Add 10.1 issue data

This commit is contained in:
2026-03-20 15:44:45 -05:00
parent cbdb716299
commit 81ab70ba0f
46 changed files with 12607 additions and 2 deletions
@@ -0,0 +1,103 @@
---
type: Addressed
product: PAN-OS
version: 10.1.10-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-223317
Fixed an issue where SSL traffic failed with the error message: Error: General TLS protocol error.
## PAN-219659
Fixed an issue where root partition frequently filled up and the following error message was displayed: Disk usage for / exceeds limit, xx percent in use, cleaning filesystem.
## PAN-218947
Fixed an issue where logs were not displayed in Elasticsearch under ingestion load.
## PAN-218335
Fixed an issue with hardware destination MAC filtering on the Log Processing Card (LPC) that caused the logging card interface to be susceptible to unicast flooding.
## PAN-218001
```caveat
PA-400 Series firewalls only
```
Fixed an issue where shutdown commands rebooted the system instead of correctly triggering a shutdown.
## PAN-217681
Fixed an issue caused by out of order TCP segments where the FIN flag and TCP data was truncated in a packet, which resulted in retransmission failure.
## PAN-217477
Fixed an issue where the drop counter was incremented incorrectly. Drop counter calculations did not account for failures to send out logs from logrcvr/logd to syslog-ng.
## PAN-217169
Fixed an issue where the logrcvr stopped forwarding logs to the syslog server after a restart or crash.
## PAN-216984
Fixed an issue where internal path monitoring failed due to the sysdagent not responding.
## PAN-215911
Fixed an issue that resulted in a race condition, which caused the configd process to stop responding.
## PAN-215808
Fixed an issue where, after upgrading to PAN-OS 10.1, the log forwarding rate towards the syslog server was reduced. With this fix, the overall log-forwarding rate has also been improved.
## PAN-215315
Fixed an issue where the dataplane stopped responding due to ager and inline packet processing occurring concurrently on different cores for the same session.
## PAN-214990
Fixed an issue where firewall copper ports flapped intermittently when device telemetry was enabled.
## PAN-214815
Fixed an issue where SNMP queries were not replied to due to an internal process timeout.
## PAN-214187
Fixed an issue where superreaders were able to execute the request restart system CLI command.
## PAN-214026
Fixed an issue where, when using an ECMP weighted-round-robin algorithm, traffic was not redistributed among the links proportionally as expected from the configuration.
## PAN-212877
Fixed an issue where a race condition caused log flooding, which caused the firewall to go into an unresponsive state.
## PAN-211887
Fixed an issue on Panorama that caused recently committed changes to not be displayed when previewing the changes to push to device groups.
## PAN-210740
Fixed a memory leak issue related to the slotd process.
## PAN-196116
A new CLI command debug log-receiver param-tuning syslog-threads to increase the number of processing threads for syslog forwarding up to 16 was added to address an issue where the syslog forwarding queue depth approached its limit and the drop count increased.
## PAN-186579
Fixed an issue where, after a hardware failure, the system log did not include information about the failure.
## PAN-181724
Fixed an issue where the Panorama or firewall page remained open after the session expired and you were unable to perform additional actions.
## PAN-172853
Fixed an issue where Panorama appliances running a PAN-OS 10.0 release did not push the Security policy options **no-hip** and **quarantine** to firewalls running PAN-OS 9.1.
@@ -0,0 +1,75 @@
---
type: Addressed
product: PAN-OS
version: 10.1.10-h2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-225169
Added a CLI command to view Strata Logging Service queue usage.
## PAN-223501
Fixed an issue where diagnostic information for the dataplane in the dp-monitor.log file was not complete.
## PAN-222712
```caveat
PA-5450 firewalls only
```
Fixed a low frequency DPC restart issue.
## PAN-221984
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where an interface went down after a hotplug event and was only recoverable by restarting the firewall.
## PAN-219508
```caveat
VM-Series, PA-400 Series, PA-1400, PA-3400, and PA-5400 Series firewalls only
```
Fixed an issue where Bidirectional Forwarding Detection (BFD) packets experienced a delay in processing, which caused the BFD connection to flap.
## PAN-215436
Fixed an issue with the web interface where the latest logs took longer than expected to display under **Monitor**.
## PAN-215317
Fixed an issue where the dataplane stopped responding unexpectedly with the error message comm exited with signal of 10.
## PAN-210875
Fixed an issue where the pan_task process stopped responding due to software packet buffer 3 trailer corruption, which caused the firewall to restart.
## PAN-195439
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where the dataplane interface status went down after a hotplug event triggered by Azure infrastructure.
## PAN-184630
Fixed an issue where TLS clients, such as those using OpenSSL 3.0, enforced the TLS renegotiation extension (RFC 5746).
## PAN-180082
Fixed an issue where errors in brdagent logs caused dataplane path monitoring failure.
## PAN-160633
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
Fixed an issue where the dataplane restarted repeatedly due to an internal path monitoring failures until a power cycle.
@@ -0,0 +1,591 @@
---
type: Addressed
product: PAN-OS
version: 10.1.10
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-217431
```caveat
PA-5400 Series firewalls with DPC (Data Processing Cards) only
```
Fixed an issue with slot 2 DPCs where URL Filtering did not work as expected after upgrading to PAN-OS 10.1.9.
## PAN-217284
Fixed an intermittent issue where an LACP flap occurred when the LACP transmission rate was set to **Fast**.
## PAN-216996
Fixed an issue where, after upgrading Panorama to PAN-OS 10.1.9, multiple User-ID alerts were generated every 10 minutes.
## PAN-216710
Fixed an issue with firewalls in active/active HA configurations where GlobalProtect disconnected when the original suspected active-primary firewall became active-secondary.
## PAN-216656
Fixed an issue where the firewall was unable to fully process the user list from a child group when the child group contained more than 1,500 users.
## PAN-216366
Fixed an issue where, when custom signatures used a certain syntax, false positives were generated on devices on a PAN-OS 10.0 release.
## PAN-215503
Fixed a memory related issue where the MEMORY_POOL address was mapped incorrectly
## PAN-215125
Fixed an issue where false negatives occurred for some script samples.
## PAN-215023
```caveat
PA-400 Series firewalls only
```
Fixed an issue where the firewall did not boot up successfully and an Amber LED light was shown.
## PAN-214624
Fixed an issue where the logrcvr process stopped responding.
## PAN-213463
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where unplugging a PAN-SFP-CG transceiver from an interface with its link speed setting set to 1000 caused the firewall to incorrectly read that interface as up.
## PAN-212848
Fixed an issue where attempting to change the disk-usage cleanup threshold to 90 resulted in the error message Server error : op command for client dagger timed out as client is not available.
## PAN-212530
Fixed an issue on log collectors where the root partition reached 100% utilization.
## PAN-211997
Fixed an issue where large OSPF control packets were fragmented, which caused the neighborship to fail.
## PAN-211602
Fixed an issue where, when viewing a WildFire Analysis report via the web interface, the **detailed log view** was not accessible if the browser window was resized.
## PAN-211441
Fixed a memory leak issue related to SSL crypto operations that resulted in failed commits.
## PAN-211422
Fixed an issue where the show session packet-buffer-protection buffer-latency CLI command randomly displayed incorrect values.
## PAN-211242
Fixed an issue where missed heartbeats caused the Data Processing Card (DPC) and its corresponding Network Processing Card (NPC) to restart due to internal packet path monitoring failure.
## PAN-211150
Fixed an issue on Panorama where users with custom admin roles were incorrectly unable to view SSH profiles even when it was permitted in the custom role.
## PAN-210921
```caveat
Panorama appliances in Legacy Mode only
```
Fixed an issue where **Blocked Browsing Summary by Website** in the user activity report contained scrambled characters.
## PAN-210919
Fixed an issue where the Data Processing Card remained in a Starting state after a restart.
## PAN-210738
Fixed an issue where fragmented UDP packets were dropped.
## PAN-210661
Fixed an issue where firewalls disconnected from Strata Logging Service due to a missing key file after renewing the device certificate.
## PAN-210654
Fixed an issue with firewalls on active/passive HA configurations GlobalProtect where users were disconnected after HA failover.
## PAN-210563
Fixed an issue on Panorama where Security policy rules with a **Tag** target did not appear in the pre-rule list of a Dynamic Address Group that was part of the tag.
## PAN-210397
Fixed an issue on Panorama where VM-Series firewalls in HA configurations hosted on Amazon Web Services (AWS) were not displayed under **Deploy Master Key**.
## PAN-210236
Fixed an issue where the **Templates** list was not displayed under the **Location** drop-down for commit or configuration locks.
## PAN-210216
A debug command was added to address an issue with firewalls in high availability configurations.
## PAN-210158
```caveat
CN-Series firewalls only
```
Fixed an issue where the dataplane stopped responding after a container restart.
## PAN-210000
Fixed an issue where, when traffic and threat logs exceeded the threshold of 90% total allowed size, alarms were not generated for other log types.
## PAN-209872
Fixed an issue where dataplane ports responded to ICMP requests fewer than 64 bytes with nonzero padding bytes in the ICMP response.
