useridd) incorrectly reported successful Ops commands and did not download Dynamic Address Group updates, which prevented virtual machines from updating Dynamic Address Groups.
## PAN-111650
Fixed an issue where a process (mgmtsrvr) stopped responding when another process (masterd) sent a signal interruption after you upgraded from a PAN-OS 8.0 release to a PAN-OS 8.1 release.
## PAN-111135
Fixed an issue where Panorama displayed incorrect device monitoring values (**Panorama** > **Managed Devices** > **Health**) for the firewall.
## PAN-109406
Fixed an issue where the firewall restarted when you unplugged the QSFP+ module from the High Speed Chassis Interconnect (HSCI) port.
## PAN-108373
Fixed an issue where an application dependency warning incorrectly displayed when you configured **negate-source yes** on a security rule to deny an application.
## PAN-108012
Fixed an issue on Panorama M-Series and virtual appliances where you could not add and generate a certificate as expected.
## PAN-107864
Fixed an issue where the Online Certificate Status Protocol (OCSP) check stopped responding when the leaf certificate was sent twice in the OCSP request.
## PAN-106029
Fixed an issue where the firewall tried to resolve deleted FQDN address objects after an FQDN refresh.
## PAN-105866
Fixed an issue on a firewall in an HA active/active configuration where ARP entries were removed from a floating IP address on an Ethernet interface when you deleted another floating IP address on the same Ethernet interface.
## PAN-105763
An enhancement was made to enable you to set the signing algorithm to sha-1 or sha-256 in the Security Assertion Markup Language (SAML) message on the firewall.
## PAN-100946
Fixed an issue where VM-Series firewalls were unable to support the maximum number of tunnel interfaces due to less than expected memory allocation.
## PAN-98603
Fixed an issue on Panorama M-Series and virtual appliances where logs sent by the Endpoint Security Manager (ESM) server were incorrectly ingested.
@@ -0,0 +1,415 @@
---
type: Addressed
product: PAN-OS
version: 8.1.13
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-136698
Fixed an issue where a process (all_pktproc) stopped responding and the dataplane restarted when the firewall processed a malformed GPRS tunneling protocol (GTP) packet.
## PAN-135260
```caveat
PA-7000 Series firewalls running PAN-OS 8.1.12 only
```
Fixed an intermittent issue where the dataplane process (all_pktproc_X) on a Network Processing Card (NPC) restarted when processing IPSec tunnel traffic.
## PAN-134678
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) 28 ports 21 and 22 did not respond when plugged in with a Finisar 100G AOC cable.
## PAN-133582
Fixed an issue on the firewalls where some Dynamic Address Groups pushed from Panorama were missing member IP addresses.
## PAN-133440
Fixed an issue where fragmented traffic caused high dataplane use and firewall performance issues.
## PAN-133436
Introduced the clear url-cache all CLI command to aggressively clear the dataplane URL cache.
## PAN-133378
Fixed an issue in Panorama where a process (configd) restarted during a commit using a RADIUS super admin role.
## PAN-133048
```caveat
PA-5200 and PA-7000 Series only
```
Fixed an issue where traffic was processed asymmetrically when using Internet Protocol (IP) classifiers on virtual wire (vwire) subinterfaces.
## PAN-133042
```caveat
PA-5200 and PA-7000 Series only
```
Fixed an issue where certain GPRS tunneling protocol (GTP) traffic was dropped even when gtp nodrop was enabled.
## PAN-131993
Fixed an issue where a process (reportd) stopped responding while running a log query.
## PAN-131907
Fixed an issue where GPRS tunneling protocol (GTP) version 2 handling was unable to handle fully qualified tunnel endpoint IDs (FTEID) coming in reverse order, leading to GTP-C and GTP-U flows with incorrect IP addresses and tunnel endpoint IDs (TEIDs). This caused a GTP stateful inspection failure for further packets on the respective flows.
## PAN-130773
Fixed an issue where users saw a page with a random phone number for authentication and could not proceed further in the authentication process when multi-factor authentication (MFA) was configured as the authentication portal.
## PAN-130640
Fixed an issue where the management plane CPU was high due to index generation on summary logs.
## PAN-130573
Fixed an issue where the software pool for Regex results was depleted and caused connection failures.
## PAN-130447
Fixed an issue where offloaded traffic was dropped by the firewall every time there was an explicit commit (**Commit** on the firewall locally or **Commit All Changes** in Panorama) or an implicit commit (Antivirus update, Dynamic Update, or WildFire update, and so on) was performed on the firewall.
## PAN-130345
Fixed an issue where the Panorama VM rebooted while filtering for configuration logs when the query value was not one of the predefined string results.
## PAN-130290
Fixed an issue where in the web interface, traffic logs did not display the destination zone (**Monitor > Logs > Traffic > To Zone**) for multicast sessions.
## PAN-130262
Fixed a rare issue where 200 OK messages were dropped during the offload of traffic for App-ID inspection.
## PAN-130229
Fixed an issue on Panorama appliances where you could not change maximum transmission unit (MTU) values from the web interface and displayed the following error message: Malformed Request.
## PAN-130069
Fixed an issue where the firewall incorrectly interpreted an external dynamic list MineMeld instability error code as an empty external dynamic list.
## PAN-129658
Fixed an issue where GTP inspection stopped functioning after unrelated changes in policy and a commit followed by a high availability (HA) failover.
## PAN-129518
Fixed an issue where the firewall restarted due to an out-of-memory condition caused by a leak in a process (ikemgr).
## PAN-129490
Fixed an issue where CRL/OCSP verifications failed due to requests routing through the management interface even when service route was configured.
## PAN-128908
If an admin user password was changed but no commit was performed afterward, the new password did not persist after a reboot. Instead, the admin user could still use the old password to log in, and the calculation of expiry days was incorrect based on the password change timestamp in the database.
## PAN-128856
Fixed an issue where the disk usage calculation was getting corrupted and purging logs.
## PAN-128717
Fixed an issue in Panorama where after switching context to a managed device, the session idle timeout was not being updated, and the web session timed out even when the administrator was actively working.
## PAN-128248
A fix was made to address a vulnerability with a race condition due to an insecure creation of a file in a temporary directory in PAN-OS ([CVE-2020-2016](https://security.paloaltonetworks.com/CVE-2020-2016)).
## PAN-127087
Fixed an issue in the firewalls where a push operation (**Commit All Changes**) from Panorama failed on the passive firewall when pushing a large number of security policy additions to both firewalls in an HA pair.
## PAN-126412
Fixed an issue where hardware security model (HSM) authentication from the web interface failed if the password contained an ampersand (&).
## PAN-126278
Fixed an issue where a burst of VLAN-tagged packets in a congested system caused an overflow and locked up the firewall. The threshold has been increased with this fix.
## PAN-126202
Fixed an issue where a process (routed) stopped responding when users accessed the web interface to view the OSPF interface data (**Network > Virtual Routers > More Runtime Stats > OSPF > Interface**) if OSPF MD5 was configured in the OSPF Auth profile.
## PAN-126069
Fixed an issue in Panorama where logs couldn't be viewed when an additional log collector was configured in the existing log collector group.
## PAN-126017
Fixed an issue where set application dump on rule CLI command did not accept rule names greater than 32 characters despite a stated limit of 63 characters.
## PAN-125804
A fix was made to address an issue where an OS command injection vulnerability in the PAN-OS management server allowed authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode ([CVE-2020-2028](https://security.paloaltonetworks.com/CVE-2020-2028)).
## PAN-125546
Fixed an issue where a process failed to restart even when the system logs displayed the following message: virtual memory exceeded, restarting.
## PAN-125306
Fixed an issue where a Transmission Control Protocol (TCP) connection reuse was incorrectly handled by a high availability (HA) active/active cluster with asymmetric flows.
## PAN-125243
Fixed an issue where the VM-Series firewall restarted due to a deadlock condition occurring when processing QoS-enabled L7 traffic.
## PAN-125194
Fixed an issue where system startup failed when the collector group was configured with an incorrect serial number of invalid length.
## PAN-125122
A fix was made to address a cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS and Panorama that disclosed an authenticated PAN-OS administrator's PAN-OS session cookie ([CVE-2020-2013](https://security.paloaltonetworks.com/CVE-2020-2013)).
## PAN-125032
Fixed an issue when **Minimum Password Complexity** was **Enabled** for all local administrators, the setting was also applied to plugin users. This caused API calls from plugin users to fail (HTTP Error code 502) because the password change was not made for the users and authentication failed.
## PAN-124802
Fixed an issue where LACP connectivity issues were observed due to high CPU utilization when multiple dataplanes were used.
## PAN-124621
A fix was made to address an issue where an OS command injection vulnerability in the PAN-OS web management interface allowed authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in the PAN-OS configuration ([CVE-2020-2029](https://security.paloaltonetworks.com/CVE-2020-2029)).
## PAN-124495
Fixed an issue on Panorama where the task manager showed locally executed jobs but did not show tasks or jobs pushed to managed firewalls.
## PAN-124428
Fixed an issue where Address Resolution Protocol (ARP) randomly failed on one of the interfaces for a firewall deployed in the KVM/GCP/ESXi clouds.
## PAN-124087
Fixed an issue where GPRS tunneling protocol (GTP) v2 protocol handling was not able to handle the secondary Modify Bearer Request/Response in the GTP-C session.
## PAN-123858
Fixed an issue on firewalls where a process (useridd) restarted while processing incorrect ip-user mappings that contained blank usernames from User-ID agents.
## PAN-123843
Fixed an issue for Cloud/VM platforms where the tunnels between the log collectors did not come up when a public IP was used for the log collectors in an environment with a Panorama management server and two or more log collectors.
## PAN-123830
Fixed an issue where the GlobalProtect™ portal used an outdated getbootstrap version.
## PAN-123747
Fixed an issue where App-ID signatures failed to match when there were more than 12 partial App-ID matches within the same session.
## PAN-123736
Fixed an issue where Create Session Request message looped internally causing continuous packet inspection and consuming firewall resources.
## PAN-123391
A fix was made to address a predictable temporary file vulnerability in PAN-OS ([CVE-2020-1994](https://security.paloaltonetworks.com/CVE-2020-1994)).
## PAN-123295
Fixed an issue where the dataplane restarted due to a race condition when a configuration push and a Netflow update occurred simultaneously.
## PAN-122909
Fixed an issue on the firewalls where enabling **SSL Forward Proxy** using the hardware security module (HSM) led to intermittent failure while loading random secure websites with the following message: ERR_CERT_INVALID. This occurred mainly with servers presenting ECDSA certificates.
## PAN-122872
Fixed an issue where the Aggregate Ethernet (AE) subinterface showed a different status from the AE parent interface.
## PAN-122565
Fixed an issue where a log collector with a dynamically assigned IP address could not establish communication between other log collectors.
## PAN-121827
Fixed an issue where allow lists and auth profiles in multi-vsys systems would not allow a user to be identified in user groups.Users would show as **Not in allow list** because the multi-vsys (vsys1) was shown as **vsys0**.
## PAN-121822
Fixed an issue with certificate authentication where only the topmost certificate was used to validate the client certificate.
## PAN-121596
Fixed an issue where the OSPF protocol didn't choose the correct loopback address for the forwarding address in the Not-So-Stubby Area (NSSA).
## PAN-121319
A fix was made to address a stack-based buffer overflow vulnerability in the management server component of PAN-OS ([CVE-2020-1990](https://security.paloaltonetworks.com/CVE-2020-1990)).
## PAN-121258
Fixed an issue where some SSLv3 session traffic logs showed an Allow action even when the security rule policy had a Deny action when the url-proxy setting was enabled.
## PAN-121058
A fix was made to address a DOM-based cross site scripting vulnerability in the PAN-OS and Panorama management web interfaces ([CVE-2020-2017](https://security.paloaltonetworks.com/CVE-2020-2017)).
## PAN-120726
Fixed an issue where the firewall incorrectly populated the username after the user had been served an Anti-Phishing Continue Page due to credential phishing detection.
## PAN-120640
Fixed an issue where show routing bfd related commands triggered a routed memory leak.
## PAN-120350
Fixed an issue where an Address Resolution Protocol (ARP) broadcast storm potentially overloaded the Log Processing Card (LPC) and caused the device to reboot.
## PAN-119810
A fix was made to address the improper restriction of the XML external entity (XXE) vulnerability in the Palo Alto Networks Panorama management server ([CVE-2020-2012](https://security.paloaltonetworks.com/CVE-2020-2012)).
## PAN-119173
```caveat
PA-5000 and PA-3000 Series only
```
Fixed an issue where the passive device in a high availability (HA) pair started processing traffic, which resulted in a packet buffer leak.
## PAN-118957
A fix was made to address an authentication bypass spoofing vulnerability in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS ([CVE-2020-2002](https://security.paloaltonetworks.com/CVE-2020-2002)).
## PAN-118075
Fixed an issue where the BGP conditional advertisement did not respond as expected, which caused the prefix in the **Advertise Filters** (**Network > Virtual Router > BGP > Conditional Adv**) to be incorrectly advertised.
## PAN-117479
A fix was made to address a vulnerability with the Nginx web server included with PAN-OS ([CVE-2017-7529](https://security.paloaltonetworks.com/CVE-2017-7529)).
## PAN-117108
Fixed an issue on the firewalls where the user mappings populated by the XML API were lost after rebooting.
## PAN-116842
Fixed an issue in the firewalls where after enabling a Cortex Data Lake license, if some connections between the firewall and Customer Support Portal server were blocked, the management plane memory utilization would start increasing, leading to multiple process restarts due to an out-of-memory condition.
## PAN-115562
Fixed an issue where superuser CLI permissions for role-based administrators did not match superuser privileges.
## PAN-114648
```caveat
PA-3200 Series only
```
Fixed an issue where high availability (HA1) hearbeat backup connection flaps occurred due to ping failures caused by unavailability of buffer space when **Heartbeat Backup** was configured (**Device > High Availability > Election Settings**).
## PAN-114236
Java Runtime Environment (JRE) was upgraded to 1.8.0_201.
## PAN-112899
Fixed an issue where the content update failed due to the appweb process periodically restarting.
## PAN-111636
A fix was made to address OpenSSH issues ([PAN-SA-2020-0002](https://security.paloaltonetworks.com/PAN-SA-2020-0002) / CVE-2018-20685, CVE-2019-6109, and CVE-2019-6111).
## PAN-111061
A fix was made to upgrade OpenSSH software included with PAN-OS ([PAN-SA-2020-0005](https://security.paloaltonetworks.com/PAN-SA-2020-0005) / CVE-2016-10012).
## PAN-109808
Fixed an issue on the Panorama API where exporting packet capture (pcap) using the XML API failed, and the web interface displayed the following error message: session id is missing. For Panorama, you can specify either the serial number or both the device_name and sessionid.
## PAN-109767
Fixed an issue where high availability (HA) sync would fail due to a large core being enabled on one peer.
## PAN-108992
A fix was made to address an improper authorization vulnerability in PAN-OS ([CVE-2020-1998](https://security.paloaltonetworks.com/CVE-2020-1998)).
## PAN-108356
Fixed an issue in Panorama where progress stopped on a commit if there was a missing device group.
## PAN-107650
Fixed an isolated issue that caused a process (configd) to restart due to kernel segmentation fault errors and caused a core file to be generated.
## PAN-106784
Fixed an issue to simplify the code in the web interface when changing administrator passwords.
## PAN-105880
Fixed an issue where Panorama failed to commit templates, including log correlation configurations, to firewalls that do not support log correlation. **Note:** Correlation is not supported on PA-200, PA-220, PA-500, PA-820, PA-850, and PA-VM platforms.
## PAN-104701
Fixed an issue where the dynamic update sync to peer failed when the firewalls were in a high availability (HA) configuration.
## PAN-103038
A fix was made to address a predictable temporary filename vulnerability ([CVE-2020-1981](https://security.paloaltonetworks.com/CVE-2020-1981)).
## PAN-102839
Fixed an issue where the IPSec tunnel size limit set by the customer was not maintained correctly in the system.
## PAN-102674
A fix was made to address a shell command injection vulnerability in the PAN-OS CLI ([CVE-2020-1980](https://security.paloaltonetworks.com/CVE-2020-1980)).
## PAN-102096
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where first packet processor packet buffer is not allocated with proper alignment, which caused memory corruption.
## PAN-100734
A fix was made to address a buffer flow vulnerability in the PAN-OS management interface where authenticated users were able to crash system processes or execute arbitrary code with root privileges ([CVE-2020-2015](https://security.paloaltonetworks.com/CVE-2020-2015)).
## PAN-99359
Fixed an issue where the ZIP hardware processing engine stopped processing ZIP-related requests.
## PAN-97584
A fix was made to address a format string vulnerability in the PAN-OS log daemon (logd) on Panorama ([CVE-2020-1979](https://security.paloaltonetworks.com/CVE-2020-1979)).
## PAN-95651
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where incomplete core dump files were generated when the dataplane stopped responding, which made troubleshooting difficult.
## PAN-74442
Resolved an issue where after enabling debugs on the dataplane, the debug logs contained information about unrelated traffic.
@@ -0,0 +1,19 @@
---
type: Addressed
product: PAN-OS
version: 8.1.14-h2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-144251
```caveat
PAN-OS 8.1.14 only
```
(PA-7000 Series firewalls only) Fixed an issue where SSL decryption failed due to memory allocation failure.
## PAN-142249
Fixed an issue where WildFire submission reports could not be viewed when the firewall was using the public WildFire cloud.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 8.1.15-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-150172
Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
@@ -0,0 +1,299 @@
---
type: Addressed
product: PAN-OS
version: 8.1.15
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-5320
Fixed an issue where the WF-500 cluster did not synchronize verdicts after successful verdict recheck queries with the WildFire global cloud.
## WF500-4716
Fixed an intermittent issue on WildFire appliances where failure to purge old sample information to make room for new samples caused a cluster to be unavailable.
## PAN-148988
A fix was made to address a Security Assertion Markup Language (SAML) authentication issue ([CVE-2020-2021](https://security.paloaltonetworks.com/CVE-2020-2021)).
## PAN-148068
Fixed an issue where SSL connections were blocked if you enabled decryption with the option to block sessions that have expired certificates. This issue included servers that sent an expired AddTrust certificate authority (CA) in the certificate chain.
## PAN-144782
Fixed an issue where a configuration audit created a large number of opresult.out files, which filled up the session/pan/user_tmp directory in opt/pancfg. This caused a slow Panorama response until a device restart was performed or the files were manually deleted from the root of the device.
## PAN-144479
Fixed an issue where SNMP objects from the HOST-RESOURCES-MIB returned incorrect values when queried.
## PAN-144251
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where SSL decryption failed due to memory allocation failure.
## PAN-143957
Fixed an issue where, after loading a saved configuration snapshot by API, a custom role-based administrator required Superuser privileges to perform a full commit.
## PAN-142346
Fixed an issue where the YARA version caused the WF-500 appliance virtual machine controllers to stop responding.
## PAN-142249
Fixed an issue where WildFire submission reports could not be viewed when the firewall was using the public WildFire cloud.
## PAN-142031
Fixed an issue where a process (configd) failed to restart even when Panorama displayed the following message: virtual memory exceeded, restarting.
## PAN-145195
```caveat
and PAN-145149
```
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
## PAN-145151
```caveat
and PAN-145149
```
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
## PAN-145150
```caveat
and PAN-145149
```
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
## PAN-141563
Fixed an issue where Slot 8 path monitoring failure occurred due to a memory buildup in a process (logrcvr) that was caused by slow communication and connection between log forwarding and Cortex Data Lake.
## PAN-140846
Fixed an issue where the dataplane restarted during a commit when **Netflow** was enabled.
## PAN-140386
Fixed an intermittent issue where the firewall used IP addresses instead of domain names for URL category lookup after upgrading to 9.0.6.
## PAN-139935
Fixed an issue in the URL process where a process (devsrvr) stopped responding.
## PAN-139587
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an issue where high and continuous CPU utilization was seen on dataplanes after IPSec Encapsulating Security Payload (ESP) rekeying occurred for multiple tunnels.
## PAN-138870
Fixed an issue where a process (configd) restarted and administrators received one of the following error messages: Timed out while getting config lock. Please try again or Please wait while the server reboots... due to a database error.
## PAN-138813
Fixed a performance drop issue seen when using API to configure larger sets of objects (more than 25 objects).
## PAN-138739
Fixed an issue where, in a high availability (HA) active/active configuration in a virtual wire deployment with asymmetric traffic, decryption did not work for some sites.
## PAN-138648
Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high.
## PAN-137966
Fixed a configuration lock issue where Panorama timed out due to a process (configd) being unable to read another process (mongod).
## PAN-137387
Fixed an issue where URL filtering used the IP address instead of the hostname, which led to incorrect URL categorization.
## PAN-136649
Fixed an issue where PA-7000 20GXM and PA-7000 20GQXM Network Processing Cards (NPCs) failed to process some sessions for Layer 7 inspection due to internal maximum threshold value that was not set.
## PAN-136612
Fixed an issue where fragmented packets leaked, which caused the depletion of Work Query Entry (WQE) pools.
## PAN-136608
Fixed an issue in Panorama where the Security policy **Target** displayed the serial number of the targeted device instead of the hostname.
## PAN-136390
```caveat
PA-7000 Series with 100GB NPC only
```
Fixed an issue during firewall bootup where the following error message: Bootloader upgrade failed, ret 255 appeared when small form-factor pluggable (SFP) modules were installed.
## PAN-135141
Fixed an issue where the Log Processing Card (LPC) did not come up intermittently in a fully loaded PA-7000 Series.
## PAN-135039
Fixed an issue in Panorama where a memory leak occurred during an HA sync commit.
## PAN-134309
Fixed an issue where a process (devsrvr) restarted when it hit the limit of the number of custom patterns available in the allocated memory.
## PAN-133411
Fixed an issue where after making configuration changes and selecting **Preview Changes**, a 500 Internal Server Error message displayed due to a memory leak.
## PAN-132712
Fixed an issue where scheduled reports did not run on a PA-7000 Series firewall not managed by Panorama after upgrade to 8.1.10 or 9.0.4 and later versions.
## PAN-132047
Fixed a rare issue where log forwarding from a PA-7080 firewall to an M-600 appliance appeared to slow or fail due to an elastic search error.
## PAN-131792
Fixed an issue where the **Name** log filter (**Monitor > Logs > Traffic**) was not maintained when viewing the **Log Viewer** for a Security policy rule (**Policies > Security**) from the drop-down.
## PAN-130776
Fixed an issue on Panorama where Applications and Threats content update deployment failed due to the content version date check.
## PAN-128195
Fixed an issue on Panorama where processes (vld) ran on high CPU when the incoming system log rate was 0.
## PAN-128078
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
## PAN-127358
Fixed an issue with a memory leak in a process (configd) where virtual memory exceeded the limit, which caused the process to restart.
## PAN-127260
Fixed an issue where the /opt/pancfg partition became full due to a large amount of botnet reports that were not automatically deleted.
## PAN-126944
Fixed an issue where the Panorama Template did not allow for **Ethernet Interface Link Speed** configurations greater than 1,000Mbps.
## PAN-120614
Fixed an issue where a commit from a Panorama appliance running PAN-OS 9.1 to a managed firewall running PAN-OS 9.0 or earlier failed with the following error message in ms.log: error generating tranform ike-pre-transform.xsl.
## PAN-120454
Fixed an issue where the firewall did not fail over to the secondary LDAP server when the primary LDAP server was not reachable and the configured LDAP bind timeout was not properly honored when SSL protocol was used.
## PAN-120113
Fixed an issue where the **to**, **from**, and **subject** fields did not populate in the threat logs if the fields were out of order.
## PAN-120105
Fixed an issue where email header information intermittently was not present in threat logs.
## PAN-119645
Fixed an issue where a process (panio) used unnecessary memory and caused an out-of-memory (OOM) condition on the dataplane if the dataplane was already low on memory.
## PAN-119289
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to query Cortex Data Lake by the serial number filter.
## PAN-117606
Fixed an issue where a process (configd) crashed while making configuration changes on Panorama.
## PAN-117487
Fixed an issue where a process (mgmtsrvr) stopped responding due to a memory corruption issue when acquiring a configuration lock.
## PAN-117359
```caveat
Firewalls with an AutoFocus license only
```
Fixed an issue where AutoFocus threat intelligence did not display when hovering over source and destination addresses in the logs when you configure a service route or proxy.
## PAN-117075
Fixed an issue where the firewall did not process the TLS record in SSL Inbound Inspection as expected, which introduced out-of-order packets in the transmit stage packet capture and affected client performance while accessing HTTP video applications.
## PAN-116002
Fixed an issue where an incorrect optimization could cause IP address-to-user mapping to not update within 60 seconds.
## PAN-115093
Fixed an issue where the firewall generated excessive logs for content decoder (CTD) errors.
## PAN-115035
Fixed a rare issue where **Traffic** logs, **Threat** logs and **URL filtering** logs stopped generating.
## PAN-112120
Fixed an issue where threat **Name** field of a threat **Custom Report** displayed the threat ID instead of the threat name.
## PAN-108929
Fixed an issue where software deployment failed for managed devices.
## PAN-106773
Fixed an issue where Panorama was unable to access api.threatvault.paloaltonetworks.com with the configure proxy option.
## PAN-106763
Fixed an issue where the dataplane crashed while freeing up memory due to a corrupted or long certificate field in the handshake.
## PAN-104368
Fixed an issue where a daemon (routed) stopped responding when authentication was used for RIP.
## PAN-103290
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the firewall stopped recording dataplane diagnostic data in dp-monitor.log after a few hours of uptime.
## PAN-102202
Fixed an issue where the OSPF summary Link State Advertisement (LSA) for the default 0.0.0.0/0 route were not advertised by the Area Border Router (ABR).
## PAN-98933
Fixed an issue on an M-Series appliances in an HA active/passive configuration where the schedules (*Device > Dynamic Updates*) were unresponsive after a failover or restart of Panorama.
## PAN-98863
Fixed an issue where a process (routed) restarted when navigating through **OSPF** tabs in **Virtual Routers**.
## PAN-98628
Fixed an issue where debug software pprof service <service-name> CLI command did not yield any data.
@@ -0,0 +1,299 @@
---
type: Addressed
product: PAN-OS
version: 8.1.17
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
A security issue has been fixed ([CVE-2021-3064](https://security.paloaltonetworks.com/CVE-2021-3064)).
## PAN-154181
Fixed an issue where, on Panorama, context switching to the web interface of a managed firewall running PAN-OS 8.1.16 did not work.
## PAN-153813
Fixed an issue where the proxy configuration did not get honored, which caused certificate revocation list (CRL) checks to fail from the firewall.
## PAN-152285
Fixed an issue where certain GPRS tunneling protocol (GTP-U) sessions that could not complete installation still occupied the flow table, which led to higher session table usage.
## PAN-152106
Fixed an issue where the management plane CPU usage remained high for a longer period of time than expected due to a process (genindex.sh).
## PAN-151405
Fixed an issue where administrators were unable to export Security Assertion Markup Language (SAML) metadata files from virtual system (vsys) specific authentication profiles.
## PAN-151203
Fixed an issue where the firewall dropped certain GTPv1 Update PDP Context packets.
## PAN-151057
Fixed an issue where upgrading the capacity license on a virtual machine (VM) high availability (HA) pair resulted in both firewalls going into a non-functional state instead of only the higher capacity license firewall.
## PAN-150750
```caveat
PA-5200 Series firewalls only
```
Fixed an intermittent issue where the firewall dropped packets when two or more GTP packets on the same GTP tunnel were very close to each other.
## PAN-150748
Fixed an issue where the firewall silently dropped GTPv2-C Delete Session Response packets.
## PAN-150746
Fixed an issue where the firewall dropped GTP packets with Delete Bearer messages for EBI 6 if they were received within two seconds of receiving the Delete Bearer messages for EBI 5.
## PAN-150613
Fixed an issue that caused a process (mprelay) to stop responding when committing changes in the Netflow Server Profile configuration (**Device > Server Profiles > Netflow**).
## PAN-149912
Fixed an issue where FIB entries were removed incorrectly due to miscommunication between internal processes.
## PAN-149839
```caveat
PA-7000 Series firewalls only
```
Added CLI commands to enable/disable resource-control groups and CLI commands to set an upper memory limit of 8G on a process (mgmtsrvr). To enable resource-control groups, use debug software resource-control enable and to disable them, use debug software resource-control disable. To set the memory limit, use debug management-server limit-memory enable, and to remove the limit, use debug management-server limit-memory disable. For the memory limit change to take effect, the firewall must be rebooted.
## PAN-147996
```caveat
PA-7000b Series firewalls only
```
Fixed a buffer overflow issue.
## PAN-147741
Fixed an issue where an API call for correlated events did not return any events.
## PAN-147595
Fixed an issue where, after a policy commit and session rematch, stream control transmission protocol (SCTP) logs for an existing SCTP session still showed old rule information.
## PAN-147305
Fixed an issue where a process (useridd) stopped responding to requests.
## PAN-146650
A fix was made to address an authentication bypass vulnerability in the GlobalProtect SSL VPN component of PAN-OS that allowed an attacker to bypass all client certificate checks with an invalid certificate. As a result, the attacker was able to authenticate as any user and gain access to restricted VPN network resources when the gateway or portal was configured to rely only on certificate-based authentication ([CVE-2020-2050](https://security.paloaltonetworks.com/CVE-2020-2050)).
## PAN-146506
Fixed an issue where memory usage on a process (useridd) was high, which caused the process to restart on the firewall acting as the User-ID redistribution agent. This issue occurred when multiple clients requested IP address-to-user mappings at the same time.
## PAN-146284
Fixed an issue where Application and Threat Content installation failed on the firewall with the following error message: Error: Threat database handler failed.
## PAN-145823
Fixed an issue where BGP learned routes were incorrectly populated with a VR error as a next hop.
## PAN-145133
A fix was made to address a vulnerability in the PAN-OS signature-based threat detection engine that allowed an attacker to evade threat prevention signatures using specifically crafted TCP packets ([CVE-2020-1999](https://security.paloaltonetworks.com/CVE-2020-1999)).
## PAN-144919
Fixed an issue on an M-600 appliance where the Panorama management server stopped receiving new logs from firewalls because delayed log purging caused log storage on the Log Collectors to reach maximum capacity.
## PAN-144448
Fixed an issue with the automated correlation engine that caused firewalls to stop generating correlated event logs for the beacon-heuristics object (ID 6005).
## PAN-143959
Fixed an issue on Panorama where a custom administrator with all rights enabled was not able to display the content of the external dynamic list (EDL) on the Panorama web interface.
## PAN-143809
Fixed an issue where Log Collectors had problems ingesting logs for older days received at a high rate.
## PAN-143241
Fixed an issue where the firewall unexpectedly stopped processing traffic to due a buffer allocation failure under the QOS-based buffer allocation method.
## PAN-141551
Fixed an issue where SSH service restart management did not take effect in the SSH management server profile.
## PAN-140883
Fixed an issue where, after rebooting the firewall, the SNMP object identifier (OID) for TCP connections per second (panVsysActiveTcpCps / .1.3.6.1.4.1.25461.2.1.2.3.9.1.6.1) returned 0 until another OID was pulled. Additionally, after a restart of a daemon (snmpd), if the above OID was called before other OIDs, there was an approximate 10 second delay in populating the data pulled by each OID.
## PAN-140382
Fixed an issue where the Host Evasion Threat ID signature did not trigger for the initial session even after the DNS response was received before the session expired.
## PAN-140375
Fixed an issue where a process (logrcvr) exited due to a race condition.
## PAN-140227
```caveat
PA-7000 Series firewalls only
```
Fixed a rare issue where the firewall rebooted due to path monitoring failure on the Log Processing Card (LPC).
## PAN-140157
A fix was made to address a vulnerability where the password for a configured system proxy server for a PAN-OS appliance was displayed in cleartext when using the CLI in PAN-OS ([CVE-2020-2048](https://security.paloaltonetworks.com/CVE-2020-2048)).
## PAN-139991
Fixed an issue where the web interface and the CLI were inaccessible, which caused the following error message to display on the web interface: Timed out while getting config lock.
## PAN-139680
Fixed an issue where dynamic route updates triggered an unintentional refresh of the DHCP client interface IP address, which led to the removal and re-addition of the default route associated with the DHCP client IP address and caused traffic disruption.
## PAN-139365
```caveat
PA-7000 Series firewalls only
```
Enhanced latency-sensitive protocols processing. With this fix, the following latency-sensitive control traffic will be prioritized: BGP, Bidirectional Forwarding Detection (BFD), LACP, OSPF, OSPFv3, Protocol Independent Multicast (PIM), and Internet Group Management Protocol (IGMP).
## PAN-139233
Fixed an issue where host information profile (HIP) reports failed to show up via the web interface or the CLI.
## PAN-139136
Fixed an issue where a large number of groups in group mappings caused a process (useridd) to exit.
## PAN-138938
Added an enhancement to reduce the memory usage of a process (logrcvr) to avoid out-of-memory (OOM) conditions on lower-end platforms.
## PAN-138573
Fixed an issue where the keyword **[Disabled]** was missing from the disabled policies exported in CSV/PDF format.
## PAN-137741
Fixed an issue where the data for a botnet report was deleted before the botnet report was completed.
## PAN-137656
Fixed an issue where the show config diff CLI command did not work correctly and produced unexpected output.
## PAN-135540
```caveat
PA-3220 firewalls only
```
Fixed an issue where the firewall generated some core files when generating tech support files
## PAN-135354
Fixed an issue where the paths between the control plane and the dataplanes in network processing cards (NPCs) stalled in the dataplane-to-control plane direction due to the Ring Descriptor entries becoming out of sync on each side. This produced unrecoverable data path monitoring failures, which caused the chassis to become nonfunctional.
## PAN-134226
Fixed an issue where **AdminStatus** for HA1 and High Speed Chassis Interconnect (HSCI) interfaces were incorrectly reported.
## PAN-133934
Fixed an intermittent issue where user-to-IP address mappings were not redistributed to client firewalls.
## PAN-133388
Fixed an issue where an HA configuration went out of sync when the HA sync job was queued and processed during an ongoing content installation job on the passive firewall.
## PAN-130955
Fixed an issue where templates on the secondary Panorama appliance were out of sync with the primary Panorama appliance due to an empty content-preview node.
## PAN-130357
Fixed a memory leak issue where virtual memory used by the SNMP process started to slowly increase when the request was sent with a request-id of 0.
## PAN-129376
```caveat
PA-800 Series firewalls only
```
Fixed an issue that prevented ports 9-12 from being powered down by hardware after being requested to do so.
## PAN-128172
Fixed an issue on Panorama where the show system logdb-quota CLI command took more time than expected, which caused the configuration lock to time out.
## PAN-128048
Fixed an issue where certificate-based authentication with IKEv2 IPSec tunnels failed to establish with some third-party vendors.
## PAN-127318
Fixed an issue where the firewall intermittently dropped DNS A or AAAA queries received over IPSec tunnels due to a session installation failure.
## PAN-125218
A fix was made to address an information exposure vulnerability in Panorama that disclosed the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performed a context switch ([CVE-2020-2022](https://security.paloaltonetworks.com/CVE-2020-2022)).
## PAN-124916
Added two ciphers for GlobalProtect Portal TLS connections.
## PAN-124331
Fixed an issue where the LDAP query took longer than expected to populate in the web interface.
## PAN-122672
Fixed an issue where the firewall returned incorrect information about the logging service status when the information was requested through the web interface.
## PAN-121944
Fixed an issue where the **Device Connectivity** status was grey on the firewall web interface even when the SSL session to the logging service was successful.
## PAN-121483
Fixed an issue where Data Filtering profiles did not generate a packet capture (pcap) for Server Message Block (SMB) when action was set to Alert.
## PAN-120245
Fixed an issue on Panorama where WildFire cloud content download failed for content deployment to the WF-500 appliance.
## PAN-109877
Fixed an issue where BGP flapped continuously with Jumbo Frames enabled on the firewall.
## PAN-104254
Fixed a rare issue where a dataplane process stopped responding.
## PAN-100254
Fixed an issue where an incorrect subnet mask was displayed for redistributed routes in the show routing protocol redist all CLI command.
## PAN-96528
A fix was made to address a memory corruption vulnerability in the GlobalProtect portal and GlobalProtect gateway that enabled an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges ([CVE-2021-3064](https://security.paloaltonetworks.com/CVE-2021-3064)).
## PAN-96187
Fixed an issue where Panorama did not set the preference list on a firewall for a Log Collector that was configured through the CLI.
@@ -0,0 +1,134 @@
---
type: Addressed
product: PAN-OS
version: 8.1.19
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-161731
Functionality was added to enable, via the CLI, the removal of key exchange algorithms used by SSH.
- Use debug system ssh-kex-prune cipher [diffie-hellman-group1-sha1 diffie-hellman-group-exchange-sha1 .. ] to enable removal of specified key exchanges.
- Use debug system ssh-kex-prune none to enable addition of key exchanges.
## PAN-159135
Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above.
## PAN-158988
Fixed an issue with HTTP Header Insertion where the payload was truncated when processing a segmented TCP stream and when the client retransmitted the packet with the same sequence number that was previously received segmented.
## PAN-158844
Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh.
## PAN-158638
Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg.
## PAN-156240
A fix was made to address an issue where a cryptographically weak pseudo-random number (PRNG) was used during authentication to the PAN-OS interface. As a result, attackers with the capability to observe their own authentication secrets over a long duration on the firewall had the ability to impersonate another authenticated web interface administrators session ([CVE-2021-3047](https://security.paloaltonetworks.com/CVE-2021-3047)).
## PAN-155009
Fixed an issue on the firewall where executing the request system bootstrap-usb prepare CLI command returned a server error.
## PAN-154114
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where secrets in PAN-OS XML API requests were logged in cleartext in the web server logs when the API was used incorrectly ([CVE-2021-3036](https://security.paloaltonetworks.com/CVE-2021-3036)).
## PAN-153213
Fixed a rare issue where TCP packets randomly dropped due to reassembly failure.
## PAN-152648
Fixed an issue where multiple all_pktproc processes stopped responding, which caused the dataplane to restart.
## PAN-152098
Fixed an issue where the Policy Optimizer for some device groups showed incorrect data with a - character in the rule usage column.
## PAN-151458
Fixed an issue on firewalls with high availability active/active configurations where GlobalProtect gateways timed out on-demand connections. This occurred because the **Inactivity Logout** timer did not reset.
## PAN-150998
Fixed an issue where, when deploying a VM-Series firewall on VMware NSX that had been assigned a serial number that was used by a previously deactivated firewall, the new firewall was deployed in a deactivated or partially deactivated state.
## PAN-150852
Fixed an issue with SMTP that occurred when attachment file names were longer than the allocated buffer. If the file name was longer than the buffer and Layer 7 inspection was enabled, the file was dropped, which caused session errors and an email to not be sent.
## PAN-150798
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot.
## PAN-150023
A fix was made to address an issue where an improper authentication vulnerability enabled a Security Assertion Markup Language (SAML) authenticated user to impersonate any user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)).
## PAN-149641
Fixed an issue where firewalls stopped refreshing IP tag information when configured with the **VM Information Sources** feature with a VMWare vCenter Server.
## PAN-149339
Fixed an issue where, when an ECMP route changed, the flow table in the offload engine was not updated.
## PAN-147783
Checks were added to help prevent the dataplane from restarting.
## PAN-147781
A fix was made to address an issue where an OS command argument injection vulnerability in the PAN-OS web interface enabled an authenticated administrator to read any arbitrary file from the file system ([CVE-2021-3045](https://security.paloaltonetworks.com/CVE-2021-3045)).
## PAN-147254
jQuery was updated to 3.5.1.
## PAN-147221
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
## PAN-145733
Fixed an issue where the SNMP INDEX for panZoneTable on the PAN-COMMON-MIB.my file did not work as expected, which led to entries in panZoneTable not being uniquely identified.
## PAN-144975
Fixed an intermittent issue where a high traffic load in a Layer 2 deployment caused SNMP and Panorama health monitoring failures.
## PAN-136347
Fixed an issue wherer DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding.
## PAN-136073
Fixed an issue where the High Speed Chassis Interconnect (HSCI) port flapped continuously after an upgrade or reboot.
## PAN-132035
Fixed an issue on Panorama appliances in an active/passive HA configuration where a managed firewall generated high priority alerts that it failed to connect to the passive Panorama appliance's User-ID agent server. This issue occurred because the firewall was only able to connect to one Panorama User-ID server at a time, and it connected only to the active Panorama appliance's User-ID server.
## PAN-131474
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where the connection details for a scheduled configuration export were logged in system logs ([CVE-2021-3037](https://security.paloaltonetworks.com/CVE-2021-3037)).
## PAN-128042
Fixed an issue where the dynamic address group failed due to a process (devsrvr) not being synced with another process (useridd).
## PAN-124579
Fixed an issue where a process (all_task_3) restarted, which caused the tunnels to reset.