## PAN-209696
Fixed an issue where link-local address communication for IPv6, BFD, and OSPFv3 neighbors was dropped when IP address spoofing check was enabled in a Zone Protection profile.
## PAN-209683
Fixed an issue where Panorama was unable to retrieve IP address-to-username mapping from a firewall on a PAN-OS 8.1 release.
## PAN-209617
Fixed an issue with firewalls in active/passive HA configurations where the passive firewall created an incorrect SCTP association due to the HA sync messages from the active firewall having an incorrect value.
## PAN-209501
Fixed an issue where the GlobalProtect logdb quota was not displayed in the show system logdb quota output.
## PAN-209491
Fixed an issue on the web interface where the **Session Expire Time** displayed a past date if the device time was in December.
## PAN-209375
Fixed an issue on the firewall where log filtering did not work as expected.
## PAN-209108
Fixed an issue where a Panorama in Management Only mode was unable to display logs from log collectors due to missing schema files.
## PAN-208930
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where autotagging in log forwarding did not work.
## PAN-208902
Fixed an issue where, when a client sent a TCP/FIN packet, the firewall displayed the end reason as aged-out instead of tcp-fin.
## PAN-208877
Fixed an issue where the all_task process stopped responding when freeing the HTTP/2 stream, which caused the dataplane to go down.
## PAN-208792
Fixed an issue where authentication failed when the service route for RADIUS traffic was configured as **use default** for IPv4 addresses and included the dataplane interface as the destination route.
## PAN-208526
Fixed an issue where API calls did not display tunnel info.
## PAN-208485
Fixed an issue where NAT policies were not visible on the CLI if they contained more than 32 characters.
## PAN-208438
Fixed an issue on Panorama where Security policy rules incorrectly displayed as disabled.
## PAN-208325
```caveat
PA-5400 Series, PA-3400 Series, PA-400 Series only, and PA-5450 firewalls only
```
Fixed an issue where the firewall was unable to automatically renew the device certificate.
## PAN-208316
Fixed an issue where user-group names were unable to be configured as the source user via the test security-policy-match command.
## PAN-208240
Fixed an issue where, when attempting to replace an existing certificate, importing a new certificate with the same name as the existing certificate failed due to mismatched public and private keys.
## PAN-208210
Fixed an issue where changes to the syslog server configuration were not applied without first restarting the management server.
## PAN-208201
Fixed an issue on the firewall where the modified date and time was incorrectly updated after a commit operation, PAN-OS upgrade, or reboot.
## PAN-208189
Fixed an issue when traffic failed to match and reach all destinations if a Security policy rule includes FQDN objects that resolve to two or more IP addresses.
## PAN-208187
Fixed an issue where REST API requests did not work for GlobalProtect gateway tunnels.
## PAN-208039
```caveat
PA-7000 Series firewalls with SMC-B only
```
Fixed an issue where the details of configuration changes were not included in configuration logs on the syslog server.
## PAN-207741
Fixed an issue where Large Scale VPN (LSVPN) Portal authentication failed with the error invalid http response. return error(Authentication failed; Retry authentication when the satellite connected to more than one portal.
## PAN-207663
Fixed a Clientless VPN issue where JSON stringifies caused issues with the application rewrite.
## PAN-207661
Fixed an issue with firewalls in active/active HA configurations where the virtual floating IP address configuration under a Panorama template was overridden and displayed From Template Override: undefined as a source.
## PAN-207577
Fixed an issue where **Panorama > Setup > Interfaces** was not accessible for users with custom admin roles even when the interface option was selected for the custom admin roles.
## PAN-207562
Fixed an issue where the shard count displayed by the show log-collector-es-cluster health CLI command was higher than the recommended limit. The recommended limit can be calculated with the formula 20*heap-memory*no-of-data-nodes.
## PAN-207400
Fixed an issue on Octeon based platforms where fragmented VLAN tagged packets dropped on an aggregate interface.
## PAN-206640
Fixed an issue where the ikemgr process stopped responding, which caused IPSec tunnels to go down.
## PAN-206396
Fixed an issue where HIP report flip and HIP check failed when a user was part of multiple user groups with different domains.
## PAN-206333
Fixed an issue where the **Include/Exclude IP** filter under **Data Distribution** did not work correctly.
## PAN-206268
Fixed an issue where an authentication key field, even though not supported, was enabled under the **Device** tab on Panorama.
## PAN-206221
Fixed an issue where scheduled configuration pushes with **Include Device and Network Templates** selected did not work.
## PAN-206128
```caveat
PA-7000 Series firewalls with NPCs (Network Processing Cards) only
```
Improved debugging capability for an issue where the firewall restarted due to heartbeat failures and then failed with the following error message: Power not OK.
## PAN-205995
Fixed an issue where logs from unaffected log collector groups were not displayed when a log collector was down.
## PAN-205955
Fixed an issue where RAID rebuilds occurred even with healthy disks and a clean shutdown.
## PAN-205829
Fixed an issue where logs did not display **Host-ID** details for GlobalProtect users despite having a quarantine Security policy rule. This occurred due to a missed local cache lookup.
## PAN-205804
Fixed an issue on Panorama where a WildFire scheduled update for managed devices triggered multiple UploadInstall jobs per minute.
## PAN-205513
Fixed an issue where the stats dump file generated by Panorama for a device firewall differed from the stats dump file generated by the managed device.
## PAN-205451
Fixed an issue where the pan_com process stopped responding due to aggressive commits.
## PAN-205369
Fixed an issue where connections to Strata Logging Service were initialized from the firewall even when Strata Logging Service forwarding was disabled.
## PAN-205337
Fixed an issue in the **Run Now** section of custom reports where **Threat/Content Name** displayed in hypertext, and hovering over the text with the mouse displayed the message undefined.
## PAN-205086
Fixed an issue where DNS Security categories were able to be deleted from spyware profiles.
## PAN-204987
Fixed an issue where the firewall changed sequence numbers for reused sessions.
## PAN-204718
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where, after upgrading to PAN-OS 10.1.6-h3, a TACACS user login displayed the following error message during the first login attempt: Could not chdir to home directory /opt/pancfg/home/user: Permission denied.
## PAN-204683
Fixed an issue where logs were unable to be generated due to old logs not getting purged and /opt/panlogs reaching over 100% usage.
## PAN-204420
```caveat
WF-500 appliances only
```
Fixed an issue where, after an upgrade to a PAN-OS 10.1 release, SNMP traps were not sent to the SNMP server. This occurred due to SNMP trap server settings not being enabled.
## PAN-204233
Fixed an issue where, when the firewall received a 513 error from the WildFire cloud, the firewall attempted to repeatedly send the same file.
## PAN-203663
Fixed an issue where administrators were unable to change the password of a local database for users configured as a local admin user via an authentication profile.
## PAN-203655
Fixed an issue where enabling **event-specific traps** (**Device** > **Setup** > **Operations** > **Miscellaneous** > **SNMP Setup**), the new deviating device system logs included incorrect information.
## PAN-203339
Fixed an issue where services failed due to the RAID rebuild not being completed on time.
## PAN-203137
```caveat
PA-5450 firewalls only
```
Fixed an issue where HSCI ports did not come up when QSFP DAC cables were used.
## PAN-202981
Fixed an issue on Panorama where global find did not return results for existing universally unique identifiers (UUID).
## PAN-201855
Fixed an issue where, after cloning a template, a certificate with the block private key option enabled was corrupted.
## PAN-201839
Fixed an issue where GlobalProtect HIP matches failed for Mac users due to invalid characters being present in the subject alternative attributes in the certificate on the HIP report.
## PAN-201721
Fixed an issue with firewalls in HA configurations where HA setup generated the error mismatch due to device update during a content update even though the version was the same.
## PAN-201601
Fixed an issue where the all_task process stopped responding after adding customer hyperscan signatures.
## PAN-201561
Fixed an issue where LSVPN satellite authentication cookies were not synced across high availability LSVPN portals.
## PAN-201466
Fixed an issue where the system log generated on GlobalProtect satellite did not provide the reason for failures to connect to the GlobalProtect portal or gateway.
## PAN-201085
```caveat
PA-5450 firewalls only
```
Fixed an issue where inserting the NPC and DPC on slot2 created excessive logs in the bcm.log file.
## PAN-200676
Fixed an issue with firewalls in active/passive HA configurations where the user counts in the management plane were not synchronized between the active and the passive firewall.
## PAN-200356
Fixed an issue where the **Elapsed seconds** field incorrectly displayed as 0 for DHCP packets coming from the firewall.
## PAN-199687
Fixed an issue where content updates failed when using prelicensed keys during the bootstrap process.
## PAN-199557
Fixed an issue on Panorama where virtual memory usage exceeded the set limit, which caused the configd process to restart.
## PAN-198693
Fixed an issue where decrypted SSH sessions were interrupted with a decryption error.
## PAN-198453
Fixed an issue where you were unable to resize the **Description** pop-up window (**Policies > Security > Prerules**).
## PAN-198333
Fixed an issue where the SaaS PDF report incorrectly displayed the sanctioned application tag count as 1.
## PAN-198043
Fixed a rare issue where a BuildXmlCache job failed on the firewall.
## PAN-197388
Fixed an issue where, when the firewall forwarded Threat logs via email, the email client truncated the sender and recipient email addresses when they were put between angle brackets (<, >).