@@ -0,0 +1,383 @@
---
type: Addressed
product: PAN-OS
version: 8.1.1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-4599
Fixed an issue on WF-500 appliance clusters where attempts to submit samples for analysis through the WildFire XML API failed with a 499 or 502 error in the HTTP response when the local worker was fully loaded.
## WF500-4535
Fixed an issue where the WF-500 appliance couldnt forward logs over TCP or SSL to a syslog server.
## WF500-4473
Fixed an issue where the root partition on the WF-500 appliance reached its maximum storage capacity because the following log files had no size limit and grew continuously: appweb_access.log, trap-access.log, wpc_build_detail.log, rsyncd.log, cluster-mgr.log, and cluster-script.log. With this fix, the appweb_access.log, trap-access.log, and wpc_build_detail.log logs have a limit of 10MB and the WF-500 appliance maintains one rotating backup file for each of these logs to store old data when a log exceeds the limit. Also with this fix, the rsyncd.log, cluster-mgr.log, and cluster-script.log logs have a limit of 5MB and the WF-500 appliance maintains eight rotating backup files for each of these logs.
## WF500-4397
Fixed an issue in a WF-500 appliance cluster where the controller backup node was stuck in global-db-service: WaitingforLeaderReady status when you tried to add nodes to the cluster.
## WF500-4363
Fixed an issue where firewalls and Panorama management servers couldnt retrieve reports from a WF-500 appliance due to an interruption in its data migration after you upgraded the appliance from a PAN-OS 7.1 release to a PAN-OS 8.0 or later release. With this fix, you can run the new debug device data-migration show CLI command on the WF-500 appliance after each upgrade to verify data migration finished successfully (output is Migration inMySQL is successful). Don't perform additional upgrades on the WF-500 appliance until the data migration finishes.
## PAN-95536
Fixed an issue where Dedicated Log Collectors failed to forward logs to syslog servers.
## PAN-95504
Fixed an issue on the firewall and Panorama management server where the web interface became unresponsive because the management server process (mgmtsrvr) restarted after you set its debugging level to debug (through the debug management-server on debug CLI command).
## PAN-95288
Fixed an issue where the firewall web interface didn't display System logs (**Monitor** > **Logs** > **System**) after you upgraded to PAN-OS 8.1 and then logged in using an administrative account that existed before the upgrade.
## PAN-94845
Fixed an issue where App-ID didnt recognize GPRS Tunneling Protocol User Plane (GTP-U) in GTP messages on port 2152 when only single-direction message packets arrived (Traffic logs indicated application insufficient-data).
## PAN-94741
Fixed an issue on the Panorama management server where characters in the **Secret** string of a TACACS+ server profile changed on the firewall after you pushed the server profile configuration from a template stack (**Device** > **Server Profiles** > **TACACS+**).
## PAN-94700
Fixed an issue on the PA-200, PA-220, PA-220R, PA-500, and PA-800 Series firewalls where the GlobalProtect data file installation failed after you upgraded the firewall to PAN-OS 8.1.
## PAN-94661
Fixed an issue where the firewall and Panorama management server displayed policy rules in a jumbled order when you scrolled the rule list in the **Policies** tab. The firewall and Panorama also opened the wrong rule for editing when you double-clicked one.
## PAN-94640
Fixed an issue where System logs included the following debugging information even though the firewall successfully resolved IP addresses: Failed to resolve domain name:xxx.yyy.zzafter trying all attempts to name servers: A.B.C.D, W.X.Y.Z. With this fix, daemon logs include that debugging information instead of System logs.
## PAN-94633
Fixed an issue where, after upgrading the firewall to PAN-OS 8.1, LDAP authentication failed if the associated authentication profile had an **Allow List** with entries other than **All** (**Device** > **Authentication Profile**).
## PAN-94569
Fixed an issue where GlobalProtect client authentication failed after you entered domains in upper case characters in the **Allow List** of an authentication profile (**Device** > **Authentication Profile** > **<authentication_profile>** > **Advanced**).
## PAN-94445
Fixed an issue where Server Message Block (SMB) sessions were in a discard state with the session end reason resources-unavailable.
## PAN-94387
Fixed an issue where the **Check URL Category** link in URL Filtering profiles opened a page that displayed a page not found error instead of opening the web page used to check the PAN-DB URL Filtering database for the URL Filtering category of a URL (**Objects** > **Security Profiles** > **URL Filtering**).
## PAN-94386
Fixed an issue where the firewall dropped packet data protocol (PDP) context update and delete messages that had a tunnel endpoint identifier (TEID) of zero in GPRS Tunneling Protocol (GTP) traffic, and the traffic failed when the dropped messages were valid.
## PAN-94379
Fixed an issue in a Panorama deployment with a Collector Group containing multiple Log Collectors where the logging search engine restarted after you changed the SSH keys used for high availability (HA). The disruption to the search engine caused an out-of-memory condition and caused Panorama to display logs and report data from only one Log Collector in the Collector Group.
## PAN-94317
Fixed the following LDAP authentication issues:
- Authentication failed for users who belonged to user groups for which you specified LDAP short names instead of long names in the **Allow List** of an authentication profile (**Device** > **Authentication Profile**).
- When performing LDAP lookups based on entries in the **Allow List** of LDAP authentication profiles, the firewall treated unknown group names as usernames.
- Authentication failed for users who belonged to multiple groups that you entered in the **Allow List** of different LDAP authentication profiles.
## PAN-94288
Fixed an issue where the default view and maximized view of the Application Usage report (**ACC** > **Network Activity**) didn't display matching values when you set the **Time** to **Last 12 Hrs** or a longer period.
## PAN-94170
Fixed an issue where GTP traffic failed because the firewall dropped GTP-U echo request packets.
## PAN-94135
Fixed an issue where device monitoring did not work on the Panorama management server.
## PAN-93930
Fixed an issue on firewalls with SSL decryption configured where the dataplane restarted because the all_pktproc process stopped responding after decryption errors occurred.
## PAN-93865
Fixed an issue where the GlobalProtect agent couldn't split tunnel applications based on the destination domain because the **Include Domain** and **Exclude Domain** lists were not pushed to the agent after the user established the GlobalProtect connection (**Network** > **GlobalProtect** > **Gateways** > **gateway>** > **Agent** > **Client Settings** > **client_settings_configuration>** > **Split Tunnel** > **Domain and Application**). In addition, the GlobalProtect agent couldn't include applications in the VPN tunnel based on the application process name because the **Include Client Application Process Name** list was not pushed to the agent after the user established the GlobalProtect connection.
## PAN-93854
Fixed an issue where the VM-Series firewall for NSX randomly disrupted traffic due to high CPU usage by the pan_task process.
## PAN-93640
Fixed an issue on firewalls where the Log Collector preference list displayed the IP address as unknown for a Panorama Log Collector deployed on AWS if the interface (ethernet1/1 to ethernet1/5) used for sending logs did not have a public IP address configured and you pushed configurations to the Collector Group.
## PAN-93431
Fixed an issue where the Panorama management server failed to export Traffic logs as a CSV file (**Monitor** > **Logs** > **Traffic**) after you set the **Max Rows in CSV Export** to more than 500,000 rows (**Panorama** > **Setup** > **Management** > **Logging and Reporting Settings** > **Log Export and Reporting**).
## PAN-93430
Fixed an issue where the firewall web interface didn't display Host Information Profile (HIP) information in HIP Match logs for end users who had Microsoft-supported special characters in their domains or usernames.
## PAN-93336
Fixed an issue where the firewall intermittently became unresponsive because the management server process (mgmtsrvr) stopped responding during a commit after you configured policy rules to use external dynamic lists (EDLs).
## PAN-93106
Fixed an issue where the Google Chrome browser displayed certificate warnings for self-signed ECDSA certificates that you generated on the firewall.
## PAN-93090
Fixed an issue where the GCP DHCP Server took 30-50 seconds to respond to a DHCP discover request, causing DHCP IP assignments to fail.
## PAN-93089
A security-related fix was made to prevent denial of service (DoS) to the management web interface (CVE-2018-8715).
## PAN-93072
Fixed an issue on hardware firewalls that were decrypting SSL traffic where multiple commits in a short period of time caused the firewalls to become unresponsive.
## PAN-93052
Fixed an issue where IPv6 BGP peering persisted (not all BGP routes were withdrawn) after the associated firewall interface went down.
## PAN-92950
Fixed an issue where a Panorama appliance experienced memory depletion after allowing you to mistakenly enter the IP address of the appliance when using the set deviceconfig system panorama-server <IP_address> or set log-collector <Log_Collector> deviceconfig system configuration mode CLI commands. These commands enable connectivity with separate appliances. With this fix, the command displays an error message when you specify the IP address of the appliance on which you run the command instead of the appliance to which it must connect. The correct IP address depends on the type of appliance on which you run the command:
- **Panorama management server** in an HA configuration—Specify the IP address of the Panorama HA peer.
- **Dedicated Log Collector**—Specify the IP addresses of the Panorama management servers, where panorama-server specifies the primary HA Panorama (or the only Panorama in a non-HA configuration) and panorama-server-2 specifies the secondary HA Panorama: set log-collector <Log_Collector> deviceconfig system {panorama-server | panorama-server-2} <IP_address>.
## PAN-92944
Fixed an issue where the firewall assigned the wrong URL filtering category to traffic that contained a malformed host header. With this fix, the firewall enables the blocking of any traffic with a malformed URL.
## PAN-92916
Fixed an issue where firewalls configured for User-ID redistribution failed to redistribute IP address-to-username mappings due to a memory leak.
## PAN-92858
Fixed an issue where the Panorama management server could not generate reports and the ACC page became unresponsive when too many heartbeats were missed because Panorama never cleared reportIDs greater than 65535.
## PAN-92789
Fixed an issue where VM-Series firewalls deleted logs by reinitializing the logging disk when the periodic file system integrity check (FSCK) took over 30 minutes during bootup.
## PAN-92788
Fixed an issue where the PAN-OS XML API returned the same job IDs for all report jobs on the firewall. With this fix, the PAN-OS XML API returns the correct job ID for each report job.
## PAN-92738
Fixed an issue on the Panorama management server where administrators with read-only privileges couldnt view deployment **Schedules** for content updates (**Panorama** > **Device Deployment** > **Dynamic Updates**).
## PAN-92678
Fixed an issue on Panorama management servers in an HA configuration where, after failover caused the secondary HA peer to become active, it failed to deploy scheduled dynamic updates to Log Collectors and firewalls.
## PAN-92604
Fixed an issue where a Panorama Collector Group didnt forward logs to some external servers after you configured multiple server profiles (**Panorama** > **Collector Groups** > **<Collector_Group>** > **Collector Log Forwarding**).
## PAN-92564
Fixed an issue where a small percentage of writable third-party SFP transceivers (not purchased from Palo Alto Networks®) stopped working or experienced other issues after you upgraded the firewall to which the SFPs are connected to a PAN-OS 8.1 release. With this fix, you must not reboot the firewall after you download and install the PAN-OS 8.1 base image until after you download and install the PAN-OS 8.1.1 release. For additional details, upgrade considerations, and instructions for upgrading your firewalls, refer to the [PAN-OS 8.1 upgrade information](https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features.html).
## PAN-92560
Fixed an issue where SSL Forward Proxy decryption didnt work after you excluded every predefined **Hostname** from decryption (**Device** > **Certificate Management** > **SSL Decryption Exclusion**).
## PAN-92487
Fixed an issue where enabling jumbo frames (**Device** > **Setup** > **Session**) reduced throughput because:
- The firewalls hardcoded the maximum segment size (TCP MSS) within TCP SYN packets and in server-to-client traffic at 1,460 bytes when packets exceed that size. With this fix, the firewalls no longer hardcode the TCP MSS value for TCP sessions.
- PA-7000 Series and PA-5200 Series firewalls hardcoded the maximum transmission unit (MTU) at 1,500 bytes for the encapsulation stage when tunneled clear-text traffic and the originating tunnel session were on different dataplanes. With this fix, the firewalls use the MTU configured for the interface (**Network** > **Interfaces** > **<interface>** > **Advanced** > **Other Info**) instead of hardcoding the MTU at 1,500 bytes.
## PAN-92445
Fixed an issue where the Panorama management server didn't display log data in **Monitor** > **Logs**, the **ACC** tab, or reports when Panorama was in a different timezone than the Dedicated Log Collectors because Panorama applied the wrong time filter.
## PAN-92380
Fixed an issue where, when you tried to export a custom report, and your Chrome or Firefox browser was configured to block popup windows, the firewall instead downloaded a Tech Support File to your client system.
## PAN-92256
Fixed an issue where the firewall didn't **Block sessions with unsupported cipher suites** based on Decryption policy rules for SSL Inbound Inspection when the rules referenced a **Decryption Profile** with a list of allowed ciphers that didn't match the ciphers that the destination server specified (**Objects** > **Decryption** > **Decryption Profile**). With this fix, the firewall checks the ciphers of both the source client and destination server against the cipher list in Decryption profiles when evaluating whether to allow sessions based on Decryption policy.
## PAN-92251
Fixed an issue where VM-Series firewalls used the incorrect MAC address in DHCP messages initiated from a subinterface after you configured that subinterface as a **DHCP Client** (**Network** > **Interfaces** > **Ethernet** > **<subinterface>** > **IPv4**) and disabled the **Use Hypervisor Assigned MAC Address** option (**Device** > **Management** > **Setup**).
## PAN-92163
Fixed an issue where firewalls in an active/passive HA configuration took longer than expected to fail over after you configured them to redistribute routes between an interior gateway protocol (IGP) and Border Gateway Protocol (BGP).
## PAN-92152
Fixed an issue where the firewall web interface displayed a blank **Device** > **Licenses** page when you had 10 x 5 phone support.
## PAN-92082
Fixed an issue where the firewall didn't generate URL Filtering logs for user credential submissions associated with a URL that was not a container page after you selected **Log container page only** and set the **User Credential Submission** action to **alert** for the URL category in a URL Filtering profile (**Objects** > **Security Profiles** > **URL Filtering** > **<ULR_Filtering_profile>**). With this fix, the firewall generates URL Filtering logs for user credential submissions regardless of whether you enable **Log container page only** in the URL Filtering profile.
## PAN-91946
Fixed an issue where the Panorama management server intermittently did not refresh health data for managed firewalls (**Panorama** > **Managed Devices** > **Health**) and therefore displayed 0 for session statistics.
## PAN-91945
Fixed an issue where the firewall didn't generate a System log to indicate when the reason that end users couldnt authenticate to a GlobalProtect portal was a DNS resolution failure for the FQDNs in a RADIUS server profile (**Device** > **Server Profiles** > **RADIUS**).
## PAN-91809
Fixed an issue on VM-Series firewalls for Azure where, after the firewall rebooted, some interfaces configured as DHCP clients intermittently did not receive DHCP-assigned IP addresses.
## PAN-91776
Fixed an issue where endpoint users could not authenticate to GlobalProtect when specifying a **User Domain** with Microsoft-supported symbols such as the dollar symbol ($) in the authentication profile (**Device** > **Authentication Profile**).
## PAN-91597
As an enhancement to improve security for the firewall, the management (MGT) interface now includes the following HTTP security headers: X-XSS-Protection, X-Content-Type-Options, and Content-Security-Policy.
## PAN-91591
Fixed an issue where the GlobalProtect agent failed to establish a TCP connection with the GlobalProtect gateway when TCP SYN packets had unsupported congestion notification flag bits set (ECN or CWR).
## PAN-91564
A security-related fix was made to prevent a local privilege escalation vulnerability that allowed administrators to access the password hashes of local users (CVE-2018-9334).
## PAN-91559
Fixed an issue where PA-5200 Series firewalls caused slow traffic over IPSec VPN tunnels because the firewalls reordered TCP segments during IPSec encryption.
## PAN-91370
Fixed an issue where the firewall dropped IPv6 traffic while enforcing IPv6 bidirectional NAT policy rules because the firewall incorrectly translated the destination address for a host that resided on a directly attached network.
## PAN-91360
Fixed an issue where, in rare cases, the firewall couldn't establish connections with GlobalProtect agents because the rasmgr process stopped responding when hundreds of end users logged in and out of GlobalProtect at the same time.
## PAN-91254
Fixed an issue where end user accounts were locked out after you configured authentication based on a RADIUS server profile with multiple servers (**Device** > **Server Profiles** > **RADIUS**) and enabled the gateway to **Retrieve Framed-IP-Address attribute from authentication server** (**Network** > **GlobalProtect** > **Gateways** > **<gateway>** > **Agent** > **Client Settings** > **<client_settings_configuration>** > **IP Pools**). With this fix, instead of requesting framed IP addresses from all the servers in a RADIUS server profile at the same time, the firewall sends the request to only one server at a time until one of the servers responds.
## PAN-90824
An enhancement was made to improve compatibility for the [HTTP log forwarding feature](https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/configure-log-forwarding.html) so that you can specify the TLS version that the HTTP log forwarding feature uses to connect to the HTTP server.
To specify the version, use the debug system https-settings tls-version CLI command. (To view the version that is currently specified, use the debug system https-settings command.)
## PAN-90753
Fixed an issue where firewalls in an active/passive HA configuration didnt synchronize multicast sessions between the firewall HA peers.
## PAN-90448
Fixed an issue where PA-7000 Series and PA-5200 Series firewalls didn't properly **Rematch all sessions on config policy change** for offloaded sessions (**Device** > **Setup** > **Session**).
## PAN-90411
Fixed an issue where PA-5200 Series firewalls didnt forward buffered logs to Panorama Log Collectors after connectivity between the firewalls and Log Collectors was disrupted and then restored.
## PAN-90404
Fixed an issue where the Panorama management server intermittently displayed the connections among Log Collectors as disconnected after pushing configurations to a Collector Group (**Panorama** > **Managed Collectors**).
## PAN-90347
Fixed an issue on a PA-5000 Series firewall configured to use an IPSec tunnel containing multiple proxy IDs (**Network** > **IPSec Tunnels** > **<tunnel>** > **Proxy IDs**) where the firewall dropped tunneled traffic after clear text sessions were established on a different dataplane than the first dataplane (DP0).
## PAN-90190
Fixed an issue on the Panorama virtual appliance on a VMware ESXi server where VMware Tools failed to start after you upgraded to PAN-OS 8.1.
## PAN-90143
Fixed an issue where administrators intermittently failed to log in to the firewall because it intermittently restarted processes continuously due to an out-of-memory condition.
## PAN-90048
Fixed an issue where automatic commits failed after you configured Security policy rules that referenced region objects for the source or destination and then upgraded the PAN-OS software.
## PAN-89992
Fixed an issue where the firewall didnt efficiently handle traffic in which the number of Address Resolution Protocol (ARP) packets exceeded the processing capacity of the firewall. With this fix, the firewall handles ARP packets more efficiently.
## PAN-89748
Fixed an issue on the Panorama virtual appliance for Azure where commit operations failed after you added administrator accounts other than the default admin account, switched from Panorama mode to Log Collector mode, made configuration changes, and then tried to commit your changes. With this fix, Panorama removes all administrator accounts other than the default admin account when you switch to Log Collector mode. Dedicated Log Collectors support only the default admin account.
## PAN-89715
Fixed an issue on PA-5200 Series firewalls in an active/passive HA configuration where failover took a few seconds longer than expected when it was triggered after the passive firewall rebooted.
## PAN-89525
Fixed a configuration parsing issue where a default setup of the Authentication Profile caused the firewall to reboot during commit. If the administrator configured the Authentication Profile with any allowed values, including the default values, the configuration committed successfully. The issue was observed on a PA-500 firewall in FIPS-CC mode.
## PAN-89171
Fixed an issue on firewalls in an HA configuration where an auto-commit failed (the error message was Error:Duplicate user name) after you connected a new suspended-secondary peer to an active-primary peer.
## PAN-88852
Fixed an issue where VM-Series firewalls stopped displaying URL Filtering logs after you configured a URL Filtering profile with an alert action (**Objects** > **Security Profiles** > **URL Filtering**).
## PAN-88752
Fixed an issue where User-ID agents configured to detect credential phishing didnt detect passwords that contained a blank space.
## PAN-88649
Fixed an issue where, after receiving machine account names in UPN format from a Windows-based User-ID agent, the firewall misidentified them as user accounts and overrode usernames with machine names in IP address-to-username mappings.
## PAN-87964
Fixed an issue where the firewall couldn't render URL content for end users after you configured GlobalProtect Clientless VPN with a **Hostname** set to a Layer 3 subinterface or VLAN interface (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **General**).
## PAN-87309
Fixed an issue where, after you configured a GlobalProtect gateway to exclude all video streaming traffic from the VPN tunnel, Hulu and Sling TV traffic could not be redirected if you did not configure any security profiles (such as a File Blocking profile) for your firewall Security policies.
## PAN-86934
Fixed an issue where the firewall applied case sensitivity to the names of shared user groups that were defined in its local database and, as a result, users who belonged to those groups couldn't access applications through GlobalProtect Clientless VPN even after successful authentication. With this fix, the firewall ignores character case when evaluating the names of user groups in its local database.
## PAN-86076
As an enhancement to improve security for GlobalProtect deployments, the GlobalProtect portal now includes the following HTTP security headers in responses to end user login requests: X-XSS-Protection, X-Content-Type-Options, and Content-Security-Policy.
## PAN-86028
Fixed an issue in an HA active/active configuration where traffic in a GlobalProtect VPN tunnel in SSL mode failed after Layer 7 processing if asymmetric routing was involved.
## PAN-85308
Fixed an issue in the output for on-demand custom reports (select **Monitor** > **Manage Custom Reports** > **<report>** and **Run Now**) where the **<column_heading>** drop-down displayed a **Columns** option even though you couldn't add or remove columns. With this fix, the **<column_heading>** drop-down no longer displays a **Columns** option.
## PAN-83001
Fixed an issue where the firewall dropped packets based on a QoS class even though traffic didnt exceed the maximum bandwidth for that class.
## PAN-81495
Fixed an issue where connections that the firewall handles as an Application Level Gateway (ALG) service were disconnected when destination NAT and decryption were enabled.
## PAN-80664
Fixed an issue where, after end users who haven't yet enrolled in Duo failed to authenticate to a GlobalProtect portal that used a RADIUS server integrated with Duo for multi-factor authentication, the portal login page displayed Invalidusername or password as the authentication error instead of displaying a Duo enrollment URL so that the users could enroll.
@@ -0,0 +1,181 @@
---
type: Addressed
product: PAN-OS
version: 8.1.20
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-5568
Fixed an issue where a firewall in FIPS mode running PAN-OS 8.1.18 or a later version failed to connect with a WildFire appliance in normal mode.
## PAN-168921
Fixed an issue in active/active high availability (HA) configuration where traffic with complete packets was showing up as incomplete and being disconnected due to a non-session owner device closing the session prematurely.
## PAN-167989
Fixed a timing issue between downloading and installing threads that occurred when Panorama pushed content updates and the firewall fetched content updates simultaneously.
## PAN-166836
Fixed an issue where session failed due to resource unavailability.
## PAN-166299
```caveat
PA-3000 Series firewalls only
```
Fixed an issue where Server Message Block (SMB) sessions failed due to resource unavailability.
## PAN-166241
A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ([CVE-2021-3055](https://security.paloaltonetworks.com/CVE-2021-3055)).
## PAN-164922
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
## PAN-164846
Fixed an issue where packet buffers were depleted.
## PAN-164422
```caveat
VM-Series firewalls only
```
A fix was made to address improper access control that enabled an attacker with authenticated access to GlobalProtect portals and GlobalProtect gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon Web Services (AWS) ([CVE-2021-3062](https://security.paloaltonetworks.com/CVE-2021-3062)).
## PAN-160744
Fixed an issue where the negative time difference between the dataplane and the management plane during the client certificate info check prevented the GlobalProtect client from connecting to the GlobalProtect gateway with the following error message: Required client certificate not found.
## PAN-160708
Fixed an issue where the dataplane restarted after configuring a a **deny_all** policy.
## PAN-158723
A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)).
## PAN-158262
A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code.
A fix was made to address a buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS that allowed a remote attacker to execute arbitrary code ([CVE-2020-10188](https://security.paloaltonetworks.com/CVE-2020-10188)).
## PAN-157834
Fixed an issue with missing zone entries in CSV or PDF export files.
## PAN-157730
Fixed an issue where, after a firewall reboot, a commit or auto-commit operation failed with the following error message: ID population failed. This issue occurred because the Phase1 ID assignment failure did not trigger an idmgr reset.
## PAN-157632
Fixed an intermittent issue where the firewall dropped GPRS Tunneling Protocol (GTP-U) traffic with the message TEID=0x00000000.
## PAN-157346
Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal<portal-config> > Agent<agent-config> > HIP Data Collection**).
## PAN-156225
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to later 9.1 releases and from PAN-OS 10.0.0 to PAN-OS 10.0.4.
## PAN-155532
Fixed an issue where the mgmtsrv process restarted due to a missing protective check around access to potentially NULL pointers.
## PAN-154526
Fixed an issue where a process (genindex.sh) caused high memory usage on the management plane. Due to the resulting out-of-memory (OOM) condition, multiple processes stopped responding.
## PAN-154376
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
## PAN-153908
```caveat
PA-5000 Series firewalls only
```
Fixed an issue where the show vpn flow CLI command displayed incorrect details.
## PAN-153382
Fixed an issue where the per-minute resource monitor was three minutes behind.
## PAN-153261
Fixed an issue where not all fragmented packets were transmitted, which caused increased packet buffer usage.
## PAN-153107
Fixed an issue where a dataplane process stopped responding while processing fragmented traffic on GTP-U tunnels.
## PAN-151120
Fixed an issue where the SYN-ACK packet matched stale entries in the session flow table and was dropped on the firewall with the following error message: Inactive flow state 0.
## PAN-150337
A fix was made to address a reflect cross-site scripting (XSS) vulnerability in the PAN-OS web interface that enabled an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performed arbitrary actions in the web interface as the targeted authenticated administrator ([CVE-2021-3052](https://security.paloaltonetworks.com/CVE-2021-3052)).
## PAN-149501
A fix was made to address a memory corruption vulnerability in the GlobalProtect Clientless VPN that enabled an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication ([CVE-2021-3056](https://security.paloaltonetworks.com/CVE-2021-3056)).
## PAN-147221
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
## PAN-146250
Fixed an issue where, in two separate but simultaneous sessions, the same software packet buffer was owned and processed.
## PAN-146107
Fixed an issue where memory allocation failure caused a process (pan_comm) to restart several times, which caused the firewall to restart.
## PAN-143426
Fixed a memory leak issue where a process (devsrvr) restarted due to the memory limit being exceeded.
## PAN-138727
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
## PAN-128634
A debug command was added to provide more verbose output when troubleshooting packet processing on the firewall.
## PAN-120013
Fixed an issue where secure communication settings were incorrectly synchronized between Panorama appliances in an HA configuration.
## PAN-119922
Fixed an issue in Panorama where the show config diff command was not working correctly and produced unexpected output.
## PAN-118667
Fixed an issue where firewall policy configurations displayed **[object Object]** instead of the object names.
## PAN-115541
Fixed an issue where removing a cipher from an SSL/TLS profile did not take effect if it was attached to the management interface.
## PAN-110429
Fixed an issue with firewalls in an HA configuration where multiple all_pktproc processes stopped responding due to missing heartbeats, which caused service outages.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 8.1.21-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,23 @@
---
type: Addressed
product: PAN-OS
version: 8.1.21
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Fixed a Denial-of-Service (DoS) vulnerability in the GlobalProtect portal and gateway ([CVE-2021-3063](https://security.paloaltonetworks.com/CVE-2021-3063)).
## PAN-170466
Fixed an memory reference issue related to the devsrvr process that caused the process to stop responding.
## PAN-149911
Fixed an issue where URL filtering logs for credential phishing displayed a slash character ( / ) in the URL field.
## PAN-141454
Fixed an issue where the output of the CLI command show running resource-monitor ingress-backlogs displayed an incorrect total utilization value.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 8.1.23-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-192999
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
## PAN-140736
Fixed an issue where configuration synchronization failed in a high availability (HA) configuration.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 8.1.25-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 8.1.25-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 8.1.25.2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237871
```caveat
WF-500 appliances and PAN-DB private cloud deployments only
```
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 8.1.25
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
This release includes bug and performance fixes.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 8.1.26-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-239241
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-237935
Extended the root certificate for WildFire appliances to December 31, 2032.
@@ -0,0 +1,405 @@
---
type: Addressed
product: PAN-OS
version: 8.1.2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-4625
Fixed an issue where the WF-500 appliance provided no option to configure the master key. With this fix, you can use the request master-key new-master-key <key> lifetime <lifetime> CLI command to configure the master key.
## PAN-97531
Fixed an issue on PA-3200 Series firewalls where powering down a copper interface disrupted the operations of other interfaces that were grouped with it at the hardware level.
## PAN-97283
Fixed an issue on PA-3200 Series firewalls where SFP/SFP+ ports intermittently failed to come up after a reboot.
## PAN-97003
Fixed an issue on offline VM-Series firewalls where the web interface and CLI did not display license information after you activated licenses.
## PAN-96938
Fixed an issue with dataplane restarts when the mix of network traffic included a high ratio of RTP and RTP Control Protocol (RTCP) traffic.
## PAN-96734
Fixed an issue where a process (configd) stopped responding during a partial revert operation when reverting an interface configuration.
## PAN-96622
Fixed an issue where the GlobalProtect™ portal landing page did not return the HTTP Strict Transport Security (HSTS) header in the error response page when sending the response to an endpoint.
## PAN-96587
Fixed an issue where PA-7000 Series and PA-5200 Series firewalls intermittently failed to forward logs to Log Collectors or the Logging Service due to DNS resolution failure for the FQDNs of those log receivers.
## PAN-96572
Fixed an issue where, after end users successfully authenticated for access to a service or application, their web browsers briefly displayed a page indicating authentication completed and then they were redirected to an unknown URL that the user did not specify.
## PAN-96490
Fixed an issue where syslog servers misrepresented HIP Match, Authentication, and User-ID™ logs received from the firewall because the order changed in the first seven syslog fields for those log types. With this fix, the first seven syslog fields are the same for all log types.
## PAN-96102
Fixed an issue on the Panorama™ management server where partial revert operations failed with the following error after you used the PAN-OS® XML API to create template stacks: template-stack-> is missing 'settings' template-stack is invalid.
## PAN-96088
Fixed an issue where the active firewall in a high availability (HA) configuration did not synchronize the GlobalProtect data file to the passive firewall.
## PAN-95895
Fixed an issue on firewalls that collect port-to-username mappings from Terminal Services agents where the firewalls didn't enforce user-based policies correctly because the dataplane had incorrect primary-to-alternative-username mappings even after you cleared the User-ID cache.
## PAN-95736
Fixed an issue where the mprelay process stopped responding when a commit occurred while the firewall was identifying flows that needed a NetFlow update.
## PAN-95683
Fixed an issue where, after you upgraded the firewall to PAN-OS 8.1, a 500 Internal Server error occurred for traffic that matched a Security policy rule with a URL Filtering profile that specified a continue action (**Objects** > **Security Profiles** > **URL Filtering**) because the firewall did not correctly apply AES encryption or synchronize the associated API key between the management plane and dataplane.
## PAN-95513
Fixed an issue on the Panorama management server where selecting additional target firewalls for a shared policy rule cleared any existing firewall selections for that rule (**Panorama** > **Policies** > **<policy_type>** > **{Pre Rules | Post Rules | Default Rules}** > **Target**).
## PAN-95486
Fixed an issue with VM-Series firewalls on Azure where dynamic updates failed for the GlobalProtect Data File when you scheduled the updates using the management interface.
## PAN-95445
```caveat
This fix requires the VMware NSX 2.0.4 or a later plugin.
```
Fixed an issue where VM-Series firewalls for NSX and firewalls in an NSX notify group (**Panorama** > **VMware NSX** > **Notify Group**) briefly dropped traffic while receiving dynamic address updates after the primary Panorama in a high availability (HA) configuration failed over.
## PAN-95443
Fixed an issue where a VM-Series firewall on KVM in DPDK mode didn't receive traffic after you configured it to use the i40e single-root input/output virtualization (SR-IOV) virtual function (VF). This fix requires that you install i40e driver version 2.1.16 or later, and that you set the VF to be trusted by running the following CLI command on the KVM host:
ip link set dev eth0 vf 1 trust on
## PAN-95197
Fixed an issue where mobile endpoints that used GPRS Tunneling Protocol (GTP) lost traffic and had to reconnect because the firewall dropped the response message that a Gateway GPRS support node (GGSN) sent for a second Packet Data Protocol (PDP) context update.
## PAN-95163
Fixed an issue where, after you added group mapping configurations, an out-of-memory condition developed that intermittently caused the User-ID process (useridd) to restart and temporarily prevented the firewall from receiving updates to user mappings and group mappings.
## PAN-95130
Fixed an issue on the firewall and Panorama management server where you could not assign tags that contained a colon ( : ) to service or service group objects.
## PAN-95124
Fixed an issue where the firewall did not correctly modify the Configuration XML file (by removing ctd skip-block-http-range) when you upgraded from PAN-OS 8.0 to PAN-OS 8.1.
## PAN-95056
Fixed an issue on the Panorama management server where the configd process restarted when an external health monitoring script (such as GoldenGate) executed against Panorama, which became unusable until configd finished restarting.
## PAN-94917
Fixed an issue on Panorama Log Collectors where the show system masterkey-properties CLI command did not display the master key lifetime and reminder settings.
## PAN-94912
Fixed an issue where PA-5200 Series and PA-3200 Series firewalls in an active/active high availability (HA) configuration sent packets in the wrong direction in a virtual wire deployment.
## PAN-94853
Fixed an issue where mobile endpoints that use GPRS Tunneling Protocol (GTP) lose GTP-U traffic because the firewall dropped all GTP-U packets as packets without sessions after receiving two GTP requests with the same tunnel endpoint identifiers (TEIDs) and IP addresses.
## PAN-94697
Fixed an issue where commit failures occurred after you configured a DHCP-enabled subinterface as the local Interface for an IKE gateway configuration (**Network** > **Network Profiles** > **IKE Gateways** > **<IKE_gateway>** > **General**).
## PAN-94586
Fixed an issue where the Panorama management server exported reports slowly or not at all due to DNS resolution failures.
## PAN-94582
Fixed an issue where the firewall did not correctly re-learn a User-ID mapping after that mapping was temporarily lost and recovered through successful WMI probing.
## PAN-94578
Fixed an issue where WildFire submissions with a filename that contained %20n or a subject that contained %n caused the management server (mgmtsrvr) process to stop responding.
## PAN-94575
Fixed an issue where a Panorama management server running PAN-OS 8.1 failed to push host information profile (HIP) objects that specified Encrypted Locations with State values to firewalls running PAN-OS 8.0 or an earlier release (**Objects** > **GlobalProtect** > **HIP Objects** > **<HIP_object>** > **Disk Encryption** > **Criteria** > **<encrypted_location>**).
## PAN-94516
Fixed an issue on PA-500, PA-220, PA-220-R, and PA-200 firewalls where commits failed after the Panorama management server pushed a Decryption profile that you configured to **Block sessions if HSM not available** to firewalls that did not support a hardware security module (HSM).
## PAN-94510
Fixed an issue where the total log storage utilization that the firewall displayed did not account for **IP Tag** storage that was set to less than two per cent (**Device** > **Setup** > **Management** > **Logging and Reporting Settings** > **Log Storage**).
## PAN-94450
Fixed an issue where QSFP+ interfaces (13 and 14) on a PA-7000-20GQ-NPC Network Processing Card (NPC) unexpectedly flapped when the card was booting up.
## PAN-94413
Fixed an issue on Panorama M-Series and virtual appliances where the hash of the shared policy was incorrectly calculated, which caused an in-sync shared policy status to display as out-of-sync.
## PAN-94382
Fixed an issue on the Panorama management server where the Task Manager displayed Completed status immediately after you initiated a push operation to firewalls (**Commit all** job) even though the push operation was still in progress.
## PAN-94318
Fixed an issue where the VM-Series firewall for Azure intermittently failed to resolve URLs and generated the following error because Azure prematurely timed out the connection to the PAN-DB cloud after four minutes: Failed tosend Update Request to the Cloud.
## PAN-94278
Fixed an issue where a Panorama Collector Group forwarded Threat and WildFire® Submission logs to the wrong external server after you configured match list profiles with the same name for both log types (**Panorama** > **Collector Groups** > **<Collector_Group>** > **Collector Log Forwarding** > **{Threat | WildFire}** > **<match_list_profile>**).
## PAN-94239
Fixed an issue where the firewall routed Open Shortest Path First (OSPF) unicast hello messages (P2MP non-broadcast) using a forwarding information base (FIB) instead of sending the messages over the interface to which the OSPF neighbor connected.
## PAN-94187
Fixed an issue where the firewall did not apply tag-based matching rules for dynamic address groups unless you enclosed the tag names with single quotes ('<tag_name>') in the matching rules (**Objects** > **Address Groups** > **<address_group>**).
## PAN-94167
Fixed an issue where a firewall forwarded a deleted or expired IP address-to-username mapping to another firewall through User-ID Redistribution but the receiving firewall still displayed the mapping as an active IP address-to-username mapping.
## PAN-94165
Fixed an issue where the firewall used an incorrect next hop in the Border Gateway Protocol (BGP) route that it advertised to External BGP (eBGP) peers in the BGP peer group.
## PAN-94163
Fixed an issue on firewalls deployed in virtual wire mode where SSL decryption failed due to a memory pool allocation failure.
## PAN-94122
Fixed an issue where firewalls intermittently blocked SSL traffic due to a certificate timeout error after you enabled SSL Forward Proxy decryption and configured the firewall to **Block sessions on certificate status check timeout** (**Objects** > **Decryption** > **Decryption Profile** > **<Decryption_profile>** > **SSL Decryption** > **SSL Forward Proxy**).
## PAN-94070
Fixed an issue where Bidirectional Forwarding Detection (BFD) sessions were active in only one virtual router when two or more virtual routers had active BGP sessions (with BFD enabled) using the same peer IP address.
## PAN-94058
```caveat
GlobalProtect configurations only
```
Fixed an issue where a configured Layer 3 interface erroneously opened ports 28869/tcp and 28870/tcp on the IP address assigned to that Layer 3 interface.
## PAN-94023
Fixed an issue where the request system external-list show type ip name <EDL_name> CLI command did not display external dynamic list entries after you restarted the management server (mgmtsrvr) process.
## PAN-93937
Fixed an issue where the management server (mgmtsrvr) process on the firewall restarted when you pushed configurations from the Panorama management server.
## PAN-93889
Fixed an issue where the Panorama management server generated high-severity System logs with the Syslogconnection established to server message after you configured Traps log ingestion (**Panorama** > **Log Ingestion Profile**) for forwarding to a syslog server (**Panorama** > **Server Profiles** > **Syslog**) and committed configuration changes (**Commit** > **Commit to Panorama**).
## PAN-93755
Fixed an issue where SSL decrypted traffic failed after you configured the firewall to **Enforce Symmetric Return** in Policy Based Forwarding (PBF) policy rules (**Policies** > **Policy Based Forwarding**).
## PAN-93722
Fixed an issue where the firewall failed to perform decryption because endpoints tried to resume decrypted inbound perfect forward secrecy (PFS) sessions.
## PAN-93715
In certain customer environments, enhancements in PAN-OS 8.1.2 to change fan speeds may help reduce rare cases of drive communication failure in PA-5200 Series firewalls.
## PAN-93705
Fixed an issue where configuring additional interfaces (such as ethernet1/1 or ethernet1/2) on the Panorama management server in Management Only mode caused an attempt to create a local Log Collector when you committed the configuration (**Panorama** > **Setup** > **Interfaces**), which caused the commit to fail because a local Log Collector is not supported on a Panorama management sever in Management Only mode.
## PAN-93522
Fixed an issue on firewalls in a high availability (HA) configuration where traffic was disrupted because the dataplane restarted unexpectedly when the firewall concurrently processed HA messages and packets for the same session. This issue occurred on all firewall models except the PA-200 and VM-50 firewalls.
## PAN-93412
Fixed an issue where the Security policy rules pushed from Panorama to a firewall did not display in the list of available rules in the global filters list in the Application Command Center (ACC).
## PAN-93411
Fixed an issue on VM-Series firewalls for KVM where applications that relied on multicasting failed because the firewalls filtered multicast traffic by the physical function (PF) after you configured them to use single root I/O virtualization (SR-IOV) virtual function (VF) devices.
## PAN-93410
Fixed an issue where PA-5200 Series firewalls sent logs to the passive or suspended Panorama virtual appliance in Legacy mode in a high availability (HA) configuration. With this fix, the firewalls send logs only to the active Panorama.
## PAN-93318
Fixed an issue where firewall CPU usage reached 100 per cent due to SNMP polling for logical interfaces based on updates to the Link Layer Discovery Protocol (LLDP) MIB (LLDP-V2-MIB.my).
## PAN-93244
A security-related fix was made to prevent a Cross-Site Scripting (XSS) attack through the PAN-OS session browser (CVE-2018-9335).