## PAN-197115
Fixed an issue where, when the total number of in-used HIP Profiles was greater than 32, traffic from the GlobalProtect Agent did not hit the expected Security policy rule configured with the HIP Profile even though a HIP Match log was generated.
## PAN-196597
Fixed an issue where the dnsproxyd process stopped responding due to corruption.
## PAN-196417
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where firewalls experienced slow SNMP responses, which caused the SNMP server to time out before polling completion.
## PAN-196345
Fixed an issue where scheduled dynamic content updates failed to be retrieved by managed firewalls from Panorama when connectivity was slow.
## PAN-196003
Fixed an issue where the **Adjust Columns** options for Panorama Traffic logs did not correctly autoadjust the columns.
## PAN-195251
Fixed an issue where IPSec tunnel re-keying generated the critical log message tunnel-status-up.
## PAN-194805
Fixed an issue where scheduled configuration backups to the SCP server failed with the error message No ECDSA host key is known.
## PAN-193710
Fixed an issue where running the show interface CLI command caused the pan_comm process to stop responding during a configuration change.
## PAN-193521
Fixed an issue where **Panorama > Device > Deployment > Software** did not display software after running **check now** for managed devices.
## PAN-192739
Fixed an issue where the error message Machine Learning found virus was displayed in threat CSV logs as **Threat ID/Name** when WildFire Inline ML detected malware.
## PAN-192681
Fixed an issue where HIP database storage on the firewall reached full capacity due to the firewall not purging older HIP reports.
## PAN-192417
Fixed an issue where botnet reports were not generated on the firewall.
## PAN-190903
Fixed an issue where MAC addresses in threat capture were swapped between the source MAC and destination MAC addresses.
## PAN-189442
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to reboot.
## PAN-189395
```caveat
PA-400 Series firewalls only
```
Fixed an issue where running a PAN-OS 10.2 release caused dataplane processes to restart unexpectedly.
## PAN-189441
Fixed an issue where the pan_comm process repeatedly restarted, which caused commits to fail.
## PAN-189423
Fixed an issue where exporting correlation logs generated an empty file.
## PAN-189196
Fixed an issue on the firewall where the DHCP server did not send DHCP NAK packets correctly when **Served Addresses** were configured.
## PAN-188403
Fixed an issue on the web interface where the interzone-default rule hit count was not displayed.
## PAN-187253
```caveat
PA-400 Series firewalls only
```
Fixed an issue where the *all_task* process stopped repsonding.
## PAN-186956
Fixed an issue where SD-WAN DIA VIF did not become active if default gateways for the member interface did not respond to pings.
## PAN-186412
Fixed an issue where invalid packet-ptr was seen in work entries.
## PAN-186182
Fixed an issue where software buffer 3 was depleted when URL proxy was enabled and SSL sessions were decrypted to inject the block page. This issue occurred when an HTTP/2 block page was displayed for a large POST request.
## PAN-185770
Fixed an issue where the firewall displayed the error message Malformed Request when an email address included an ampersand ( & ) when configuring an Email server profile.
## PAN-182689
Fixed an issue where a signature from a previous WildFire package triggered malware detection even though the signature was no longer present in the current WildFire package.
## PAN-180655
Fixed an issue where FTP connections failed when SSL Inbound Inspection was enabled and a Security Profile was attached to the FTP connection allow policy rule.
## PAN-172977
Fixed an issue where session offloading did not occur on a tap interface under a high packet load.
## PAN-172806
Fixed an issue that the logrcvr process crashes during the firewall reboots.
## PAN-170414
Fixed an issue related to an OOM condition in the dataplane, which was caused by multiple panio commands using extra memory.
## PAN-168102
Fixed an issue where the API format to check heap usage of a node showed a JSON error.
@@ -0,0 +1,51 @@
---
type: Addressed
product: PAN-OS
version: 10.1.11-h10
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-272809
A fix was made to address [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
## PAN-260796
Fixed an issue where servers were not accessible through an active SSL GlobalProtect VPN tunnel until a new connection was established or the session was cleared on the firewall.
## PAN-254704
```caveat
LSVPN Portal firewalls in active/passive HA configurations only
```
Fixed an issue where the satellite cookie key did not sync between LSVPN portal high availability (HA) firewalls, which resulted in re-authentication of satellites with the portal during an HA failover.
## PAN-248748
Fixed an issue that caused the dataplane to stop responding when running a packet diagnostic with Jumbo frames enabled.
## PAN-242561
Fixed an issue where GlobalProtect tunnels disconnected shortly after being established when SSL was used as the transfer protocol.
## PAN-239952
```caveat
Firewalls in active/passive HA configurations only
```
Fixed an issue where HA sync messages from the active firewall took longer than expected to reach the passive firewall.
## PAN-225969
Fixed an issue where some traffic was not correctly identified for data filtering.
## PAN-217147
Fixed an issue where commits took longer than expected when a large number of Security policy rules were configured.
## PAN-210260
Fixed an issue on firewalls in HA configurations where the peer satellite firewall was able to connect to the GlobalProtect portal without username and password authentication.
@@ -0,0 +1,83 @@
---
type: Addressed
product: PAN-OS
version: 10.1.11-h5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-242784
Fixed an issue where DNS resolution failed on platforms that obtained DNS server IP addresses from DHCP.
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-235741
Fixed an issue where DNS resolution failed for firewall and Panorama plugins.
## PAN-235585
Fixed an issue where, when custom signatures and predefined signatures shared the same literal pattern part, the custom signature caused an incorrect calculation for the length of the predefined signature, which resulted in App-ID not detected correctly.
## PAN-234929
Fixed an issue where tabs in the **ACC** such as **Network Activity** **Threat Activity** and **Blocked Activity** did not display data when you applied a **Time** filter of **Last 15 Minutes**, **Last Hour**, **Last 6 Hours**, or **Last 12 Hours**, and the data that was displayed with the **Last 24 Hours** filter was not accurate. Reports that were run against summary logs also did not display accurate results.
## PAN-234238
Fixed an issue where a Security policy that referenced more than 30 HIP profiles caused buffer overflow, which caused other Security policies with HIP profiles to misidentified users and traffic was denied.
## PAN-232132
Fixed an issue where DNS response packets were malformed when an Anti-Spyware Security Profile was enabled.
## PAN-231552
Fixed an issue where traffic returning from a third-party Security chain was dropped.
## PAN-228877
```caveat
PA-5200 Series, PA-5400 Series, and PA-7000 Series only
```
Fixed an issue with out-of-memory (OOM) conditions which caused slot restarts due to pan_cmd consuming more than 300MB.
## PAN-227539
Fixed an issue where excess WIF process memory use caused processes to restart due to OOM conditions.
## PAN-226792
Fixed an issue where the logrcvr process stored older content versions in the shared memory even when newer content updates were installed.
## PAN-224954
Fixed an issue where, after upgrading and rebooting a Panorama appliance in Panorama or Log Collector mode, managed firewalls continuously disconnected.
## PAN-222002
Fixed an issue where content updates failed with the error message Unable to get key pancontent-8.0.pass from cryptod. Error -9.
## PAN-221881
Fixed an issue where log ingestion to Panorama failed, which resulted in missing logs under the **Monitor** tab.
## PAN-220790
Fixed an issue where the reportd process stopped responding, which caused Panorama to restart.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
## PAN-208400
Fixed an issue where pushing dynamic objects to the firewall did not send all Panorama objects that matched the dynamic object filter when **Share Unused Address and Service Objects with Device** was selected on Panorama.
@@ -0,0 +1,31 @@
---
type: Addressed
product: PAN-OS
version: 10.1.12-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-272809
A fix was made to address [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
## PAN-242561
Fixed an issue where GlobalProtect tunnels disconnected shortly after being established when SSL was used as the transfer protocol.
## PAN-241018
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed a Dataplane Development Kit (DPDK) issue where interfaces remained in a link-down stage after an Azure hot plug event.
## PAN-238949
Fixed a memory corruption issue where multiple processes stopped responding.
## PAN-205482
Fixed an issue related to the configd process where Panorama displayed the error **Server not responding** when editing policies.
@@ -0,0 +1,43 @@
---
type: Addressed
product: PAN-OS
version: 10.1.13-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-248651
Fixed a GlobalProtect issue that prevented the firewall from sending authentication cookies.
## PAN-248105
Fixed an issue where the GlobalProtect SSL VPN tunnel immediately disconnected due to a keep-alive timeout.
## PAN-246960
Fixed an issue where firewalls failed to fetch content updates from the Wildfire Private Cloud due to an **Unsupported protocol** error.
## PAN-246215
Fixed an issue where the sleep time for a suspended pan_task process caused configuration and policy updates to be blocked.
## PAN-243463
Fixed an issue where high Enhanced Application Log traffic used excess system resources and caused processes to not work.
## PAN-239354
Fixed an issue where DNS resolution was delayed when an Antispyware policy rule was applied to both client to firewall and firewall to internal DNS server legs of a connection.
## PAN-225963
Fixed an issue where the IP address-to-user mapping was not correct.