## PAN-93242
A security-related fix was made to prevent a Cross-Site Scripting (XSS) vulnerability in a PAN-OS web interface administration page (CVE-2018-9337).
## PAN-93233
Fixed an issue where PA-7000 Series firewalls caused slow traffic over IPSec VPN tunnels because the firewalls reordered TCP segments during IPSec encryption when the tunnel session and inner traffic session were on different dataplanes.
## PAN-93207
Fixed an issue where the firewall reported the incorrect hostname when responding to SNMP get requests.
## PAN-93046
Fixed an issue where administrators whose roles have the **Privacy** privilege disabled (**Device** > **Admin Roles** > **<role>** > **Web UI**) can view details about source IP addresses and usernames in the PDF reports exported from the firewall.
## PAN-92958
Fixed an issue where disk utilization increased unnecessarily because the firewall did not archive and rotate the /var/on file, which therefore grew to over 40MB.
## PAN-92892
```caveat
VM-50 Lite firewalls only
```
Fixed an intermittent issue where Failed to back up PAN-DB errors were reported in the system log due to management plane out-of-memory errors when a process (devsrvr) attempted to run an md5 checksum.
## PAN-92821
Fixed an issue where WildFire Submission logs did not correctly display the subject fields of emails because the firewall did not remove white spaces between encoded chunks in those fields.
## PAN-92676
Fixed an issue where an administrator whose Admin Role profile had the **Command Line** privileges set to **superuser** (**Device** > **Admin Roles** > **<role>** > **Command Line**) could not request tech-support dump from the CLI.
## PAN-92569
Fixed an issue where the firewall displayed a continue-and-override response page when users tried to access a URL that the firewall incorrectly categorized as unknown because it learned the URL field as an IP address.
## PAN-92456
Fixed an issue on the Panorama management server where administrators couldn't log in to the web interface because disk space utilization reached 100 per cent due to the continuous growth of cmserror log files.
## PAN-92366
Fixed an issue where PA-5200 Series firewalls in an active/passive high availability (HA) configuration dropped Bidirectional Forwarding Detection (BFD) sessions when the passive firewall was in an initialization state after you rebooted it.
## PAN-92149
Fixed an issue on PA-3250 and PA-3260 firewalls where the hardware signature match engine was disabled and the PAN-OS software performed signature matching instead, resulting in a ten percent degradation in threat detection performance.
## PAN-91689
Fixed an issue where the Panorama management server removed address objects and—in the **Network** tab settings and NAT policy rules—used the associated IP address values without reference to the address objects before pushing configurations to firewalls.
## PAN-91421
Fixed an issue where the firewall dataplane restarted and resulted in temporary traffic loss when any process stopped responding while system resource usage was running high.
## PAN-91238
Fixed an issue where an Aggregate Ethernet (AE) interface with Link Aggregation Control Protocol (LACP) enabled on the firewall went down after a cisco-nexus primary virtual port channel (vPC) switch LACP peer rebooted and came back up.
## PAN-91088
Fixed an issue on PA-7000 Series firewalls in a high availability (HA) configuration where the HA3 link did not come up after you upgraded to PAN-OS 8.1.0 or a later PAN-OS 8.1 release.
## PAN-90920
Fixed an issue on PA-5200 Series firewalls where the dataplane restarted due to an internal path monitoring failure.
## PAN-90692
Fixed an issue where PA-5200 Series firewalls dropped offloaded traffic after you enabled session offloading (enabled by default), configured subinterfaces on the second aggregate Ethernet (AE) interface group (ae2), and configured QoS on a non-AE interface.
## PAN-90690
Fixed an issue where Panorama appliances ignored the time-zone offset in logs sent from the Traps Endpoint Security Manager (ESM).
## PAN-90623
Fixed an issue where the Panorama management server displayed template configurations as Out of Sync for firewalls with multiple virtual systems even though the template configurations were in sync.
## PAN-90418
Fixed an issue where PA-7000 Series, PA-5200 Series, PA-5000 Series, PA-3200 Series, and PA-3000 Series firewalls dropped packets because their dataplanes restarted due to QoS queue corruption.
## PAN-89988
Fixed an issue where the firewall dataplane intermittently restarted, causing traffic loss, after you attached a NetFlow server profile to an interface for which the firewall assigned an invalid identifier.
## PAN-89794
Fixed an issue on PA-3050, PA-3060, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls in a high availability (HA) configuration where multicast sessions intermittently stopped forwarding traffic after HA failover on firewalls with hardware offloading enabled (default).
## PAN-88674
Fixed an issue on the Panorama management server where administrators with the superuser read-only role could view the Password Hash used to access a Log Collector CLI after another superuser used browser developer tools to modify the input type for that field (**Panorama** > **Managed Collectors** > **<Log_Collector>** > **Authentication**).
## PAN-88428
Fixed an issue where the VM-Series firewall incorrectly displayed network interfaces as having a Link Speed of 1000 and a Link Duplex set to half when the actual values were different (**Network** > **Interfaces** > **<interface>** > **Advanced**).
## PAN-87265
Fixed an issue where the Panorama management server displayed no output for the User Activity Report (**Monitor** > **PDF Reports** > **User Activity Report**).
## PAN-87079
```caveat
PA-3060, PA-3050, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
Fixed an issue where Threat logs displayed an Other IP Flood message instead of identifying the threat name of the correct protocol (such as TCP Flood) when traffic reached the configured SYN flood max-rate threshold (**Objects** > **Security Profiles** > **DoS Protection** > **<DoS_Protection_profile>** > **Flood Protection** > **SYN Flood**).
## PAN-86672
Fixed an issue where in rare cases a commit caused the disk to become full due to an incorrect disk quota size value, and as a result the firewall behaved unpredictably (for example, the web interface and CLI became unresponsive).
## PAN-86647
Fixed an issue on the Panorama management server where editing the **Description** of a shared policy rule and clicking **OK** caused the **Target** setting to revert to Any firewalls instead of the selected firewalls.
## PAN-84647
Fixed an issue with scheduled log exports that prevented firewalls running in FIPS-CC mode from successfully exporting the logs using Secure Copy (SCP).
## PAN-84238
Fixed an issue where the Panorama management server failed to push configurations to firewalls running a PAN-OS 7.1 release and displayed the following error:
wins-server-> primary is invalid
## PAN-80922
Fixed an issue where the firewall failed to parse the merged configuration file after you changed the master key; it parsed only the running configuration file. With this fix, the firewall parses both files as expected after you change the master key.
## PAN-68256
Fixed an issue on PA-7000 Series firewalls in a high availability (HA) configuration where the HA data link (HSCI) interfaces intermittently failed to initialize properly during bootup.
## PAN-48553
Fixed an issue where, after pushing the high availability (HA) Group ID from a Panorama management server to a firewall and overriding the value on the firewall (**Device** > **High Availability** > **General** > **Setup**), the following error displayed even though the value was within the permitted range:
deviceconfig -> high-availability-> group -> should be equal to or between 1 and 63.
@@ -0,0 +1,547 @@
---
type: Addressed
product: PAN-OS
version: 8.1.3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-4645
Fixed an issue where RAID rebuilding after disk replacement either failed or took longer than expected.
## PAN-101101
Fixed an issue with inconsistencies in the IP address-to-username mappings after upgrading the User-ID agent to a User-ID agent 8.1 release.
## PAN-100896
Fixed an issue where the dataplane restarted multiple times when multiple processes stopped responding when accessing invalid memory.
## PAN-100870
Fixed an issue where the GlobalProtect app incorrectly displays a warning (Password Warning:Password expires in 0 days) even though the password has not, yet, expired.
## PAN-100312
Fixed an intermittent issue where the dataplane restarted when processing Clientless VPN traffic.
## PAN-100015
Fixed an issue where a PA-7000 Series firewall with a 20GQ Network Processing Card (NPC) failed to properly initiate all QSFP modules.
## PAN-99968
Fixed an issue where the firewall incorrectly dropped GTPv2-C Modify Bearer Response packets due to a sequence-number mismatch.
## PAN-99896
Fixed an issue where the route (routed) process on a passive firewall in a high availability (HA) cluster restarted when receiving an update from the active peer for a multicast route destined for a multicast group that does not exist on the firewall.
## PAN-99624
Fixed an issue where emails were not sent using the configured email service route as expected.
## PAN-99585
Fixed an issue where a PA-3200 Series firewall processed traffic that was in suspended mode
## PAN-99584
Fixed an issue where a PA-5200 Series firewall processed traffic that was in suspended mode.
## PAN-99380
Fixed an issue where the dataplane stopped responding when a tunnel interface on the firewall received fragmented packets.
## PAN-99362
Fixed an issue on a VM-Series firewall on Azure where a process (logrcvr) stopped responding.
## PAN-99316
Fixed an issue where the SAP Success Factor app failed to load because the Cipher-cloud was configuring cookies with the at ( @ ) character in the cookie name but Palo Alto Networks firewalls used the @ character as a separator for storing cookies locally, which caused the firewall to misinterpret the cookies.
## PAN-99263
Fixed an issue where NetFlow caused an invalid memory-access issue that caused the pan_task process to stop responding.
## PAN-99212
Fixed an issue where the firewall incorrectly dropped ARP packets and increased the flow_arp_throttle counter.
## PAN-99067
Fixed an issue where a firewall frequently flapped a BGP session when the firewall did not receive any response from the BFD peer or when BFD was configured only on the firewall.
## PAN-98735
Fixed an issue where upgrading a Panorama management server on Microsoft Azure from PAN-OS 8.1.0 to PAN-OS 8.1.1 or PAN-OS 8.1.2 resulted in an autocommit failure.
## PAN-98624
Fixed an issue where an administrator who has all administrative rights is unable to add a device to Panorama from the web interface.
## PAN-98530
Fixed a memory leak associated with the logrcvr process when using custom syslog filters in a syslog profile.
## PAN-98470
Fixed an issue on a firewall with GTP stateful inspection enabled where the firewall incorrectly identified GTP echo packets as GTP-U application packets.
## PAN-98397
Fixed an issue on PA-3200 series firewalls where the offload processor did not process route-deletion update messages , which left behind stale route entries and caused sessions to become unresponsive during the session-offload stage.
## PAN-98329
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where an SFP+ (10Gbps PAN-SFP-PLUS-CU-5M) transceiver was incorrectly identified as an SFP (1Gbps) transceiver.
## PAN-98217
Fixed an issue where user-account group members in subgroups (n+1) were unnecessarily queried when nested level was set to n.
## PAN-98116
Fixed an issue where PA-3000 Series firewalls passed file descriptors in a dataplane process (pan_comm) during content (apps and threats) installation and FQDNRefresh job execution, which caused the hardware Layer 7 engine to identify applications incorrectly.
## PAN-98097
Fixed an issue on PA-3000 Series, PA-3200 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls where Captive Portal was inaccessible for traffic on Secure HTTP (https) websites when SSL decryption was enabled and users were behind a proxy server.
## PAN-98088
Fixed an issue where an error (mailsend: failed to get stat of file) appeared in the System log due to an incorrect condition check even though there were no issues with the firewall sending PDF reports.
## PAN-97905
Fixed an issue where device-group operations were discarded when a concurrent commit was triggered by a different administrator.
## PAN-97810
Fixed an issue where, after upgrading to PAN-OS 8.1.1, User-ID usernames were not populated in traffic logs as expected even though User-ID mappings were present on the dataplane.
## PAN-97724
Fixed an issue with the Japanese language mode where a firewall displayed garbled characters when an administrator was logging in to the web interface.
## PAN-97634
Fixed an issue where the firewall rebooted when the management (MGT) interface was connected to a network that contained a network loop, which caused excessive traffic flow on the interface. This issue was observed only on a PA-220 firewall.
## PAN-97594
Fixed an issue where administrators could not use the new colors that were introduced in PAN-OS 8.1 for creating and modifying banners and messages; these colors were unavailable from the CLI and, though available from the web interface (**Device** > **Setup** > **Management** > **Banners and Messages** > **Banners**), administrators received an Operation Failed error when attempting to use them.
## PAN-97561
Fixed an issue where a Panorama appliance running PAN-OS 8.1.2 was unable to connect to the Logging Service.
## PAN-97497
Fixed an issue where the default for newly added cloned security rules was **Move Top**, which placed the new rule at the top of the list. With this fix, the default is **After Rule** as it was in PAN-OS 8.0 and earlier releases.
## PAN-97282
Fixed an issue where Inbound inspection failed when a cipher was cleared from the TLS structure during session resumption.
## PAN-97225
Fixed an issue where new Vendor names for the HIP check were not included when Panorama pushed the configuration to firewalls.
## PAN-97208
Fixed an issue where a firewall in a high availability (HA) active/active virtual wire (vwire) configuration with SSL decryption enabled passed traffic through the wrong firewall.
## PAN-97082
Fixed an issue where the firewall incorrectly blocked SSL sessions subjected to Inbound decryption due to UnsupportedVersion when the Decryption rule referenced a decryption profile with **Min - Max TLS Version**, even though **Block sessions with unsupported versions** was disabled (**Objects** > **Decryption** > **Decryption Profile**). With this fix, the firewall checks the TLS version that the server accepted and compares it with the decryption profile settings when evaluating whether to allow or bypass sessions based on Decryption rules.
## PAN-97060
Fixed an issue where the User-ID (useridd) process stopped responding due to an out-of-memory issue related to User-ID group mapping.
## PAN-97045
Fixed an issue on PA-850 firewalls where the session rematch option failed to execute when you added an IP address to the External Dynamic List (EDL) block list.
## PAN-96997
Fixed an intermittent issue where detecting an unreachable WF-500 node took longer than expected.
## PAN-96978
Fixed an issue where the **GlobalProtect Clientless VPN** and **GlobalProtect Data** options did not display as expected on Panorama (**Template** > **Device** > **Dynamic Updates**).
## PAN-96918
Fixed an issue where an unreachable DNS server due to aggressive timers increased the time of PPPoE negotiation and, in some cases, caused negotiation to fail.
## PAN-96909
A security-related fix was made to address a Denial of Service (DoS) that existed in the PAN-OS management web interface and allowed an authenticated user to shut down all management sessions, which causes the firewall to redirect all logged-in users to the login page (CVE-2018-10140).
## PAN-96889
Fixed an issue where administrators were required to perform a commit force before pushing a partial or regular commit operation to managed appliances when the management server (mgmtsrvr) or configuration (configd) process encountered a virtual memory leak and restarted.
## PAN-96779
Fixed an issue where using the the XML API to retrieve Hit Count on a security rule returned an error message: Anerror occurred. See dagger.log for information.
## PAN-96737
Fixed an issue with an incorrect policy match because google-docs-base was incorrectly identified as SSL.
## PAN-96388
Fixed an issue in a non-vsys configuration where a firewall dropped the Client Hello packet from tunneled traffic when inbound decryption was enabled because the firewall considered that packet to be an inter-vsys inbound packet.
## PAN-96326
Fixed an issue where endpoints could not authenticate to a GlobalProtect portal or gateway through client certificate authentication due to an OCSP status of Unknown when the portal or the gateway used a Certificate profile that specified Online Certificate Status Protocol (OCSP) to validate certificates (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Authentication**).
## PAN-96200
Fixed an issue where PA-220 firewalls that were bootstrapped with a configuration that enabled jumbo frames did not change the packet buffer size as expected, which resulted in a dataplane restart.
## PAN-96150
Fixed a memory corruption error that caused the dataplane to restart when content decode length was zero.
## PAN-96113
Fixed an issue where the show routing protocol bgp rib-out CLI command did not display advertised routes that the firewall sent to the BGP peer. This issue was observed only in a deployment where a firewall is connected to a Border Gateway Protocol (BGP) peer that advertised a route for which the next hop is not in the same subnetwork as the BGP peer interface.
## PAN-96003
Fixed an issue where the GTP Protection profile name did not appear in the **Global Find** and **Filter** options in the Profile column of the security rule to which the GTP profile was attached.
## PAN-95996
Fixed an issue where Panorama virtual appliances converted from legacy mode to Panorama mode did not properly purge logs, which caused low disk space issues in /opt/panlogs partition.
## PAN-95993
Fixed an issue where the firewall did not properly identify the google-translate application.
## PAN-95955
Fixed an issue on PA-3200 Series firewalls where incorrect internal memory allocation reduced the number of simultaneous SSL decryption sessions that the firewall could support.
## PAN-95884
Fixed an issue where routing FIB entries that were learned from a BGP peer were not deleted when BGP Peering went down.
## PAN-95854
Fixed an issue where the Filter drop-down did not display properly when you keep the default Target for a Policy rule set to **Any**.
## PAN-95766
Fixed an issue where Q-in-Q-tagged packets passed through a firewall without inspection or session creation.
## PAN-95740
Fixed an issue where multicast FIB entries were inconsistent across dataplanes, which caused the firewall to intermittently drop multicast packets.
## PAN-95730
Fixed an issue where a firewall dropped SIP-RTP packets flowing through a GRE tunnel when a Tunnel Inspection Policy was configured with Security Options (Tunnel Inspection zones).
## PAN-95712
Fixed an issue where browsers failed to load custom response pages on decrypted websites when those pages were larger than 8,191 bytes. With this fix, the firewall supports decryption of custom response pages up to 17,999 bytes.
## PAN-95509
Fixed an issue where the parent device group in the hierarchy did not automatically acquire read-only access for a URL Profile as expected after you assigned write access to a child device group of that parent.
## PAN-95476
Fixed an issue where a certificate failed to load when the certificate public key exceeded the supported number of characters (2,048).
## PAN-95439
Fixed an issue where using the test nat-policy-match command from the XML API does not result in any matches when the matching policy is a destination NAT policy.
## PAN-95339
Fixed an issue where a firewall sent packets out of order when the sending rate was too high.
## PAN-95192
Fixed an issue where the SSL Certificate Error Notify page didn't display the <certname/> <issuer/> variables in the SSL-cert-status-page.
## PAN-95120
Fixed an issue where VM-Series firewall bootstrapping failed when you transferred the bootstrap package using a base64 encoded user-data file.
## PAN-95114
Fixed an issue where TACACS+ authorization responded with Illegal packet version because a firewall was incorrectly sending minor version 1, which impacts TACACS+ servers and causes a failed authorization.
## PAN-95113
Fixed an where issue where non-local administrators using TACACS were unable to log in to the CLI.
## PAN-95090
Fixed an issue where imported custom applications did not display in Security Policies that were created through the web interface.
## PAN-95061
Fixed an issue on PA-220 firewalls where either a commit or an EDLRefresh job failed with the following error message: failed to handle CONFIG_UPDATE_START. This issue occurred after an increase in the number of type URL entries in an external dynamic list.
## PAN-95046
Fixed an issue where the dataplane restarted on a VM-Series firewall on KVM.
## PAN-94920
Fixed an issue where PA-5200 Series firewalls in a high availability (HA) active/active configuration experienced internal packet corruption that caused the firewalls to stop passing traffic when the active member of a cluster came back up as passive after being either suspended or rebooted (moving from tentative to passive state).
## PAN-94864
Fixed an issue where firewalls receiving IP addresses via DHCP failed to resolve FQDN objects to an IP address.
## PAN-94777
Fixed an issue where a 500Internal Server error occurred for traffic that matched a Security policy rule with a URL Filtering profile that specified a continue action (**Objects** > **Security Profiles** > **URL Filtering**) because the firewall did not treat the API keys as binary strings.
## PAN-94698
Fixed an issue on PA-5000 Series firewalls where a process (all_pktproc) on the dataplane stopped responding if you enabled the **send icmp unreachable** Action Setting (**Policies** > **<rule>** > **Actions**).
## PAN-94646
Fixed an issue with firewalls in a high availability (HA) configuration where a an HA sync initiated from the active peer caused a race condition while processing the previous request.
## PAN-94637
Fixed an issue where an XML API call to execute the request system external-list show command did not escape the ampersand ( & ) character in the Source section of the XML output, which resulted in a parse error.
## PAN-94571
Fixed an issue on PA-800 Series, PA-3200 Series, and PA-5200 Series firewalls where tunnel-bound traffic was incorrectly routed through an ECMP route instead of a PBF route as expected.
## PAN-94497
Fixed an issue where the default static route was not present in the routing table after you removed the DHCP-provided default gateway when you configured a default static route and DHCP provided the same default route.
## PAN-94452
Fixed an issue where the firewall recorded GPRS Tunneling Protocol (GTP) packets multiple times in firewall-stage packet captures (pcaps).
## PAN-94447
Fixed an issue where deleting all FQDN objects that are no longer in use did not remove them from the FQDN refresh table, which caused firewalls to continue resolving these old objects per the schedule.