## PAN-220907
```caveat
VM-Series firewalls only
```
Fixed an issue where large packets were dropped from the dataplane to the management plane, which caused OSPF neighborship to fail.
@@ -0,0 +1,31 @@
---
type: Addressed
product: PAN-OS
version: 10.1.13-h5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-272809
A fix was made to address [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
## PAN-262340
Fixed an issue where FQDN resolution failed for address objects, and all FQDN traffic was denied by the interzone-default policy rule.
## PAN-262287
Fixed an issue where dereferencing a NULL pointer that occurred caused pan_task processes to stop responding.
## PAN-260842
A CLI command was introduced to address an issue where TCP packets were out of order.
## PAN-230755
Fixed an issue where the devsrvr process intermittently restarted when processing traffic with a Cloud App ID.
## PAN-216368
Fixed an issue where the configuration commit process on chassis based platforms did not recognize load failures on the dataplane.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h10
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-279604
Fixed an issue where scheduled SaaS application usage reports were generated incorrectly, and the login page was displayed instead of the report content.
@@ -0,0 +1,19 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h11
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-262383
Fixed an issue where the firewall was unable to decompress the HTTP2 header, which caused the session to be classified as unknown-tcp instead of web-browsing.
## PAN-232530
Fixed an issue where the useridd process ran out of memory and restarted when the number of user or user groups exceeded the threshold.
## PAN-227368
Fixed an issue where the GlobalProtect app was unable to connect to a portal or gateway and GlobalProtect Clientless VPN users were unable to access applications if authentication took more than 20 seconds.
@@ -0,0 +1,27 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h13
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-269155
Fixed an issue where an OOM condition occurred, which caused processes to stop responding.
## PAN-265434
Fixed an issue where the flow process restarted with the error message SIGABRT __GI_raise __GI_abort __libc_message malloc_printer.
## PAN-257960
Fixed an issue where ICD's virtual memory continuously increased due to an increase in unknown IP addresses, which resulted in high management plane CPU utilization.
## PAN-256867
Fixed an issue where the logrcvr process stopped responding while processing session logs for forwarding to the LFC.
## PAN-245428
Fixed an issue where FIB entries aged out and were incorrectly removed after an HA failover event.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h14
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-265549
A fix was made to address [CVE-2025-0137](https://security.paloaltonetworks.com/CVE-2025-0137).
## PAN-250162
A fix was made to address [CVE-2025-0136](https://security.paloaltonetworks.com/CVE-2025-0136).
@@ -0,0 +1,23 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h16
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-284744
A fix was made to address [CVE-2025-4229](https://security.paloaltonetworks.com/CVE-2025-4229).
## PAN-255323
```caveat
PA-7050 firewalls only
```
Fixed an issue where the Network Processing Card (NPC), Data Processing Card (DPC), and Log forwarding Card (LFC) remained in a starting state after an unexpected power cycle.
## PAN-238594
Fixed an issue where the firewall rebooted when a QSFP28 cable was removed from the port while the port was passing traffic.
@@ -0,0 +1,19 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h19
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-269091
Fixed an issue where the varrcvr process stopped responding.
## PAN-258570
Fixed an issue where the firewall might reboot unexpectedly due to the varrcvr process progressively using more memory when WildFire file forwarding is handling PE files.
## PAN-238594
Fixed an issue where the firewall rebooted when a QSFP28 cable was removed from the port while the port was passing traffic.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h20
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-273694
```caveat
VM-Series firewalls with multiple NICs only
```
Fixed an issue were the queue count in the task dump displayed an incorrect number of queues for SR-IOV interfaces due to the queue mapping logic incorrectly using a non-multi-NIC function.
@@ -0,0 +1,39 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-258702
```caveat
WF-500 appliances only
```
Fixed an issue where the varrcvr process stopped responding when files were being forwarded to the WildFire cloud.
## PAN-257197
Fixed an issue where ifType and ifSpeed were not populated in asynchronous mode of SNMP operations.
## PAN-251847
Fixed an issue on log collectors where the incoming log rate was lower than expected.
## PAN-255163
```caveat
CN-Series firewalls only
```
Fixed an issue where the system database key that stored the configuration status of the dataplane pod was not updated frequently.
## PAN-248130
Fixed an issue where the **AND** operation under a Dynamic Address Group comparison did not work after upgrading the AWS plugin to 3.0.1.
## PAN-247257
Fixed an issue where the useridd process stopped responding, which caused the firewall to reboot.
@@ -0,0 +1,51 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h6
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-272809
A fix was made to address [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
## PAN-264883
```caveat
PA-7080 appliances with Log Forwarding Cards (LPCs) only
```
Fixed an issue where syslog forwarding over TCP stopped after upgrading.
## PAN-264249
Fixed an issue on the firewall where SNMP queries timed out when using SNMP.
## PAN-263287
The PAN-COMMON-MIB.my file was updated to support new object identifiers (OID) to poll interface use via SNMP with table identifiers.
## PAN-262340
Fixed an issue where FQDN resolution failed for address objects, and all FQDN traffic was denied by the interzone-default policy rule.
## PAN-259910
Fixed an issue where the firewall reported the same value over consecutive SNMP polls when asynchronous mode was enabled.
## PAN-257601
```caveat
PA-5450 firewalls only
```
Fixed an issue where Networking Cards (NC) experienced an internal link fault which caused path monitoring failure on the Dataplane Processing Card (DPC).
## PAN-241044
Fixed an issue where traffic was denied by the interzone-default policy rule when a Security policy rule with an FQDN destination was configured.
## PAN-164885
Fixed an issue on Panorama where **Commit and Push** or **Push to Devices** operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping.
@@ -0,0 +1,39 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14-h8
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-273215
Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading.
## PAN-268823
Fixed an issue where **Monitor > Log Display** did not display all logs when you applied
## PAN-268339
Fixed an issue where syslog-ng failed to start due to the syslog-ng.config file being corrupted when upgrading from PAN-OS 10.2.9-h1 to PAN-OS 10.2.11.
## PAN-264871
Fixed an issue on Panorama where the configd process stopped responding when viewing IP addresses on dynamic address groups with a large number of IP addresses.
## PAN-262330
Fixed an issue where traffic logs were not forwarded to the syslog server.
## PAN-260604
Fixed an issue where the firewall displayed inaccurate throughput utilization stats in NetFlow analyzer tools.
## PAN-260512
Fixed an issue where accessing the IP address of the device address group objects from the user interface caused the configd process to stop responding.
## PAN-259351
A fix was made to address [CVE-2024-3393](https://security.paloaltonetworks.com/CVE-2024-3393).
@@ -0,0 +1,327 @@
---
type: Addressed
product: PAN-OS
version: 10.1.14
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-253317
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where you were unable to log in to the firewall after a private data reset.
## PAN-251013
Fixed an issue on the web interface where the **Virtual Router** and **Virtual System** configurations for the template incorrectly showed as **none**.
## PAN-246420
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where the firewall rebooted unexpectedly during an upgrade.
## PAN-246155
Fixed an issue where the firewall dropped small fragmented ICMP messages with the discard-icmp-ping-zero-id counter when a Zone Protection profile was enabled.
## PAN-245157
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where the firewall restarted after an HA failover when DPDK was enabled.
## PAN-245125
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where file descriptors were not closed due to invalid configurations.
## PAN-245041
Fixed an issue where the WF-500 appliance returned an error verdict for every sample in FIPS mode.
## PAN-242027
Fixed an issue where the all-task process repeatedly restarted during memory allocation failures.
## PAN-241888
Fixed an issue where DHCP lease renewal failed due to a change in the firewall timestamp (**Device > Setup > Management**).
## PAN-241230
Fixed an issue where the SNMP get request status value for Panorama connections was incorrect.
## PAN-241018
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed a Data Plane Development Kit (DPDK) issue where interfaces remained in a link-down stage after an Azure hot plug event.
## PAN-240993
Fixed an issue where you were unable to revert a sort in task manager in the admin column.
## PAN-240786
Fixed an issue on firewalls in HA configurations where VXLAN sessions were allocated, but not installed or freed, which resulted in a constant high session table usage that was not synced between the firewalls. This resulted in a session count mismatch.
## PAN-240618
Fixed an issue where configuration commits were successful even when dynamic peer IKE gateways configured on the same interface and IP address that did not have the same IKE Crypto profile.
## PAN-240327
Fixed an issue where traffic on all branches was impacted when the SD-WAN MPLS link on one branch went down.
## PAN-240308
Fixed an issue where ElasticSearch did not work as expected when RAID-mounts were not fully ready after a reboot.
## PAN-239255
Fixed an issue where the firewall did not update the ARP cache timeout value after modifying the arp-cache-timeout setting.
## PAN-238705
```caveat
PA-400 Series firewalls only
```
Fixed an issue where HA link-monitor did not work.
## PAN-238643
Fixed an issue where a memory leak caused multiple processes to stop responding when VM Information Sources was configured.
## PAN-238621
Fixed an issue where the HA3 link status remained down when updating the HA3 interface configuration when the AE interface was up.
## PAN-238592
```caveat
PA-3410 firewalls only
```
Fixed an issue where the firewall did not boot up after upgrading due to a TPM lockout condition that persisted for over 24 hours.
## PAN-238508
Fixed an issue where the routed process created excessive logs in the log file.
## PAN-238355
Fixed an issue where, when a device group was not successfully renamed, unexpected configuration changes to the device group structure occurred.
## PAN-238249
Fixed an issue where static route path monitor packets from a multislot chassis were intercepted by the firewall performing Static NAT (SNAT).
## PAN-238183
Fixed an issue where Panorama displayed deviating device system logs for nonconnected interfaces.
## PAN-237657
Fixed an issue with 100% CPU utilization in the varrcvr process that occurred during an incremental WildFire update.
## PAN-237608
Fixed an issue where a NetFlow export truncated the source username.
## PAN-236233
Fixed an issue where SNMP reports displayed incorrect values for SSL Proxy sessions and SSL Proxy utilization.
## PAN-235840
Fixed an issue where, after a configuration push from Panorama to managed firewalls, the status displayed as **None** and the push took longer than expected.
## PAN-235557
Fixed an issue where uploads from tunnels, including GlobalProtect, were slower than expected when the inner and outer sessions were on different dataplanes.
## PAN-235531
Fixed an issue where GlobalProtect logs displayed incorrect vsys numbers on Panorama.
## PAN-235475
Fixed an issue where firewall sinkhole functionality was disrupted when a domain entry in an external dynamic list started with a period (.) character.
## PAN-235168
Fixed an issue where disk space became full even after clearing old logs and content images.
## PAN-234596
Fixed an issue on firewalls in active/passive HA configurations where the passive firewall incorrectly became active after a reboot.
## PAN-234169
Fixed an issue where downloading files failed or was slower than expected due to malware scanning even when the session was matched to a Security policy rule with no Anti-Virus profile attached.
## PAN-233965
Fixed an issue where the tund process stopped responding, which caused push operation to managed firewalls or making changes to local firewalls to fail.
## PAN-233692
Fixed an issue on Panorama where the configd process stopped, which caused performance issues.
## PAN-233689
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where the Log Forwarding Card (LFC) disk quota usage was reported as 0 MB for all log types.
## PAN-233603
```caveat
CN-Series firewalls only
```
Fixed an issue where slot information was not correct after a slotd process restart on the management pod.
## PAN-231395
Fixed an intermittent issue where the OCSP query failed.
## PAN-231270
Fixed an issue where Panorama became unresponsive due to the useridd process not responding.
## PAN-231237
```caveat
Firewalls only in FIPS mode only
```
Fixed an issue where the firewall repeatedly displayed the error message Cipher decrypt-final failure.
## PAN-229874
Fixed an issue where the firewall was unable to form OSPFv3 adjacency when using an ESP authentication profile.
## PAN-229873
```caveat
PA-7050 firewalls only
```
Fixed an issue related to brdagent process errors.
## PAN-229832
Fixed an intermittent issue where MLAV and URL cloud connectivity were lost.
## PAN-228277
Fixed an issue where commits took longer than expected.
## PAN-224772
Fixed a high memory usage issue with the mongodb process that caused an OOM condition.
## PAN-224365
Fixed an issue where excessive network path monitoring messages were generated in the system logs.
## PAN-222500
Fixed an issue where an old configuration unexpectedly merged during a push from Panorama.
## PAN-220907
```caveat
VM-Series firewalls only
```
Fixed an issue where large packets were dropped from the dataplane to the management plane, which caused OSPF neighborship to fail.
## PAN-220767
Fixed an issue where, at the beginning of a session, out of order packets with a TCP payload were truncated with a nonzero trailer.
## PAN-220490
Fixed an issue where the commit warning **Missing pre-defined DNS security category** was incorrectly displayed.
## PAN-219113
Fixed an issue where, when a port on the NPC was configured for log forwarding, the ingress traffic on the card was sent for processing to the LPC, and the LPC card was reloaded when the ingress volume of traffic was high.
## PAN-218136
Fixed an issue where the service route setting Palo Alto Networks Services was not applied to **Threat Vault** communication.
## PAN-217307
Fixed an issue where the log-start and log-end policy rule filters did not return reliable results when set to no or yes.
## PAN-217147
Fixed an issue where commits took longer than expected when a large number of Security policy rules were configured.
## PAN-216941
```caveat
M-700 Appliances in Log Collector mode only
```
Fixed an issue where Panorama stopped processing and saving logs.
## PAN-215561
Fixed an issue where GlobalProtect authentication failed when new users were added to an existing local database group user list.
## PAN-214463
Fixed an issue where IKE re-key negotiation failed with a third-party vendor and the firewall acting as the initiator received a response with the VENDOR_ID payload and the error message unexpected critical payload (type 43).
## PAN-213918
Fixed an issue where mlav-test-pe-file.exe was not detected by WildFire Inline ML.
## PAN-212606
Fixed an issue where the static gateway IKE-SA was established based on the peer ID even though the peer IP address matched a different object.
## PAN-211575
Fixed an issue where a local commit on Panorama remained at 99% for longer than expected before completing.
## PAN-210260
Fixed an issue on firewalls in HA configurations where the peer satellite firewall was able to connect to the GlobalProtect portal without username and password authentication.
## PAN-196395
```caveat
PA-5450 firewalls only
```
Fixed an issue where the firewall accepted 12 Aggregate Ethernet interfaces, but you were unable to configure interfaces 9-12 via the web interface.
## PAN-194782
Fixed an issue on Panorama where, if you added a new local or nonlocal administrator account or an admin user to a template, authentication profiles were incorrectly referenced.
## PAN-182011
Fixed an issue where the httpd process stopped responding and generated a core after a commit.
@@ -0,0 +1,159 @@
---
type: Addressed
product: PAN-OS
version: 10.1.2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-175685
```caveat
PA-7000 Series and PA-5450 firewalls only
```
Fixed an issue where PAN-OS displayed the incorrect chassis serial number when an MPC (Management Processor Card) or SMC (Switch Management Card) was moved from one chassis to another.
## PAN-174448
Fixed an issue where Zero-Touch Provisioning (ZTP) configuration wasn't removed after disabling it, which resulted in predefined configurations to be loaded after a reboot.
## PAN-174326
A fix was made to address an OS command injection vulnerability in the PAN-OS web interface that enabled an authenticated administrator to execute arbitrary OS commands to escalate privileges ([CVE-2021-3050](https://security.paloaltonetworks.com/CVE-2021-3050)).
## PAN-174254
```caveat
VM-Series firewalls deployed in Amazon Web Services (AWS) only
```
Fixed an issue where Gateway Load Balancer (GWLB) inspection incorrectly displayed as false after a reboot.
## PAN-174244
Fixed an issue where a sudden increase in URL data approached the maximum cache capacity of the firewall.
## PAN-174049
Fixed an issue where a process (authd) used old Thermite certificate post renewals, which caused authentication failures when using the Cloud Authentication service.
## PAN-173903
Fixed an issue where clicking a hyperlink on a web page caused the web browser to download a file instead.
## PAN-172518
Fixed an issue where a race condition occurred and caused a process (useridd) to restart.
## PAN-172515
Fixed an issue where, when downgrading from PAN-OS 10.1 to an earlier version, with Cloud Authentication Service configured in an Authentication profile, the firewall did not remove the Cloud Authentication Service from the Authentication profile and displayed the authentication method as **None**, and subsequent commits failed.
## PAN-172490
Fixed an issue on firewalls in HA configuration where HA-2 links continuously flapped on HSCI interfaces after upgrading to PAN-OS 8.1.19.
## PAN-172454
Fixed an issue where, when the firewall communicated with the Cloud Identity Engine before the device certificate was installed on the firewall or Panorama, subsequent queries to the Cloud Identity Engine failed.
## PAN-172295
Fixed an issue where a HIP database cache loop caused high CPU utilization on a process (useridd) and caused IP address-to-user mapping redistribution failure.
## PAN-172276
```caveat
PA-400 Series firewalls only
```
Fixed an intermittent issue where changing the port speed from auto-negotiate to 1G caused the dataplane port to flap, which resulted in lost traffic.
## PAN-172125
Fixed an intermittent issue where processing HIP messages in the (useridd) process caused a memory leak.
## PAN-171878
Fixed an issue with SD-WAN path selection logic that caused an all_pktproc dataplane to stop responding.
## PAN-171744
Fixed an issue where no data was displayed for the Forward Error Correction (FEC) plot for SD-WAN application performance (**Panorama** > **SD-WAN** > **Monitoring**).
## PAN-171442
Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments with overlay routing and cross-zone load balancing enabled where packets were forwarded to the incorrect GWLB interface.
## PAN-171203
Fixed an issue in an HA configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
## PAN-170681
Fixed an issue where the data redistribution agent and the data redistribution client failed to connect due to the agent not sending a SSL Server hello response.
## PAN-170103
Fixed an issue where a process (ikemgr) stopped responding while making configuration changes. This issue occurred if Site-to-Site IPSec was using certification-based authentication.
## PAN-169566
Fixed an issue where configuration files were not exported using the scheduled Secure Copy (SCP).
## PAN-168903
Fixed an issue where deleting licenses on the firewall incorrectly set the GlobalProtect gateway license node to false. The firewall displayed the following error message during a GlobalProtect application connection: Could not connect to the gateway. The device or feature requires a GlobalProtect subscription license, even though the gateway firewall had a valid gateway license.