## PAN-94409
Fixed an issue where FTP traffic failed and hit an incorrect security policy due to missing predict sessions.
## PAN-94291
Fixed an issue where a firewall failed to process packets if the previous session was cleared (either from the CLI or web interface), the client uses the same source port, and when the new session is installed on dataplane1 (dp1).
## PAN-94290
Fixed an issue where fragmented packets were dropped when traversing a firewall in an HA active/active configuration.
## PAN-94221
Fixed an issue when QoS was configured where the dataplane restarted due to a packet process failure.
## PAN-94124
Fixed an issue where a PA-800 Series firewall dropped UDP packets traversing port 0.
## PAN-94062
Fixed an issue where the dataplane stopped responding due to a failed packet buffer initialization after the firewall rebooted.
## PAN-94043
Fixed an issue where, when an administrator made and committed partial changes, the disabled address objects used in a disabled security policy were pushed from Panorama and retained on the firewall but were deleted when an administrator performed a full commit from Panorama.
## PAN-93990
Fixed an issue where a VM-Series firewall was unable to ping the gateway in a multiple virtual router configuration when interfaces received IP address through DHCP.
## PAN-93973
Fixed an issue on an M-100 appliance where logging stopped when a process (vldmgr) stopped responding.
## PAN-93864
Fixed an issue where the password field did not display in the GlobalProtect portal login dialog if you attached the certificate profile to the portal configuration.
## PAN-93811
Fixed an issue where the Panorama task manager view on the web interface stopped responding after multiple appliances reported multiple errors and warnings in commit job details.
## PAN-93754
A security-related fix was made to address vulnerabilities related to some SAML implementations (CVE-2018-0486 and CVE-2018-0489). Refer to [www.kb.cert.org/vuls/id/475445](https://www.kb.cert.org/vuls/id/475445) for details.
## PAN-93753
Fixed an issue on PA-200 firewalls where disk space usage was constantly running high and often reaching maximum capacity. With this fix, the PA-200 firewall purges logs more quickly and it no longer requires as much space for monitor daemons.
## PAN-93609
Fixed an issue where the firewall silently dropped the first packet of a session when that packet was received as a fragmented packet (typically with UDP traffic).
## PAN-93457
Fixed an issue where continuous renewal for a session that went into DISCARD state when the firewall reached its resource limit prevented the creation of new sessions that matched that DISCARD session.
## PAN-93331
Fixed an issue where the firewall applied the wrong checksum when a re-transmitted packet in a NAT session had different TCP flags, which caused the recipient to drop those packets.
## PAN-93329
Fixed an issue where the non-session-owner firewall in a high availability (HA) active/active configuration with asymmetric traffic flow dropped TCP traffic when TCP reassembly failed.
## PAN-93152
Fixed an intermittent Panorama issue where, after upgrading to PAN-OS 8.0 or a later release and when connected to a WF-500 appliance, commit validations failed due to a mismatched threat ID range on the WildFire private cloud.
## PAN-93005
Fixed an issue where the firewall generated System logs with high severity for Dataplane undersevere load conditions that did not affect traffic. With this fix, the System logs have low severity for Dataplaneunder severe load conditions that do not affect traffic.
## PAN-92745
Fixed an issue where the Vulnerability Protection profile exceptions view included threat IDs that were disabled or not supported for the PAN-OS release version. Now, only IDs for signatures that are included in the currently-installed content package are displayed.
## PAN-92740
Fixed an issue in an NSX environment where the Panorama management server displayed an incorrect number of tags under Dynamic Address Groups when you configured a static tag in one or more address groups.
## PAN-92609
Fixed an issue where the firewall could not forward full information for a Protocol-Independent Multicast (PIM) group to a peer PIM router when the PIM bootstrap message was larger than the maximum transmission unit (MTU) of the firewall interface.
## PAN-92548
Fixed an intermittent issue where a race condition caused the Logging Service or WF-500 appliances to disconnect from or become unresponsive to firewalls or the Panorama management server.
## PAN-92257
Fixed an issue where the firewall was intermittently sending incorrect bytes-per-packet values for some flows to the NetFlow collector.
## PAN-92105
Fixed an issue where the Panorama Log Collectors did not receive some firewall logs and took longer than expected to receive all logs when a Collector Group had spaces in its name.
## PAN-92033
Fixed an issue during the software download process that prevented some firewalls and appliances from properly receiving these images.
## PAN-92017
Fixed an issue where Log Collectors that belonged to a collector group with a space in its name failed to fully connect to one another, which affected log visibility and logging performance.
## PAN-91926
Fixed an issue where GlobalProtect users could not access some websites decrypted by the firewall due to an issue with premature deletion of proxy sessions.
## PAN-91662
Fixed an issue where a certificate was loaded without a digital signature, which caused the configuration (configd) daemon to stop responding.
## PAN-91316
Fixed an issue where you couldn't unlock administrator accounts with expired passwords because the firewall didn't display a lock icon for their accounts in the Locked User column (**Device** > **Administrators**).
## PAN-91259
Fixed an issue where the predict session for the rmi-iiop application was not created correctly, which caused server-to-client initiated sessions to traverse slow-path inspection and, eventually, policy rules denied the traffic associated with these sessions.
## PAN-91021
Fixed an issue where, in a multiple virtual system (vsys) configuration on Panorama, you could not add a certificate defined in vsys to a certificate profile in the same vsys unless the vsys was defined using the default name.
## PAN-90952
Fixed an issue on PA-5000 Series firewalls where multicast traffic failed because PAN-OS did not remove stale sessions from the hardware session offload processor.
## PAN-90752
Fixed an issue on Panorama where the Last Commit State column (**Panorama** > **Managed Devices**) did not get updated after a Template-Only configuration push to firewalls.
## PAN-90535
Fixed an issue where the firewall unnecessarily sent an Authorize-only request to the RADIUS server which was denied during the login process if you disabled the **Retrieve Framed-IP-Address attribute from authentication server** (**Network** > **GlobalProtect** > **Gateways** > **<gateway>** > **Agent** > **Client Settings** > **<clients_configuration>** > **IP Pools**) in the GlobalProtect gateway configuration.
## PAN-89620
Fixed an intermittent issue where traffic stopped flowing through the IPSec tunnel in a hub-and-spoke multiple-vendor configuration.
## PAN-89346
Fixed an issue where an XML API call to execute the show system raid detail command returned an error.
## PAN-88473
Fixed an issue where the firewall was sending incorrect bytes-per-packet values to the NetFlow collector when two servers were configured in the same NetFlow profile.
## PAN-88048
Fixed an issue where a VM-Series firewall on KVM in MMAP mode didn't receive traffic after you enabled the i40e single-root input/output virtualization (SR-IOV) virtual function (VF).
## PAN-87855
Fixed an issue where some ICMP Type 4 traffic was not blocked as expected after you created a deny Security policy rule with custom App-ID for ICMP Type 4 traffic.
## PAN-87166
Fixed a rare issue on PA-7000 Series firewalls where 20GQ NPC QSFP+ ports didn't link up (during online insertion and removal (OIR), link-state change, or boot up events) and became unrecoverable until the NPC was restarted.
## PAN-86769
Fixed an issue where a firewall did not forward logs when using the category eq command-and-control filter.
## PAN-86630
Fixed an issue where the firewall dropped H.323 gatekeeper-assisted calls after failing to perform NAT translation of third-party addresses in H.323 messages.
## PAN-86327
Fixed an issue where the firewall rebooted into maintenance mode.
## PAN-85522
Fixed an issue on PA-5200 Series firewalls where an SFP+ (10Gbps) transceiver (PAN-SFP-PLUS-CU-5M) was incorrectly identified as an SFP (1Gbps) transceiver.
## PAN-83153
Fixed an issue where a Panorama virtual appliance in Legacy mode that was deployed in a high availability (HA) configuration did not receive logs forwarded from PA-7000 Series and PA-5200 Series firewalls.
## PAN-83047
Fixed an issue where the firewall displayed the following commit warning when you configured a GlobalProtect gateway with a **Tunnel Interface** set to the default **tunnel** interface (**Network** > **GlobalProtect** > **Gateways** > **<gateway>** > **General**) even after you enabled IPv6: Warning: tunnel tunnel ipv6 is not enabled. IPv6 address will be ignored!
## PAN-80091
Fixed an issue where no results were returned for a Global Find request when using the short name domain\group format.
## PAN-79291
Fixed an intermittent issue with ZIP hardware offloading where firewalls identified ZIP files as threats when they were sent over Simple Mail Transfer Protocol (SMTP).
## PAN-42036
Fixed a rare intermittent issue on PA-800 Series, PA-2000 Series, PA-3000 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls where the firewall unexpectedly rebooted due to memory page allocation failure, which generated a non-maskable interrupt (NMI) watchdog error on the serial console.
## PAN-33746
Fixed an issue where the firewall dropped IKE traffic when another IKE session was in the discard state on the firewall because the the new session matched the discard session. This issue persisted because the discard sessions remained on the firewall longer than expected because the firewall refreshed the discard-session timeout each time the 5-tuple on a new session matched the 5-tuple on the discard session.
@@ -0,0 +1,483 @@
---
type: Addressed
product: PAN-OS
version: 8.1.4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-4739
Fixed an issue where WF-500 appliances failed to analyze Excel files because the files contained links and required a manual response to a popup dialog about whether to update those links before opening the file.
## WF500-4738
Fixed an issue where the WF-500 appliance factory reset failed.
## WF500-4737
Fixed an issue on a WF-500 appliance where in maintenance mode, network activity did not occur.
## WF500-4690
Fixed an issue where the WF-500 appliance reported incorrect memory utilization values through SNMP (hrStorageUsed).
## WF500-4664
Fixed an issue where the WF-500 appliance SNMP notifications did not provide information for the eth2 and eth3 interfaces.
## WF500-4466
Fixed an issue on WF-500 passive cluster members where file forwarding was incorrectly disabled, which prevented the passive firewall from uploading samples.
## WF500-4362
Fixed an issue on WF-500 appliances that caused a compliance scan to incorrectly report two vulnerabilities: SSL Server Supports DES Ciphers (Sweet32 Exposure) and NGINX Log Escape Sequence Injection Vulnerability.
## PAN-105724
Fixed an issue where the firewall did not generate a new random value in the TLS Server Hello message, which breaks TLSv1.3 connections when SSL Forward Proxy decryption is enabled.
## PAN-104920
Fixed an issue where administrators were not able to create a WF-500 cluster unless they first configured an HA1 backup.
## PAN-104293
Fixed a rare issue where PA-3200 Series firewalls started dropping offloaded traffic.
## PAN-104131
Fixed an issue with the Panorama Interconnect plugin where Panorama Node child jobs were not displayed under Panorama Controller Tasks (**Panorama** > **Interconnect** > **Tasks**) as expected when you tried to **Push Common Config** (**Panorama** > **Interconnect** > **Panorama Nodes**).
## PAN-104116
Fixed an issue where a hardware packet buffer leak caused firewall performance to degrade.
## PAN-103921
Fixed an issue on a PA 3200 Series firewall where the dataplane failed due to an internal path monitoring failure.
## PAN-103442
Fixed an intermittent issue on a PA-3200 Series firewall where the forwarding information base (FIB) did not update correctly, which prevented successful forwarding of offloaded traffic.
## PAN-102943
Fixed an Issue where a process (mgmtsrvr) failed on EDL refresh when configured over a Secured Socket Layer (SSL) connection.
## PAN-102750
Fixed an issue on a PA-5000 Series firewall where the dataplane restarts when multicast traffic matched a stale session on the offload processor that was not cleared as expected.
## PAN-102664
Fixed an issue where a process (rasmgr) restarted when a satellite tunnel tear down command and a get user config command occurred simultaneously.
## PAN-102631
Fixed an issue where a process (rasmgr) restarted multiple times, which caused the firewall to reboot.
## PAN-102168
Fixed an issue where a PA-5200 Series firewall processed the tunnel-monitoring with profile-failover as having the tunnel status up and peers as down during initial configuration.
## PAN-102140
Fixed an issue where Extended Authentication (X-Auth) clients intermittently failed to establish an IPSec tunnel to GlobalProtect™ gateways.
## PAN-101955
Fixed an issue on an M-100 appliance in a high availability (HA) configuration where administrators could not reestablish access to the appliance after a session ended unexpectedly.
## PAN-101704
Fixed an issue where a configured Layer 3 interface erroneously opened ports 28869/tcp and 28870/tcp on the IP address assigned to that Layer 3 interface.
## PAN-101289
Fixed an issue where simultaneous management access allowed only one user to log in at a time.
## PAN-101182
Fixed an issue where a system failure occurred due to packet size exceeding the hardware limit.
## PAN-100985
Fixed an issue with PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls where the firewall fails to clear cache for refreshing the FQDN list, which periodically results in an out of memory condition that forces the firewall to reboot.
## PAN-100794
Fixed an issue where SNMP fan trays did not initialize as expected and prevented the SNMP manager from receiving fan tray information.
## PAN-100715
Fixed an issue on VM-Series firewalls where the dataplane stops processing traffic when attempting to transmit packets larger than the firewall maximum transmission unit (MTU).
## PAN-100345
```caveat
PA-200, PA-220, PA-220R, PA-500, and PA-800 Series firewall only
```
Fixed an issue where a large number of group mappings caused the firewall to display out-of-memory (OOM) errors and restart.
## PAN-100031
Fixed an issue where the content rewriter module failed to properly handle simultaneous chunked and zipped responses, and did not send end of response.
## PAN-99964
Fixed an issue on an M-100 appliance where a bulk set of commands timed out causing config locks and, while running any subsequent show commands, responded with the following message: Server error: Timed out while getting config lock. Please try again.
## PAN-99936
Fixed an issue where access to Panorama™ accounts failed due to the removal of IPv4 address and exclusive use of IPv6 on the management (MGT) port.
## PAN-99897
Fixed an issue where a configuration change commit was accepted when only one virtual wire (vwire) interface was defined in a vwire pair. With this fix, a commit for a change where only one vwire interface is defined for a vwire pair is rejected and an error message is displayed.
## PAN-99830
A security-related fix was made to address a cross-site scripting (XSS) vulnerability in the GlobalProtect Portal login page.
## PAN-99780
Fixed an issue where the second virtual system (vsys) dropped TCP traffic that was out-of-order when that second vsys controlled the proxy session in a multi-vsys configuration.
## PAN-99590
Fixed an issue where the firewall did not return Captive Portal response pages as expected due to depletion of file descriptors.
## PAN-99392
Fixed an issue where RADIUS VSA administrators were able to login for one hour after their VSA administrator role was removed on the RADIUS server.
## PAN-99310
Fixed an issue where the firewall attempted to reconnect to the LDAP server when an empty Distinguished Name (DN) returned for an invalid user.
## PAN-99260
Fixed an issue where the firewall dataplane restarted due to missing SIP parent information after an HA failover event.
## PAN-99141
Fixed an issue in an HA active/active virtual wire configuration where a race condition caused the firewall to intermittently drop First SYN packets when they traversed the HA3 link.
## PAN-99110
Fixed an issue where a library (libpam_pan.so) did not handle incorrect passwords as expected.
## PAN-99095
Fixed an issue in Panorama where a commit failed message appeared in the Template Last Commit column in the device management summary after a Panorama reboot or upgrade.
## PAN-99060
Fixed an issue where searching through pcaps from a Log Collector in a configuration with multiple Log Collectors took longer than expected.
## PAN-98976
Fixed an intermittent issue where Captive Portal multi-factor authentication (MFA) failed and discarded new MFA requests.
## PAN-98949
Fixed an issue on Panorama where generating a threat pcap from the web interface (**Monitor** tab) took longer than expected and caused the web interface and CLI to become inaccessible.
## PAN-98885
Fixed an issue where high elastic search memory load caused the firewall not to display logs and reboot
## PAN-98694
Fixed an issue on a PA-5200 Series firewall in an HA active/passive configuration where the firewall dropped TCP-FIN packets after a failover.
## PAN-98635
Fixed an issue on the Panorama centralized management server where the logs related to the clear-log system were not forwarded to the Syslog server.
## PAN-98632
Fixed an issue on VM-Series firewalls where administrators could not log in to a firewall with an AMI image created from a virtual machine (VM).
## PAN-98504
A security-related fix was made to address three OpenSSL vulnerabilities: CVE-2018-0732, CVE-2018-0737, and CVE-2018-0739.
## PAN-98479
Fixed an issue where Panorama displayed a File not found error when you attempted to view or download Threat pcaps from the **Monitor** tab.
## PAN-98392
Fixed an issue where the commit failed and the device server log displayed the following message: failed to handle CONFIG_UPDATE_START.
## PAN-98320
Fixed an issue where after you exit a process, a fixed amount of memory did not release which caused memory leaks.
## PAN-98195
Fixed an issue on a PA-220 firewall in an HA active/passive configuration and with jumbo frames enabled (**Device** > **Setup** > **Session**) where configuration and dynamic updates failed to synchronize.
## PAN-98189
Fixed an issue where firewall overrides configuration to not validate first ASN, resulting in multi-lateral BGP connection flaps peering over an internet exchange.
## PAN-98101
Fixed an issue where a log record in the JSON query caused a process (reportd) to fail.
## PAN-97881
Fixed an issue where an administrator with the CLI Device Read privilege was able to discard a session that was revoked.
## PAN-97832
Fixed an issue on VM-Series firewalls where the virtual machine (VM) information source made incorrect calls in FIPS-CC mode.
## PAN-97831
Fixed an issue where the set ssh service-restart mgmt CLI command did not respond correctly.
## PAN-97572
Fixed an issue in an HA active/passive configuration where URL request messages were not prioritized from the dataplane to the management plane and where a high rate of log generation in the dataplane caused inconsistent URL categorization.
## PAN-97547
Fixed an issue where the log in banner did not display properly when configured to single long-line.
## PAN-97358
Fixed an issue in an HA active/passive configuration where an HA sync job executed while a commit all job was processing.
## PAN-97355
Fixed an issue where the GlobalProtect connection failed with the following dataplane ICMPv6 message: Packet too big due to the firewall MTU value set lower than normal.
## PAN-97324
Fixed an issue where values were missing in the URL field in the Data Filtering logs.
## PAN-97315
Fixed an issue on Panorama M-Series and virtual appliances where the configuration (configd) process stopped responding after you entered a filter string and tried to **Add Match Criteria** for any **Dynamic** address group type (**Objects** > **Address Groups**).
## PAN-97296
Fixed an issue where the Panorama web interface **Group Mapping Setting** took longer to load than expected when there were multiple device groups and each group reported to a different master device.
## PAN-97253
Fixed an issue where audio failed for long-lived session initiated protocol (SIP) sessions subjected to six content updates.
## PAN-97084
Fixed a rare issue where the task manager failed to load in the web interface when a pending job caused subsequent completed jobs to be inappropriately held in memory.
## PAN-97077
Fixed an issue on Panorama M-Series and virtual appliances where the report-generation process stopped responding due to a corrupt log record in the JSON query.
## PAN-96796
Fixed an intermittent issue where session BIND messages were dropped in a Dynamic IP configuration.
## PAN-96780
Fixed an issue on a PA-3220 firewall where the external dynamic list refresh and commit, failed after an increase in the number of external dynamic list objects in the firewall.
## PAN-96678
Fixed an issue on PA-800 Series firewalls where the web interface did not display or allow you to configure the bandwidth setting any higher than 1Gbps.
## PAN-96645
Fixed an issue where generation of extraneous data filtering logs for SMB protocol traffic occurred without data filtering or file blocking securities rules in place.
## PAN-96579
Fixed an issue where the Syslog server received an incorrect vsys/port log message when multiple vsys systems, with the same profile name and different port numbers, are connected to a single syslog server.
## PAN-96565
Fixed an issue where the DNS proxy process failed due to a DNS response packet containing a TXT resource record with length = 0.
## PAN-96477
Fixed an issue where PA-5000 Series firewalls did not send an IGMP query immediately after an HA failover.
## PAN-96461
Fixed an issue where software deployment from Panorama to a managed firewall failed.
## PAN-96431
A security-related fix was made to prevent HTTP Header Injection in the Captive Portal.
## PAN-96316
Fixed an issue during a decrypted session on an L3 Aggregate Ethernet (AE) interface, where an incorrectly formatted threat packet capture (pcap) caused malformed packet captures during an inspection.
## PAN-96231
Fixed an issue where a commit took significantly longer than expected when cloning a rule compared to when configuring a new rule when the configuration contained a large number of rules.
## PAN-96183
Fixed an issue on Panorama M-Series and virtual appliances where logs failed to purge from the log-disks when /opt/pancfg partition usage reached 100%.