## PAN-168718
Fixed an issue where, when a client or server received partial application data, the record was partially processed by legacy code. This caused decryption to fail when a decryption profile protocol was set to a maximum of TLSv1.3.
## PAN-167115
Fixed an issue where, after upgrading to 10.0.3, admin sessions on Panorama were not logged out after the idle timeout expired.
## PAN-167099
Fixed a configuration management issue that resulted in a process (ikemgr) failing to recognize changes in subsequent commits.
## PAN-109759
Fixed an issue where the firewall did not generate a notification for the GlobalProtect client when the firewall denied unencrypted TLS sessions due to an authentication policy match.
## PAN-165225
Fixed an issue where hwpredict was enabled by default.
## PAN-161745
Fixed an issue where the time-to-live (TTL) value received from the DNS server reset to 0 on DNS secure TCP transactions when anti-spyware profiles were used, which caused DNS dynamic updates to fail.
## PAN-158958
Fixed an issue where the debug sslmgr view crl command failed when an ampersand (&) character was included in the URL for the certificate revocation list (CRL).
## PAN-157518
Fixed an issue where using tags to target a device group in a Security policy rule did not work, and the rule was displayed in all device groups (**Preview Rules**).
## PAN-157027
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
## PAN-154905
```caveat
Panorama appliances on PAN-OS 10.0 releases only
```
Fixed an issue with Security policy rule configuration where, in the **Source** and **Destination** tabs, the **Query Traffic** setting was not available for Address Groups.
## PAN-138727
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
## PAN-136961
Fixed an issue where during QoS config generation the Aggregate Ethernet (AE) subnets were incorrectly calculated cumulatively across all AEs instead of calculating just the total subnets of an AE.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 10.1.3-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-182010
Fixed an issue on Panorama where a managed firewall running a PAN-OS 10.1 version did not reconnect to Panorama. This issue occurred when a managed firewall was added to Panorama management using the device registration authentication key and also had the device certificate installed at the time of the reconnect.
@@ -0,0 +1,27 @@
---
type: Addressed
product: PAN-OS
version: 10.1.4-h6
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-231771
Fixed an issue where the firewall issued /box/getserv/ requests with PAN-OS 7.1.0 and did not take device certificates.
## PAN-227568
When a device certificate is installed, renewed, or removed, the firewall will reconnect to the WildFire cloud to use the newest certificate.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 10.1.5-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,27 @@
---
type: Addressed
product: PAN-OS
version: 10.1.5-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-231771
Fixed an issue where the firewall issued /box/getserv/ requests with PAN-OS 7.1.0 and did not take device certificates.
## PAN-227568
When a device certificate is installed, renewed, or removed, the firewall will reconnect to the WildFire cloud to use the newest certificate.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,721 @@
---
type: Addressed
product: PAN-OS
version: 10.1.5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-189769
Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments with overlay routing enabled where, when a single firewall was the backend of multiple GWLBs, packets were re-encapsulated with an incorrect source IP address.
## PAN-189665
```caveat
FIPS-CC enabled firewalls only
```
Fixed an issue where the firewall was unable to connect to log collectors after an upgrade due to missing cipher suites.
## PAN-189468
Fixed an issue where the firewall onboard packet processor used by the PAN-OS content-inspection (CTD) engine can generate high dataplane resource usage when overwhelmed by a session with an unusually high number of packets. This can result in resource-unavailable messages due to the content inspection queue filling up. Factors related to the likelihood of an occurrence include enablement of content-inspection based features that are configured in such a way that might process thousands of packets in rapid succession (such as SMB file transfers). This can cause poor performance for the affected session and other sessions using the same packet processor. PA-3000 series and VM-Series firewalls are not impacted.
## PAN-189230
```caveat
VM-Series firewalls only
```
Fixed an issue that caused the pan_task process to stop responding with floating point exception (FPE) when there was a module of 0 on the queue number.
## PAN-188883
Fixed an issue where, when pre-generated license key files were manually uploaded via the web interface, they weren't properly recognized by PAN-OS and didn't display a serial number or initiate a reboot.
## PAN-187894
```caveat
VM-Series firewalls only
```
Fixed an issue with vm_license_response.log that consumed a large portion of the root partition.
## PAN-187769
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed a Data Plane Development Kit (DPDK) issue where interfaces remained in a link-down state after an Azure hot plug event. This issue occurred due to a hot plug of Accelerated Networking interfaces on the Azure backend caused by host updates, which led to Virtual Function unregister/Register messages on the VM side.
## PAN-187438
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where HSCI interfaces didnt come up when using BiDi transceivers.
## PAN-186785
Fixed an issue where, after logging in, Panorama displayed a 500 error page after five minutes of logging for dynamic group template admin types with access to approximately 115 managed devices or 120 dynamic groups.
## PAN-186725
Fixed an issue where index creation failed when Elasticsearch attempted to create a new index with a duplicate index name.
## PAN-186646
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where traffic flow through IKE NATT IPSec S2S tunnels broke on tunnel rekey with multiple data processing cards (DPC).
## PAN-186516
Fixed an issue where log queries that included WildFire submission logs returned more slowly than expected.
## PAN-186402
```caveat
PA-440 Series firewalls only
```
Fixed an issue where the firewall's maximum tunnel limit was incorrect.
## PAN-185750
Updated an issue to eliminate failed pan_comm software issues that caused the dataplane to restart unexpectedly
## PAN-185726
Fixed an issue where the dataplane exited during IPSec encapsulation and decapsulation offload operations.
## PAN-185695
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where up to 75% traffic loss occurred on GlobalProtect tunnels with multiple DPCs.
## PAN-185359
Fixed an issue where you were unable to reference shared address objects as a BGP peer address (**Virtual Router > BGP > Peer Group > Peer Address**).
## PAN-185164
Fixed an issue where processing corrupted IoT messages caused the wificlient process to restart.
## PAN-185163
Fixed an issue where the distributord process hit the FD limit, which caused User-ID redistribution to not function properly.
## PAN-184761
Fixed an issue where Security policies were deleted on managed devices upon a successful push from Panorama to multiple device groups. This occurred when the Security policies had **device_tags** selected in the target section.
## PAN-184445
Fixed an issue where, after upgrading the Panorama, tagged address objects used in dynamic address groups were removed after a full commit and push. This issue occurred when the setting **Share Unused Address and Service Objects with Devices** was left unchecked.
## PAN-184432
Fixed an issue where the logrcvr process stopped responding due to a heartbeat failure that was caused by sysd nodes being stuck on logdb_writers for system, configuration, and alarm logs.
## PAN-184224
Fixed an issue on Panorama where you were unable to select a template variable in **Templates > Device > Log Forwarding Card > Log Forwarding Card Interface > Network > IP address location**.
## PAN-184076
Fixed an issue on the firewall web interface where logs were delayed when querying for logs.
## PAN-184047
Fixed an issue where Terminal Service agent (TS agent) connections with a certificate profile and the certificate chain on the TS agent failed. This occurred because common name validation and key usage checks were being performed in the root or intermediate certificate.
## PAN-183774
Fixed an memory leak issue in the mgmtsrvr process, which resulted in an out-of-memory (OOM) condition and high availability (HA) failover.
## PAN-183428
Fixed an issue where, when exporting or pushing a device configuration bundle from Panorama, a validation error occurred with GlobalProtect gateway inactivity logout time.
## PAN-183239
Fixed an issue where the firewall randomly disconnected from the WildFire URL cloud.
## PAN-183112
Fixed an issue where the threat log type ml-virus wasn't forwarded to Panorama or to external servers.
## PAN-182954
```caveat
PA-7000 Series firewalls with Log Processing Cards (LPC) only
```
Fixed an issue where excessive threat ID lookups caused logs to be lost.
## PAN-182903
Fixed an issue where SD-WAN failover on a hub or branch in full mesh took longer than expected.
## PAN-182732
Fixed an issue where the GlobalProtect gateway inactivity timer wasn't refreshed even though traffic was passing through the tunnel.
## PAN-182634
```caveat
PA-400 Series firewalls only
```
Fixed an issue where the firewall detected a Power Supply Unit (PSU) failure for the opposite side when disconnecting a PSU from the device. This issue occurred when redundant PSUs were connected.
## PAN-181839
Fixed an issue where Panorama Global Search reported **No Matches found** while still returning results for matching entries on large configurations.
## PAN-181802
Fixed an issue where a memory utilization condition resulted in the web interface responding more slowly than expected and management server restarting.
## PAN-181706
Fixed an issue where the logrcvr process stopped responding after upgrading to PAN-OS 10.1.
## PAN-181579
Fixed an issue with the GlobalProtect gateway where the time-to-live (TTL) limit expired faster than real-time limit. As a result, a reconnection was required before the expected lifetime expiration.
## PAN-181558
Fixed an issue where the stats dump file was not generated properly.
## PAN-181360
Fixed an issue where staggering scheduled dynamic updates from Panorama to firewalls only worked for the first scheduled group and failed for the remaining groups of the same type.