## PAN-96109
Fixed an issue where a Panorama appliance returned the following error: mgmtsrvr: User restart reason - Virtual memory limit exceeded (8204808 > 8192000).
## PAN-95999
Fixed an issue where firewalls in an HA active/active configuration with a default session setup and owner configuration dropped packets in a GlobalProtect VPN tunnel that used a floating IP address.
## PAN-95970
Fixed an issue on a PA-500 firewall where the dataplane tunnel content pointer entered a NULL state and caused dataplane processes (pan_comm and tund) to stop responding, which caused the dataplane to restart.
## PAN-95958
Fixed an issue where a PA-220 firewall did not recognize the panDeviceLogging SNMP object identifier.
## PAN-95931
Fixed an issue where some fields did not populate the template when logs are forwarded to the HTTP Server.
## PAN-95902
Fixed an issue where the header captions you configured for PDF Summary Reports or for Custom Reports were not used for the report name as expected.
## PAN-95815
Fixed an issue where the firewall returns an empty response for the API call show user ip-user-mapping.
## PAN-95765
Fixed an issue on Panorama where **Collector Groups** and **WildFire Appliances and Clusters** (**Commit** > **Push to Devices** > **Edit Selections**) that were already in sync with the current configuration were incorrectly selected and, thus, included when you attempted to push a configuration only to appliances that were not in sync.
## PAN-95698
Fixed an issue where the firewall revealed part of a password in cleartext on the command-line interface (CLI) and management server (mgmtsrvr) log when an administrator attempted to set a password that exceeded the maximum number of characters (31) using the CLI. With this fix, the firewall reports an error when an administrator attempts to set a password that contains more than 31 characters without revealing any part of the actual password.
## PAN-95438
Fixed an issue where Panorama M-Series and virtual appliances did not resolve the FQDN list because a bootstrap setting (cfg.product.bootstrap) was set to **factory_reset**.
## PAN-95407
Fixed an issue where an API call resulted in an incorrect response.
## PAN-95331
Fixed an issue where a temporary flap on configured Aggregate Ethernet (AE) interfaces cleared the dataplane debug logs.
## PAN-95265
Fixed an issue on a PA-220 firewall where exporting the device state from Panorama command-line interface (CLI) included the default bidirectional forwarding detection (BFD) configuration, which caused a commit to fail on the firewall when uploading the device state.
## PAN-95200
Fixed an issue on an M-100 appliance where reports did not generate in user groups.
## PAN-95119
Fixed an issue where TCP segments with large sequence numbers caused the dataplane to fail while large file sizes are transferred.
## PAN-95054
Fixed an issue where temporary files not properly cleaned caused disk space issues.
## PAN-95045
Fixed an issue where the syslog messages that terminated with 0 prevented the firewall from identifying matching patterns in the message.
## PAN-94559
Fixed an issue on an M-500 appliance where a bootstrapped firewall automatically added to Panorama did not commit the changes.
## PAN-94385
Fixed an issue on Log Collectors where the show log-collector serial-number <LC_serial_number> CLI command displayed log ages that exceeded log expiration periods.
## PAN-94236
Fixed an issue where files failed to upload to the WildFire cloud when file-forwarding queue limit was reached on the dataplane. When this occurred, the WildFire upload log included the file with a status of offset mismatch.
## PAN-93847
Fixed an issue where a null-pointer exception caused the device server (devsrv) process on the management plane to restart.
## PAN-93127
Fixed an intermittent issue where NAT traffic was dropped when NAT parameters were introduced or changed in the path between the LSVPN GlobalProtect gateway and the GlobalProtect satellite. To leverage this fix in your network, you must also enable Tunnel Monitoring on the GlobalProtect Gateway (**Network** > **GlobalProtect** > **Gateways** > **<gp-gateway>** > **Satellite** > **Tunnel Settings**).
## PAN-92955
Fixed an issue on PA-5200 Series firewalls in an HA active/active configuration where session timeouts occurred when TCP timers did not update as expected for asymmetric flows.
## PAN-92596
Fixed an issue where the output of the show neighbor ndp-monitor all command-line interface (CLI) command was missing a space between the Interface and IPv6 address columns, which decreased readability.
## PAN-92334
Fixed an issue where the process (cord) stopped responding when trying to forward correlation events if there was no log forwarding profile configured for correlated events.
## PAN-91874
Fixed an issue where the log receiver failed due to the logging certificate server name indication (SNI) value.
## PAN-91835
Fixed an issue where PA-7000 Series firewalls did not send logs to Panorama.
## PAN-91715
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
Fixed an issue where the destination interface configured for a QoS profile rule did not match traffic as expected.
## PAN-90967
Fixed an intermittent issue where the Bidirectional Forwarding Detection (BFD) up time displayed negative values.
## PAN-89849
Fixed an issue where the antivirus/anti-spyware block page did not display.
## PAN-89402
Fixed an issue on PA-3200 Series firewalls where Ethernet ports 2, 3, 4, 6, 7, 8, and 10 were functioning only at 1,000Mbps (1Gbps).
## PAN-87867
Fixed an issue on an M-100 appliance where, when the interface and snapshot length (snaplen) options were enabled, the tcpdump command failed to execute with the following message: Unsupported number of arguments.
## PAN-86759
Fixed an issue where the URL session information WildFire® report displayed Unknown for sample files uploaded from firewalls running a PAN-OS 8.0 release.
## PAN-84199
Fixed an issue where, after you disabled the **Skip Auth on IKE Rekey** option in the GlobalProtect gateway, the firewall still applied the option: end users with endpoints that used Extended Authentication (X-Auth) did not have to re-authenticate when the key for establishing the IPSec tunnel expired (**Network** > **GlobalProtect** > **Gateways** > **<gateway>** > **Agent** > **Tunnel Settings**).
## PAN-83946
Fixed an issue where the default QoS profile limited the available bandwidth to 10Gbps when you specifically applied the profile to the ae2 interface; this issue occurred regardless of the bandwidth setting you configured specifically for that profile.
## PAN-82987
Fixed an issue where the Panorama web interface intermittently became unresponsive during ACC queries.
## PAN-81553
Fixed an issue where the M-100 appliance used the default value of 1,000 because the maximum number of user groups was not defined in the system configuration.
@@ -0,0 +1,443 @@
---
type: Addressed
product: PAN-OS
version: 8.1.5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-4811
Fixed an issue where WF-500 appliances displayed the wrong WildFire® content version show system info after a WildFire content update.
## PAN-108805
Fixed an intermittent issue on PA-3200 Series firewalls where a process (all_pktproc_11) failed, which caused an out of memory condition and the dataplane to restart.
## PAN-107791
Fixed an issue where after upgrading from PAN-OS® 8.1.3 to 8.1.4 the CLI two-factor administrator authentication failed.
## PAN-107449
Fixed an issue where firewalls failed to establish IKE phase 1 or phase 2 when you specified Diffie-Hellman (DH) group1.
## PAN-107365
Fixed an issue on Panorama™ M-Series and virtual appliances where after you make a change to a template and attempt to push to a target device, the device does not appear in the Push Scope Selection list (**Commit** > **Push to Devices** > **Edit Selections** > **Device Groups**).
## PAN-107005
Fixed an issue on PA-3200 Series firewalls where packets dropped when a VSS-Monitoring Ethernet trailer was being appended by an external device.
## PAN-106936
Fixed an issue where PA-800 Series firewalls intermittently restarted due to a kernel error.
## PAN-106829
Fixed an issue on a PA-3200 Series firewall where the dataplane failed due to an internal path monitoring failure.
## PAN-106502
Fixed an issue where hardware packet buffers gradually depleted when LLDP packets created locally were sent to a down interface within an Aggregate Ethernet (AE) interface.
## PAN-106231
Fixed an intermittent issue where newly created IPSec Tunnels (**Network** > **IPSec Tunnels** > **Add**) did not activate.
## PAN-106016
Fixed an issue on PA-800 Series firewalls where a kernel memory spike caused the firewall to restart.
## PAN-105926
Fixed an intermittent issue on Panorama M-Series and virtual appliances where an address object referenced in the address group was allowed to be deleted without a reference error which caused commits to fail.
## PAN-105921
Fixed an issue with Panorama where administrators were unable to use the web interface to acquire a commit or configuration lock for device groups.
## PAN-105842
Fixed an issue on Panorama M-Series and virtual appliances where the Dynamic Address Group lists did not display and displayed the following error message: Command failed with no output.
## PAN-105695
Fixed an intermittent issue where the dataplane restarted while processing SMTP traffic.
## PAN-104876
Fixed an issue on Panorama managed devices where the green Template Values Exist indicator incorrectly displayed after you closed any interface settings (**Device** > **Setup** > **Interfaces**) even when you did not make any changes.
## PAN-104771
Fixed an issue where the HTTP header insertion entries caused the dataplane to restart.
## PAN-104764
Fixed an issue on Panorama management server when using Microsoft Azure or Amazon AWS where the management interface settings (**Device** > **Setup** > **Interface** > **Management**) is disabled.
## PAN-104668
Fixed an issue where a GTP PDP update did not update the GTP-U session which caused subsequent GTP traffic to drop.
## PAN-104524
Fixed an issue where the firewall logged data in the packet-diag log for IP addresses that you did not specify in the packet-capture filters when you enabled the tunnel:flow log feature.
## PAN-104406
Fixed an intermittent issue where the replace device CLI command caused the configuration lock to stop responding.
## PAN-104163
Fixed an issue where the show config audit base-version command continuously increased the number of file descriptors and caused the management server (mgmtsrvr) to exit and restart.
## PAN-104073
Fixed an issue where the replace device old <serial number> new <serial number> command caused the configuration process (configd) to stop responding.
## PAN-103820
Fixed and issue where the template stack retains the dynamic update schedule information after you remove it.
## PAN-103383
Fixed an issue where a firewall blocked SMTP traffic when processing ZIP files due to too many packet-process loops.
## PAN-103346
Fixed an issue where the LDAP Service Route Configuration (**Device** > **Setup** > **Services** > **Service Route Configuration**) did not respond when **Customize** was selected and **non-management interfaces** were enabled.
## PAN-103248
Fixed an issue where the process (routed) infinitely looped due to a corrupt internal OSPF database (DB) which caused OSPF adjacencies to be dropped.
## PAN-103132
A security-related fix was made to address the FragmentSmack vulnerability (CVE-2018-5391 / PAN-SA-2018-0012).
## PAN-102975
Fixed an issue where SSL enabled applications accessed through a GlobalProtect™ Clientless VPN caused buffer leaks.
## PAN-102743
```caveat
PA-5250, PA-5260, “PA-5280-8.1-only”, PA-5000 Series, and PA-7000 Series firewalls only
```
Fixed an intermittent issue where GlobalProtect SSL sessions that were enforcing client certificate authentication failed to resume and caused an authentication failure.
## PAN-102337
Fixed an issue on Panorama virtual appliances in a high availability (HA) configuration where the elastic search script failed to identify the master node due to case sensitivity in the serial number that caused log-replication failures when you enabled log redundancy.
## PAN-101981
Fixed an issue where installing path monitoring for static route on a satellite in a Large Scale VPN (LSVPN) infrastructure failed.
## PAN-101819
Fixed an issue where the Panorama Controller did not display all commit-all jobs for Panorama Nodes (**Panorama** > **Interconnect** > **Tasks**) and the Panorama Controller did not push those missing jobs during a Push to Devices action when the associated Panorama Node was running a PAN-OS 8.1 release.
## PAN-101604
Fixed an issue where the firewall did not correctly process OSPF link-state updates which caused the firewall to send incorrect updates externally, which resulted in ARP broadcasts that contained incorrect source MAC and source IP addresses.
## PAN-101585
```caveat
The following PA-7000 Series NPCs only: PA-7000-20G-NPC, PA-7000-20GQ-NPC, PA-7000-20GXM-NPC, PA-7000-20GQXM-NPC
```
Fixed an issue where an egress buffer overflow that impacted internal packet path monitoring caused a high availability (HA) failover. Additionally, enhancements were made to flow control communication between the traffic manager and flow engine components to improve system stability during periods of heavy traffic.
## PAN-101525
Fixed an issue where the EDL and FQDN address objects in the security and NAT policies displayed 0.0.0.0, which caused traffic to fail to match the policy.
## PAN-101492
Fixed an issue on Panorama M-Series and virtual appliances where after you configured the Authentication fields (**Panorama** > **Authentication Profile** > **Add** > **Authentication**) for the GlobalProtect gateway template stack, the saved configuration did not get applied.
## PAN-101425
Fixed an issue where after a redistribution profile was added, the OSPF configured with an authentication profile flapped.
## PAN-101378
Fixed an issue with firewalls in a high availability (HA) active/passive configuration where the firewall processed traffic in a suspended state.
## PAN-101368
Fixed an issue where SNMP polling displayed incorrect values, which caused authentication failures each time you restarted the firewall.
## PAN-101328
Fixed an intermittent issue where SSL decryption caused Content-ID™ to block files received over SMTP.
## PAN-101124
Fixed an issue where User Principal Names (UPN) which begin with the "at" ( @ ) character caused User-ID™ to fail.
## PAN-100862
Fixed an intermittent issue where a commit error occurred when an Aggregate Ethernet (AE) sub-interface was configured as the destination interface in a QoS policy rule.
## PAN-100719
Fixed an issue where Dynamic Updates pushed from Panorama to the Firewall displayed an incorrect None scheduled value.
## PAN-100613
Fixed an issue on a PA-5200 Series firewall in a high availability (HA) active/active configuration with a virtual wire (vwire) subinterface where session setup packets sent to peer firewalls were sent back as HA2/HA3 race conditions, which caused an increase in packet descriptors and traffic to stop responding.
## PAN-100538
Fixed an issue where exporting a device state (**Device** > **Setup** > **Operations**) from Panorama failed to import to the firewall.
## PAN-100448
Fixed an issue where a scheduled external dynamic list refresh displayed incorrect update values.
## PAN-100447
```caveat
VM-Series firewalls in a high availability (HA) configuration only
```
Fixed an issue when the management interface used DHCP Client-IP assignment where the automatic commits failed after multiple PAN-OS upgrade and downgrade cycles.
## PAN-100443
Fixed an issue on Panorama M-Series and virtual appliances in a high availability (HA) active/passive configuration where the passive firewall failed to connect to a newly deployed firewall with the following error message:vm-cfg: failed to process registration from svm device. vm-state: active.
## PAN-100395
Fixed an intermittent issue on a firewall where Dead Peer Detection (DPD) (**Network** > **IKE Gateways** > **Add**) was enabled and failed during IKE negotiations.
## PAN-100256
Fixed and issue on a firewall where a Device Group was selected, the App Scope Network Monitor report (**Monitor** > **App Scope >** > **Network Monitor**) failed to display data.
## PAN-100244
Fixed an issue where a failed commit or commit validation followed by a non-user-committed event (such as an FQDN refresh, an external dynamic list refresh, or an antivirus update) resulted in an unexpected change to the configuration that caused the firewall to drop traffic.
## PAN-100238
Fixed an issue where obsolete IPv6 host entries were not purged and remained in a REACHABLE state, which caused new entries to fail.
## PAN-100228
Fixed an intermittent issue on a PA-7000 Series firewall where auto-commits prematurely executed before all Network Processing Cards (NPCs) were detected and ready.
## PAN-100144
Fixed an issue on PA-7000 Series firewalls in a high availability (HA) active/active configuration where after a HA failover event the IP address rule list continuously duplicated entries and resulted in slow response times from the firewall and, eventually, caused the Network Processing Cards (NPCs) to restart.
## PAN-100049
Fixed an issue on Panorama M-Series and virtual appliances where Push Scope Selection (**Commit** > **Push to Devices**) selected firewalls not in the hierarchy of the firewall you selected.
## PAN-99966
Fixed an issue where Commit and Push (**Commit** > **Commit and Push**) failed and displayed the following validation error: log-settings profiles match-list send-email is not a valid reference when you attempted to import a firewall configuration to Panorama.
## PAN-99965
Fixed an issue where SNMP Object identifier queries for hrStorageAllocationUnits returned negative values.
## PAN-99861
Fixed an issue where SaaS application usage reports were empty when you used special characters in naming zones.
## PAN-99860
Fixed an issue on a PA-7000 Series firewall where the Network Processing Card (NPC) rebooted due to a memory allocation issue.
## PAN-99643
Fixed an issue where a change in user-mapping information prevented the host information profile (HIP) from updating.
## PAN-99582
Fixed an issue where a firewall in a high availability (HA) active/passive configuration did not send the Bidirectional Forwarding Detection (BFD) administrator down status after a manual failover.
## PAN-99525
Fixed an issue where the destination NAT (DNAT) using a dynamic IP address caused the dataplane to fail.
## PAN-99483
```caveat
PA-5250, PA-5260, and PA-5280 firewalls only
```
Fixed an issue where, when you deployed the firewall in a network that uses Dynamic IP and Port (DIPP) NAT translation with PPTP, client systems were limited to using a translated IP address-and-port pair for only one connection.
See [Limitations](/content/techdocs/en_US/pan-os/8-1/pan-os-release-notes/pan-os-8-1-release-information/limitations.html#id1787F0E08SZ) for PA-7000 Series firewalls
## PAN-99211
Fixed an issue in a high availability (HA) active/passive configuration where the hardware offload feature attempted to reinstall IPSec sessions for individual packets, which caused additional dataplane CPU loads on both the active and passive firewalls.
## PAN-99204
Fixed an issue on Panorama M-Series and virtual appliances where a qualifier configured for a custom application signature displayed the following error message: Unauthorized request.
## PAN-99161
Fixed an issue where the Captive Portal configured with RADIUS authentication failed when a username contained the "at" ( @ ) character.
## PAN-99085
Fixed an issue where firewalls did not purge files automatically as expected, which caused WildFire updates to fail.
## PAN-98978
Fixed an intermittent issue on Panorama M-Series and virtual appliances where GlobalProtect Gateway Configuration (**Network** > **GlobalProtect** > **Gateways** > **Authentication**) responded with the following message: Malformed Request.
## PAN-98683
Fixed an issue where the firewall dropped IPv6 ping packets, which caused high availability (HA) path monitoring to fail.
## PAN-98475
Fixed an issue on a firewall configured with RADIUS where the default timeout setting failed after an administrator entered credentials through the web interface.
## PAN-98375
Fixed an issue when you configured service objects (**Objects** > **Services**) a process (all_pktproc) failed and caused the dataplane to restart.
## PAN-98332
Fixed an issue where the firewall incorrectly forwarded packets to upstream devices when it had no ARP entry for the destination IP address, which resulted in traffic outages caused by source MAC addresses that did not get updated as expected.
## PAN-98263
Fixed an issue on a PA-5000 Series firewall where SNMP values for received and transmitted bytes for Aggregate Ethernet (AE) subinterfaces returned incorrect values.
## PAN-98249
Fixed an issue where General Information (Dashboard) did not display the date information for Application Version, Threat Version, and Antivirus Version line items.
## PAN-98115
Fixed an issue on Panorama M-Series and virtual appliances in a high availability (HA) active/passive configuration where after you delete a plugin from both firewalls the configuration synchronization failed.
## PAN-98110
```caveat
PAN-OS 8.0.8 and later releases only
```
Fixed an issue where administrator setting did not change when appropriate after you imported a configuration.
## PAN-97928
Fixed an issue where you could not set the Captive Portal session timeout (**Device** > **Setup** > **Session**) to 60 seconds or longer without causing a browser redirect.
## PAN-97879
Fixed an issue on Panorama management server in a high availability (HA) active/passive configuration where a Commit (**Commit** > **Commit to Panorama**) caused the firewalls to restart.
## PAN-97853
Fixed an issue Panorama M-Series and virtual appliances with the characteristic **Data Breaches** (**Objects** > **Application Filters**) enabled caused all Device Groups entries not to display.
## PAN-97698
Fixed an issue where the firewall took longer than expected to update a URL category.
## PAN-97495
Fixed an issue on a PA-5000 Series firewall in a QoS configuration where the setting did not re-apply after the dataplane restarted.
## PAN-97199
A security-related fix was made to the way the Linux kernel handles exceptions associated with MOV to SS and POP to SS instructions (CVE-2018-8897).
## PAN-96877
Fixed an issue where license keys with special characters caused rebooting to fail.
## PAN-96696
A security-related fix was made to prevent modification of attributes in a SAML Response packet.
## PAN-96548
Fixed an issue where the command delete report custom scope shared report-name <report name> file-name did not delete the files in the directory and displayed the following error message: Server error : unable to remove directory for <report-name>.
## PAN-96522
Fixed an intermittent issue where the firewall did not rotate error logs correctly, which caused disk space issues.