## PAN-181116
Fixed memory corruption issues in PAN-OS 10.1.3 and 10.1.4 that caused the pan_comm process to stop responding and the dataplane to restart. These issues also caused GlobalProtect tunnels to fall back to SSL instead of IPSec due to the inadvertent encapsulation of the ICMP keepalive response from the firewall.
## PAN-181039
Fixed an issue with DNS cache depletion that caused continuous DNS retries.
## PAN-180916
Fixed an issue where DNS security caused the TTL value of the pointer record (PTR) to be overwritten with a value of 30 seconds.
## PAN-180760
Fixed an issue where users were unable to SSH to the firewall and encountered the following error message: Could not chdir to home directory /opt/pancfg/home/user: Permission denied.
## PAN-180095
Fixed an issue where Panorama serial-number-based redistribution agents did not redistribute HIP reports.
## PAN-179982
Fixed an issue where an OOM condition occurred due to quarantine list redistribution.
## PAN-179976
Fixed an issue where the WildFire Inline Machine Learning (ML) did not detect mlav-test-pe-file.exe when traffic was decrypted.
## PAN-179899
Fixed an issue where updating the master key did not update the SD-WAN preshared key (PSK).
## PAN-179886
Fixed an issue where new tunnels were unable to be established for Elasticsearch due to faulty logic that prevented old tunnels to be removed when a node went down.
## PAN-179413
Fixed an issue where GRE tunnels flapped during commit jobs.
## PAN-179321
A validation error was added to inform an administrator when a policy field contained the value **any**.
## PAN-179274
Fixed an issue on high availability configurations where, after upgrading to PAN-OS 9.1.10, PAN-OS 10.0.6, or PAN-OS 10.1.0, the HA1 and HA1-Backup link stayed down. This issue occurred when the peer firewall IP address was in a different subnet.
## PAN-179260
Fixed an issue where admins and other Superusers were unable to remove a commit lock that was taken by another admin user with the format <domain/user>. As a result, deleting the commit lock failed.
## PAN-179164
Fixed an issue where a web-proxy port number was added to the destination URL when captive portal authentication was run.
## PAN-179059
Fixed an issue where you were unable to delete dynamic address groups one at a time using XML API.
## PAN-178947
Fixed an issue where the useridd process stopped responding when a NULL reference attempted to be dereferenced. This issue occurred to IP address users being added.
## PAN-178860
Fixed an issue where quarantined devices appeared in the CLI but not the web interface.
## PAN-178672
Fixed an issue where a process (useridd) stopped responding due to buffer overflow.
## PAN-178615
Fixed an issue where restarting the management server created an invalid reference in the device server, which caused subsequent commits to fail.
## PAN-177981
```caveat
PA-5450 firewalls only
```
Fixed an issue where **High Speed Log Forwarding** was enabled when attempting to view local logs.
## PAN-177956
Fixed an issue where the CLI output of show location ip <ip address> returned unknown.
## PAN-177907
Fixed an issue where, after rebooting the firewall, FQDN address objects referred in rules in a virtual system (vsys) did not resolve when the vsys used a custom DNS proxy.
## PAN-177878
Fixed an issue where a role-based admin with **Operational Requests** enabled under the XML API section was unable to set the License Deactivation API key.
## PAN-177874
Fixed an issue where a process (devsrvr) stopped responding due to an unexpected returned value.
## PAN-177626
Fixed an issue where aggressive situations caused on-chip descriptor exhaustion.
## PAN-177551
A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)).
## PAN-177363
Fixed an issue where, when system logs and configuration logs on a dedicated log detector system were forwarded to a Panorama management server in Management Only mode, the logs were not ingested and were dropped. This caused the dedicated log detector system to not be viewable on a Panorama appliance in Management Only mode.
## PAN-177351
Fixed an issue where configurations failed when downgrading from PAN-OS 10.1.1 and later versions to PAN-OS 10.0.0 using the autosaveconfig.xml file.
## PAN-177187
Fixed an issue where reports using the decryption summary database and Panorama as data sources returned no results.
## PAN-177170
Fixed an issue on Panorama where a log collector group commit deleted the proxy settings configured on dedicated log collectors.
## PAN-177072
Fixed an intermittent issue where Panorama did not show new logs from firewalls.
## PAN-177060
Fixed an issue where, when the address object in the parent device group was renamed, and the address object was overridden in the child device group and called in a Security policy, the object in the Security policy was renamed as well.
## PAN-177054
Fixed an issue where, when you disabled a NAT rule, the **Destination Translation** value **none** displayed in blue and was still able to be modified to a different value.
## PAN-176997
Fixed an issue where log collectors generated **Failed to check IoT content upgrade** system logs even when no IoT license was installed.
## PAN-176889
Fixed an issue where the log collector continuously disconnected from Panorama due to high latency and a high number of packets in Send-Q.
## PAN-176746
Fixed an intermittent issue where traffic was lost when performing a failover in an HA active/passive setup.
## PAN-176376
Fixed an issue where importing a firewall configuration to Panorama failed if **Import device's shared objects into Panorama's shared context (device group specific objects will be created if unique)** was unchecked.
## PAN-176348
Fixed an issue where scheduled email alerts were not forwarded to all recipients in the override list.
## PAN-176280
Fixed an intermittent issue on Panorama where querying logs via the web interface or API did not return results.
## PAN-176262
Fixed an issue where the firewall didn't resolve specific domain names with multiple nested Canonical Name (CNAME) records when caching was enabled.
## PAN-176116
Fixed an issue where the header did not match the correct policy when IPv6 addresses were set in XFF header.
## PAN-176032
Fixed an issue where a process (authd) process stopped responding, which caused authentication to fail.
## PAN-176030
Fixed an issue where alerts related to syslog connections were not generated in the system logs.
## PAN-175717
Fixed an issue where firewalls managed by a Panorama management server entered maintenance mode if:
- Panorama was running PAN-OS 10.2 and managed firewalls were downgraded from PAN-OS 10.2 to PAN-OS 10.1.4 or earlier PAN-OS release
- Panorama was upgraded from PAN-OS 10.1 to PAN-OS 10.2 and managed firewalls were running PAN-OS 10.1.4 or earlier PAN-OS 10.1 release.
## PAN-175716
Fixed an issue where sorting address groups by name, address, or location did not work on a device group that was part of a nested device group.
## PAN-175628
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the firewall was unable to monitor AUX1 and AUX2 interfaces through SNMP.
## PAN-175570
Fixed an issue where log forwarding profiles did not show up in the dropdown under **Zones**.
## PAN-175509
Fixed an issue where a deadlock on CONFIG_LOCK caused both the web interface and CLI commands to time out until the mgmtsrvr process was restarted.
## PAN-175403
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall did not display any logs except for system logs.
## PAN-175399
Fixed an issue where enabling Use proxy to fetch logs from Strata Logging Service caused Panorama to not show logs when queried.
## PAN-175307
Fixed an issue where Panorama commits were slower than expected and the configd process stopped responding due to a memory leak.
## PAN-175259
Fixed an issue where a Security policy configured with App-ID and set to **web-browsing** and **application-default service** allowed clear-text web-browsing on tcp/443.
## PAN-175161
Fixed an issue where changing SSL connection validation settings for system logs caused the mgmtsrvr process to stop responding.
## PAN-175141
Fixed an intermittent issue where IP address-to-username mappings were not created on a redistribution client if a logout and login message shared the same timestamp.
## PAN-174998
```caveat
M-200 and M-500 appliances only
```
Fixed a capacity issue that was caused by high operational activity and large configurations. This fix increases the virtual memory limit on the configd process to 32GB.
## PAN-174894
Fixed an issue where, when the TTL value for symmetric MAC entries weren't updated to other dataplanes and HA peers, timeouts occurred for traffic using policy-based forwarding (PBF) with symmetric returns.
## PAN-174864
Fixed an issue on the Panorama interface where **Deploying Master Key** to low-end devices resulted in a **Failed to communicate** message, even when the new master key was updated on the end device. This issue occurred because a master key deployment had insufficient time to process due to a connection timeout.
## PAN-174709
Fixed an OOM condition that occurred due to multiple parallel jobs being created by the scheduled log export feature.
## PAN-174680
Fixed an issue where, when adding new configurations, Panorama didn't display a list of suggested template variables when typing in a relevant field.
## PAN-174607
Fixed an intermittent issue where, when Security profiles were attached to a policy, files that were downloaded across TLS sessions decrypted by the firewall were malformed.
## PAN-174604
Fixed an issue where the email subject of scheduled reports was enclosed in single quotation marks.
## PAN-174564
```caveat
VM-Series firewalls on a Kernel-based Virtual Machine (KVM) running on Proxmox Hypervisor only
```
Fixed an issue where SSH traffic was identified as unknown-TCP.
## PAN-174347
Fixed an issue where sequence numbers were calculated incorrectly for traffic that was subject to Session Initiation Protocol (SIP) application-level gateway (ALG) when SIP TCP Clear Text Proxy was disabled.
## PAN-174011
Fixed an issue where Panorama failed to update shared policies during partial commits when a new device group was created but not yet committed.
## PAN-173893
Fixed a memory leak issue related to the (useridd) process that occurred when group mapping was enabled.
## PAN-173753
Fixed an issue where a bar or point on a **Network Monitor** graph had to be clicked more than once to properly redirect to the corresponding ACC report.