## PAN-96462
Fixed an intermittent issue where a null pointer exception caused the configuration (configd) process to stop responding.
## PAN-96440
Fixed an issue where the static route was not reinstalled if you modified the path-monitoring hold time while the timer was active.
## PAN-96391
Fixed an issue on Panorama M-Series and virtual appliances where one template is selected to display a list of templates displayed.
## PAN-96299
Fixed an issue on VM-Series firewalls where the bootstrap in GCP failed when a software image was provided, which caused GCP to time out before media availability was provided.
## PAN-96283
Fixed an issue where administrators with predefined roles and permission to save configuration changes were not able to save their changes.
## PAN-95935
Fixed an intermittent issue on a PA-7000 Series firewall where the GlobalProtect LSVPN tunnel monitoring failed during re-key, which caused satellites to disconnect.
## PAN-95819
Fixed an issue where a firewall did not apply the configured NAT policy during a predicted RTSP session.
## PAN-95613
Fixed an issue where Commits failed when custom role-based administrators made changes to Managed Collectors (**Panorama**).
## PAN-95454
Fixed an intermittent issue on a VM-Series firewall in a VMware NSX environment where the firewall stopped passing traffic.
## PAN-95131
Fixed an issue where administrators with Device Group and Template access were not able to modify the QoS interface (**Network** > **QoS**).
## PAN-95024
Fixed an issue on a Panorama M-Series and virtual appliances where firewalls redeployed to a NSX environment, the Device State (**Panorama** > **Managed Devices** > **Summary**) displayed a Deactivated status due to the firewalls being deployed with previously assigned authorization codes.
Firewall gets the same serial number after getting redeployed in NSX environment where Panorama still think that newly deployed firewalls are de-activated because of it has a serial number used in the past.
## PAN-94532
Fixed an issue where a memory leak caused an out-of-memory (OOM) error.
## PAN-93456
Fixed an intermittent issue where VPN tunnels terminated due to IKE manager failures.
## PAN-92694
Fixed an intermittent issue where the threat log displayed unrelated URLs in the file name column.
## PAN-87152
Fixed an issue where the show running ippool command stopped responding due to a conflict with packet processing and caused the Aggregate Ethernet (AE) interface to flap.
## PAN-86426
A security-related fix was made to SAML authentication.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 8.1.6-h2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-112148
An enhancement was made to pattern-matching capabilities to accommodate additional signatures.
@@ -0,0 +1,71 @@
---
type: Addressed
product: PAN-OS
version: 8.1.9-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-123700
A security-related fix was made to prevent a memory corruption vulnerability in PAN-OS® software ([PAN-SA-2019-0023](https://securityadvisories.paloaltonetworks.com/Home/Detail/161) / CVE-2019-1582).
## PAN-123603
A security-related fix was made to prevent a memory corruption vulnerability in PAN-OS software ([PAN-SA-2019-0021](https://securityadvisories.paloaltonetworks.com/Home/Detail/159) / CVE-2019-1580).
## PAN-123564
Fixed CVE-2019-1581, see [PAN-SA-2019-0022](https://securityadvisories.paloaltonetworks.com/Home/Detail/160) for details.
## PAN-123371
Fixed an issue where the **Wildfire Analysis Report** incorrectly displayed the following error message: You are not authorized to access thispage on the web interface.
## PAN-120194
```caveat
Virtual and M-Series Panorama appliances and Log Collectors only
```
Fixed an issue where closed Elasticsearch (ES) indices were continuing to receive and re-queue logs, which resulted in high CPU usage.
## PAN-118640
Fixed an issue where the GTP-U session did not match the correct policy, which caused the IMSI and IMEI not to display in the inner session traffic and threat logs.
## PAN-117720
```caveat
GlobalProtect™ Clientless VPN environments only
```
Fixed an issue where a process (all_pktproc) stopped responding and caused the firewall to restart unexpectedly when processing GlobalProtect Clientless VPN traffic. To leverage this fix, you must first upgrade (**Devices** > **Dynamic Updates**) to GlobalProtect Clientless VPN content release 79 or a later release.
## PAN-114642
Fixed an issue where firewall logs incorrectly included the end-user IP address in GTP message logs when you configured PAA IE with IPv4 and IPv6 dual stack in the Create Session Response message.
## PAN-114275
Fixed an issue where the firewall dropped GTPv1 DELETE PDP response packets that had a termination endpoint ID (TEID) value of 0.
## PAN-105412
Fixed an issue where forward error correction (FEC) was disabled by default for AOC modules, which caused QSFP ports to flap or remain in the DOWN state. With this fix, FEC is enabled by default for AOC modules.
## PAN-105091
Fixed an issue on a firewall where stateful inspection failed, which caused the firewall to drop GTPv2-C Modify Bearer Request packets.
## PAN-99447
```caveat
Virtual and M-Series Panorama appliances and Log Collectors only
```
Fixed an issue where a Log Collector received logs destined for closed ES indices, which caused indices to return failure messages and, when the issue persisted for more than a few hours, caused Log Collectors to disconnect and reconnect repeatedly when attempting (and failing) to process the re-queued logs.
## PAN-98005
Fixed an issue where adding more than eight Log Collectors to a collector group caused the configuration (configd) process to stop responding.
@@ -0,0 +1,411 @@
---
type: Addressed
product: PAN-OS
version: 8.1.9
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-4995
Fixed an issue on Panorama™ M-Series and WF-500 appliances where administrators were unable to run the debug software disk-usage aggressive-cleaning enable CLI command and resulted in the following error message: Server error : Failed to execute op command.
## PAN-118949
Fixed an issue where after you changed the filter configuration in the user.src notin 'cns\proxy full profile the firewall displayed the following error message: Unknown user group cns\Proxy Full.
## PAN-118407
Fixed an issue where an internal path monitoring failure due to a buffer leak caused the firewall to reboot.
## PAN-117729
Fixed an issue where the firewall incorrectly displayed application dependency warnings (**Policies** > **Security**) after you initiated a commit.
## PAN-117149
Fixed an issue on firewalls configured with authentication policies where sessions matching an authentication policy did not generate traffic logs as defined in the security policy when sessions were redirected or denied.
## PAN-116851
Fixed an issue where users were unable to open an app in their browser after they logged in to GlobalProtect™ Clientless VPN until they closed any and all tabs associated with that app and then opened the app a second time. This issue occurred only when an administrator configured a Source User for the Clientless VPN Security policy rule (**Policies** > **Security** > **<GP-VPN-Security-policy-rule>** > **User**).
## PAN-116848
Fixed an issue where multiple device group administrators simultaneously enabled configuration locks caused a race condition.
## PAN-116828
Fixed an issue on Panorama M-Series and virtual appliances where the management server and a process (configd) used higher than expected CPU and memory when you added or deleted a larger than expected number of Security policy rules with an XML API.
## PAN-116613
Fixed an issue on a VM-Series firewall deployed in Microsoft Azure where packets dropped silently due to a kernel error.
## PAN-116579
Fixed an issue where the firewall sent truncated URLs to the Captive Portal Redirect message when HTTPS traffic sent through a proxy server was subjected to decryption.
## PAN-116069
```caveat
PA-200 firewalls only
```
Fixed an issue where the report generation default configuration caused an out-of-memory condition.
## PAN-116022
Fixed an issue where the NSX Manager passed a blank string to Panorama, which caused a null entry into the configuration and commits to fail.
## PAN-115526
Fixed an issue where a dataplane process (all_pktproc) stops responding due to a packet buffer protection feature.
## PAN-115494
Fixed an issue where the "/opt/pancfg/" partition became full due to a configuration preview operation not responding.
## PAN-115450
Fixed a rare issue where a race condition occurred between daemons during a tunnel re-key, which caused BGP sessions to drop from Large Scale VPN tunnels. To leverage this fix, you must run the debug rasmgr delay-nh-update CLI command.
## PAN-115415
Fixed an issue where a session created from a predict session went into DISCARD state.
## PAN-115379
Fixed an issue where you were unable to create a custom log forwarding profile when you configured a filter with the "in" and "not in" configurations (**Objects** > **Log Forwarding** > **Add** > **Add** > **Filter** > **Filter Builder**) and resulted in the following error message: Invalid filter <Log Forwarding profile name> match-list -> <match list profile-name> -> filter is invalid.
## PAN-115339
Fixed a rare issue where a commit caused the firewall to stop responding when you enabled flow debug and configured a NAT policy.
## PAN-114743
Fixed an issue on Panorama M-Series and virtual appliances where, after you upgraded the firewall to PAN-OS® 8.1, commits failed when Panorama is configured to manage shared gateway objects for managed firewalls.
## PAN-114607
Fixed an issue where all the log collectors did not get queued when you configured more than 32 collector groups.
## PAN-114548
Fixed an issue where the firewall discarded external dynamic lists after the list was downloaded and a server authentication attempt failure occurred.
## PAN-114437
Fixed an issue on Panorama M-Series and virtual appliances where, after you upgraded the firewall from PAN-OS 8.0.8 to PAN-OS 8.1.4, commits took longer than expected when you configured the Device Group with large group hierarchies.
## PAN-114434
Fixed an issue where the firewall created incorrect predict sessions, which caused flow sessions to fail for applications.
## PAN-113971
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where the High Speed Chasis Interconnect (HSCI) link flapped after you rebooted the firewall.
## PAN-113795
Fixed an issue on a firewall configured with GlobalProtect Clientless VPN where a process (all_pkts) stopped responding, which caused the dataplane to restart.
## PAN-113775
Fixed an issue where the firewall dropped UpdatePDPContext response packets and displayed the following GTP log event: 122113.
## PAN-113631
A security-related fix was made to address a use-after-free (UAF) vulnerability in the Linux kernel ([PAN-SA-2019-0017](https://securityadvisories.paloaltonetworks.com/Home/Detail/155) / CVE-2019-8912).
## PAN-113619
Fixed an issue where the GlobalProtect gateway did not assign an IP address when the local IP address was a supernet of the GlobalProtect pool.
## PAN-113614
Fixed an issue with a memory leak on Panorama appliances associated with commits that eventually caused an unexpected restart of the configuration (configd) process.
## PAN-113340
```caveat
PA-200 firewalls only
```
Fixed an issue where the management plane (MP) memory was lower than expected, which caused the MP to restart.
## PAN-113189
A security-related fix was made to correct log file string-conversion errors that caused parsing issues, which caused the User-ID (useridd) process to stop running.
## PAN-113046
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where a process (brdagent) stopped responding, which caused the management plane to stop responding.
## PAN-112674
Fixed an issue where an escape ( \ ) character was added to HTTP logs when a log contained a comma.
## PAN-112577
Fixed an issue on a VM-Series firewall in a high availability (HA) active/passive configuration where the HA1 port flapped and caused a split-brain condition.
## PAN-112446
Fixed an issue where a predefined report (blocked credential post) generated reports using the incorrect query builder (flags has credential-builder), which caused the report to incorrectly display logs for alerts.
## PAN-112319
Fixed an issue where a race condition caused a process (mgmtsrvr) to restart with an error message: Connecting to management server failed.
## PAN-112274
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) stopped responding when a role-based user with privacy settings disabled, viewed a scheduled report that required data anonymization.
## PAN-112167
Fixed an issue where IPv4 BGP routes were missing from the routing table and FIB after a failover event.
## PAN-111976
Fixed an issue where you were unable to generate user activity reports when the username included the colon ( : ), ampersand ( & ), and single parenthesis ( ' ) characters.
## PAN-111930
```caveat
PA-3200 Series firewall only
```
Fixed an issue on a firewall in an HA active/active configuration where packets looped due to a higher than expected CPU rate.
## PAN-111708
```caveat
PA-3200 Series firewalls only
```
Fixed a rare software issue that caused the dataplane to restart unexpectedly. To leverage this fix, you must run the debug dataplane set pow no-desched yes CLI command (increases CPU utilization).
## PAN-111553
Fixed an issue on the Panorama management server where the **Include Device and Network Templates** setting (**Commit** > **Push to Devices** > **Edit Selections** or **Commit** > **Commit and Push** > **Edit Selections**) was disabled by default and caused your push attempts to fail. With this fix, your push will Include Device and Network Templates by default.
## PAN-111540
Fixed an issue on PA-5200 Series firewalls where the dataplane stopped responding when the session table was full.
## PAN-111468
Fixed an issue where you were unable to save host information profile (HIP) reports due to a folder permission error.
## PAN-111308
Fixed an issue in Panorama where you were able to push and commit the log forwarding configuration to firewalls that did not support it.
## PAN-111286
Fixed an issue where you were unable to generate a custom report (**Monitor** > **Manage Custom Report** > **<device-name>** > **Report Setting**).
## PAN-111084
Fixed an issue where an out-of-memory condition caused all IPSec tunnels (which includes IKEv1, IKEv2, and NAT-T) to stop responding.
## PAN-110962
Fixed an issue where a process (all_pktproc) stopped responding when SSH decryption was enabled, which caused the dataplane to restart.
## PAN-110638
Fixed an issue where you were unable to establish a GlobalProtect connection on IPv6 and displayed the following error message: Packet too big due to the firewall MTU value set lower than normal on the neighboring firewall.
## PAN-110548
Fixed an intermittent issue where heartbeats failed on the management plane (MP), which caused the dataplane to stop responding and displayed the following error message: Dataplane is down: controlplane exit failure.
## PAN-110168
Fixed an issue where the firewall and Panorama web interface did not present HSTS headers to your web browser.
## PAN-109926
Fixed an issue where the firewall dropped HTTPS connections to GlobalProtect and did not send an HTTPS redirect, which caused the web browser to timeout.
## PAN-109853
Fixed an issue where a log collector settings preference list without an IPv4 address defined, configured an unknown entry and caused connections between log collectors to intermittently bounce.
## PAN-109746
Fixed an issue on Panorama M-Series and virtual appliances where the Device Group Syslog server profile template allowed a space between the IP address and URL, which caused pushes to firewalls to fail.
## PAN-109701
Fixed an issue on Panorama M-Series and virtual appliances where the Task Manager web interface did not sort the list of firewalls by name.
## PAN-109672
Fixed an issue on a VM-Series firewall in an HA active/passive configuration where the passive firewall received buffered packets while in an idle state when the data plane development kit (DPDK) was enabled.
## PAN-109663
Fixed an intermittent issue where the firewall dropped packets when the policy rule was set to allow during a commit or high availability (HA) sync.
## PAN-109551
Fixed an issue where group-based policy match stopped responding after a process (useridd) restarted.
## PAN-109186
Fixed an issue where the dataplane stopped responding and caused a failover event.
## PAN-109024
Fixed an issue where, after you upgrade the firewall from PAN-OS 8.0 to PAN-OS 8.1, firewalls configured with the User-ID™ agent and group mapping incorrectly mapped users to groups.
## PAN-107677
Fixed an issue on GlobalProtect where Security Assertion Markup Language (SAML) authentication failed when you used a macOS operating system.
## PAN-107143
Fixed an issue on Panorama M-Series and virtual appliances where a partial commit to the running configuration was successful but did not get applied to the configuration when you added a new address object to an existing address group.
## PAN-107117
Fixed an issue where device administrators were unable to manually upload signature files (**Device** > **Dynamic Updates**) and the firewall displayed the following error message: You need superuser privileges to do that.
## PAN-106914
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where HA1 and HA2 links stopped passing packets, which caused a split-brain condition after an automatic configuration sync.
## PAN-106543
Fixed an issue on a firewall in an HA active/active configuration where the show vpn ipsec-sa CLI command incorrectly returned an error message: Server error: An error occurred. See dagger.log for information. when you ran the command on the active secondary firewall.
## PAN-106141
Fixed an issue where a firewall was unable to establish an SSH session to a private cloud if you used the M-500 appliance interface configuration ethernet1/1 port.
## PAN-106019
Fixed an issue where a process (routed) stopped responding when an incomplete command ran in the XML API.
## PAN-105737
```caveat
PAN-OS 8.1.7 & 8.1.8 only
```
Fixed an issue where AUX ports remained in Down state after you upgraded to PAN-OS 8.1.7.
## PAN-104909
Fixed an issue where the firewall incorrectly forwarded traffic when you configured the ingress interface with a QoS policy and the egress interface as a tunnel.
## PAN-104515
Fixed an issue where the Panorama web interface took longer than expected to update the Managed Collectors (**Panorama** > **Managed Collectors**) status.
## PAN-104144
Fixed an intermittent issue where the management plane (MP) CPU on Panorama and the manged firewall experience higher than expected usage due to the redistribution of User-ID™ and when more than one user was mapped to a single IP address.
## PAN-103847
Fixed a memory buffer allocation issue that caused the Session Initiation Protocol (SIP) traffic NAT to stop responding.
## PAN-103656
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to export threat pcaps generated from Prisma™ Access and the firewall displayed the following error message: File not found.
## PAN-101598
```caveat
Japanese language only
```
Fixed an issue where the **Interface Mgmt** (**Network** > **Network Profiles** > **Interface Mgmt**) and **Management Interface Settings** (**Device** > **Setup** > **Interfaces** > **Management**) web interfaces incorrectly displayed Telnet as Temperature.
## PAN-101215
Fixed an issue where you were unable to connect to a syslog server over SSL due to a certificate validation error.
## PAN-100773
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) port on a 20GQ NPC card unexpectedly entered low power mode and did not link up.
## PAN-99958
Fixed an issue where the dataplane did not receive enough keep-alive packets as expected, which caused the Syslog server connection to age-out.
## PAN-99134
Fixed an issue where temporary files generated during preview changes did not get cleared, which caused disk space issues.
## PAN-99016
A security-related fix was made to address the LazyFP state restore vulnerability ([PAN-SA-2019-0017](https://securityadvisories.paloaltonetworks.com/Home/Detail/155) / CVE-2018-3665).
## PAN-96827
Fixed an issue where BGP command output formats did not display consistently across different PAN-OS releases.
## PAN-96790
Fixed an issue where the FTP data connection was incorrectly matched to the predict session for IPv6 addresses.
## PAN-96707
```caveat
PA-5200 Series firewalls only
```
Fixed an intermittent issue where CRC errors caused traffic issues.
## PAN-96371
Fixed an issue where you were unable to connect to GlobalProtect when a certificate did not have a common name.
## PAN-95534
Fixed an issue where the firewall could not send syslogs to the syslog server.
## PAN-95072
Fixed a log forwarding filter issue where the firewall incorrectly sent logs for policies that were not configured with log forwarding to the syslog server.
## PAN-94279
Fixed an issue where a commit with an authentication sequence configured was pushed from Panorama to a firewall and caused the firewall's management server to stop responding.
## PAN-94059
Fixed an issue where the firewall did not send a complete certificate chain when you configure the Windows User-ID Agent as a Syslog Listener.
## PAN-91442
Fixed an issue where an external dynamic list with an invalid IPv6 address range caused commits to fail.
## PAN-89820
Fixed an intermittent issue where the Data Filtering (**Monitor** > **Data Filtering**) and Threat Log (**Monitor** > **Threat**) did not display file names when you transferred multiple files into a single session.
## PAN-88987
Fixed an issue on the PA-5220 firewall with Dynamic IP and Port (DIPP) NAT where the number of translated IP addresses could not exceed 3,000 or it caused commits to fail.
## PAN-88487
Fixed an issue where the firewall stopped enforcing policy after you manually refreshed an External Dynamic List (EDL) that had an invalid IP address or that resided on an unreachable web server.
+28 -1
View File
@@ -475,7 +475,34 @@
},
"8": {
"8.1": {
"addressed": [],
"addressed": [
"8.1.0_2026-03-16.md",
"8.1.1_2026-03-16.md",
"8.1.2_2026-03-16.md",
"8.1.3_2026-03-16.md",
"8.1.4_2026-03-16.md",
"8.1.5_2026-03-16.md",
"8.1.6-h2_2026-03-16.md",
"8.1.9_2026-03-16.md",
"8.1.9-h4_2026-03-16.md",
"8.1.10_2026-03-16.md",
"8.1.12_2026-03-16.md",
"8.1.13_2026-03-16.md",
"8.1.14-h2_2026-03-16.md",
"8.1.15_2026-03-16.md",
"8.1.15-h3_2026-03-16.md",
"8.1.17_2026-03-16.md",
"8.1.19_2026-03-16.md",
"8.1.20_2026-03-16.md",
"8.1.21_2026-03-16.md",
"8.1.21-h3_2026-03-16.md",
"8.1.23-h1_2026-03-16.md",
"8.1.25_2026-03-16.md",
"8.1.25-h1_2026-03-16.md",
"8.1.25-h3_2026-03-16.md",
"8.1.25.2_2026-03-16.md",
"8.1.26-h1_2026-03-16.md"
],
"known": []
}
}