## PAN-173689
Fixed an issue where the dataplane restarted due to running out of memory in the policy cache.
## PAN-173545
Fixed an issue where exporting a device summary to CSV failed and displayed the following error message: Error while exporting.
## PAN-173509
Fixed an issue where Superuser administrators with read-only privileges (**Device > Administrators and Panorama > Administrators**) were unable to view the hardware ACL blocking setting and duration in the CLI using the following commands:
- show system setting hardware-acl-blocking-enable
- show system setting hardware-acl-blocking-duration
## PAN-173267
Fixed an issue where log queries on Panorama appliances returned with no output and the error message Schema file does not exist displayed in the reported process log.
## PAN-173179
Fixed an issue where the rem_addr field in Terminal Access Controller Access-Control System (TACACS+) authentication displayed the management or service route IP address of the firewall instead of the source IP address of the user.
## PAN-172837
Fixed an intermittent issue where the firewall didn't generate block URL logs for URLs even though the websites were blocked in the client device.
## PAN-172748
```caveat
VM-Series firewalls only
```
Fixed an issue where a process (all_task) stopped responding.
## PAN-172404
Fixed an issue where the semi-colon (;) was not recognized as token separator while doing regex for URL category matching even though it is mentioned in the documentation.
## PAN-172396
Fixed a memory leak issue related to the useridd process.
## PAN-172316
Fixed an issue where the internal interface flow control that caused the monitoring process to incorrectly determine the interface to be malfunctioning.
## PAN-172295
Fixed an issue where a HIP database cache loop caused high CPU utilization on a process (useridd) and caused IP address-to-user mapping redistribution failure.
## PAN-172243
Fixed an issue where NetFlow traffic triggered a packet buffer leak.
## PAN-172056
```caveat
VM-Series firewalls only
```
The logging rate limit was improved to prevent log loss.
## PAN-171869
Fixed an issue where HIP profile objects in security policies and authentication policies were still visible in the CLI even after replacing them with source HIP and destination HIP objects.
## PAN-171367
Fixed an issue in active/active HA configurations where sessions disconnected during an upgrade from a PAN-OS 9.0 release to a PAN-OS 9.1 release.
## PAN-171345
Fixed an issue where firewalls experienced high packet descriptor usage due to internal communication associated with WildFire.
## PAN-171181
Fixed an issue where the IPSec tunnel configuration didn't load when a double quotation mark was added to the comment section of the IPSec tunnel **General** tab.
## PAN-170952
Fixed script issues that caused diagnostic data to not be collected after path monitor failure.
## PAN-170595
Fixed an issue with Content and Threat Detection where traffic patterns created a bus error, which caused the all_pktproc process to stop responding and the dataplane to restart.
## PAN-170297
Fixed an issue where **ACC > Threat** activity did not include the threat name after upgrading to a PAN-OS 10.0 release.
## PAN-169917
Fixed an issue on Panorama where AUX interface IP addresses did not populate when configuring service routes.
## PAN-169796
Fixed an issue where the high availability path group destination IP address was removed after pushing a PAN-OS 10 release template from Panorama to a firewall running a PAN-OS 9 release.
## PAN-169433
Fixed an issue on Panorama where clicking **Run Now** for a custom report with 32 or more filters in the Query Builder returned the following message: No matching records.
## PAN-168921
Fixed an issue on firewalls in HA active/active configurations where traffic with complete packets showed up as incomplete and was disconnected due to a non-session owner closing the session prematurely.
## PAN-168890
A CLI command was added to address an issue where a configured proxy server for a service route was automatically applied to the email server service route.
## PAN-168662
Fixed an issue on Panorama where multiple copies of logs were displayed for a single session.
## PAN-168635
Fixed an issue on the firewall where, when attempting to change the master key, the existing master key was not validated first. As a result, all firewall keys were corrupted.
## PAN-168286
Fixed a memory leak issue in the mgmtsrvr process that was caused by failed commit all operations.
## PAN-168189
Fixed an issue where, even when there was active multicast traffic, the firewall sent Protocol Independent Multicast (PIM) prune messages.
## PAN-167858
Fixed an issue where a DNS Security inspection identified a TCP DNS request that had two requests in one segment as a malformed packet and dropped the packet.
## PAN-167259
Fixed an issue where, after manually uploading WildFire images, the dropdown did not display any available files to choose from.
## PAN-166368
Fixed an issue on Panorama where long FQDN queries did not resolve due to the character limit being 64 characters.
## PAN-165147
Fixed an issue where, when there was a high volume of traffic for sessions with **Application Block Pages** enabled, other regular packets were dropped.
## PAN-164871
```caveat
VM-Series firewalls only
```
Fixed an intermittent issue where deactivating the firewall via XML API using manual mode failed. This occurred because the size of the license token file was incorrect.
## PAN-164631
Fixed an issue where the **stats dump** report was empty.
## PAN-163831
Fixed an issue where IPv6 addresses were displayed instead of IPv4 in custom reports.
## PAN-163245
Fixed an issue where a commit-all or push to the firewall from Panorama failed with the following error message: client routed requesting last config in the middle of a commit/validate. Aborting current commit/validate.
## PAN-162047
```caveat
Firewalls in HA active/passive configurations only
```
Fixed a routing table mis-sync issue where routes were missing on the passive firewall when GRE tunnels with keepalives were configured.
## PAN-161297
Fixed an interoperability issue with other vendors when IKEv2 used SHA2-based certificate authentication.
## PAN-161111
Fixed an issue where TLS 1.3 Forward Proxy Decryption failed with a malloc failure error. This issue was caused by the server certificate being very large.
## PAN-161031
Fixed an issue where authentication via LDAP server failed in FIPS-CC mode when the LDAP server profile was configured with the root certificate chain and **Verify server certificate for SSL sessions** options enabled.
## PAN-159835
Fixed an issue where, after an upgrade, the following error message was displayed: Not enough space to load content to SHM.
## PAN-158639
Fixed an issue on Panorama where logs that were forwarded to a collector group did not appear, and the log collector displayed the following error message: es.init-status not ready in logjobq.
## PAN-158541
Fixed an OOM condition on the dataplane on FIPS-mode firewall decryption that used DHE ciphers.
## PAN-158369
Fixed an issue where applications did not work via the Clientless VPN when they were configured on a vlan interface
## PAN-156289
Fixed an issue where the default severities for Content Update errors were inaccurate.
## PAN-151692
Fixed a permission issue where a Panorama administrator was unable to download or install dynamic updates (**Panorama > Device Deployment**).
## PAN-151302
```caveat
PA-7000 Series firewalls with LFCs only
```
Fixed an issue where the logging rate for the LFC was not displayed in **Panorama > Managed Devices > Health**.
## PAN-146734
Fixed an issue where, when a Panorama-pushed configuration was referenced in a local configuration, commits failed after updating the master key on the firewall, which resulted in the following error message: Invalid candidate configuration. Master key change aborted....
## PAN-145833
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the firewall stopped recording dataplane diagnostic data in dp-monitor.log after a few hours of uptime.
## PAN-141454
Fixed an issue where the output of the CLI command show running resource-monitor ingress-backlogs displayed an incorrect total utilization value.
@@ -0,0 +1,79 @@
---
type: Addressed
product: PAN-OS
version: 10.1.6-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-194408
Fixed an issue where, when policy rules had the apps that implicitly depended on web browsing configured with the service application default, traffic did not match the rule correctly.
## PAN-194325
```caveat
PA-5450 firewalls only
```
Fixed an issue where the logging interface configuration was not correctly written to the syslog-ng configuration file.
## PAN-192880
Fixed an issue where, when the firewall was configured for jumbo frames, an internal interface was not set with the correct MTU, which caused byte frames larger than 1500 to be dropped when a DF bit was set.
## PAN-192403
```caveat
PA-5450 firewalls only
```
Fixed an issue on the web interface where, when configuring the management interface and logging interface in the same subnetwork, a commit warning was not displayed even though the configuration caused routing and connectivity issues.
## PAN-191558
Fixed an issue where, after an upgrade to PAN-OS 10.1.5, Global Find did not display all results related to a searched item.
## PAN-191257
Fixed an issue on the firewall where the useridd process stopped responding after a commit from Panorama. This occurred due to a timing issue where a HIP query from the dataplane was initiated before the process had finished initialization.
## PAN-190811
```caveat
PA-5450 firewalls only
```
Fixed an issue where logs were forwarded through the management interface instead of the configured log interface to be used for forwarding.
## PAN-190292
Fixed an issue where you could not configure a log interface as a service route (**Device** > **Setup** > **Services** > **Service Route**)
## PAN-189762
Fixed an issue where a predict session didn't match with the traffic when both source NAT and destination NAT were enabled.
## PAN-188833
Fixed an issue where shared address objects used as a source or destination in policies were cloned but not freed back after configuration commits.
## PAN-187126
Fixed an issue where enabling DPDK mode on the dataplane interfaces of a Microsoft Azure instance caused the brdagent process to stop responding.
## PAN-186075
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall rebooted after receiving large packets while in DPDK mode on Azure virtual machines running CX4 (MLx5) drivers.
## PAN-186024
Fixed an issue where URL category match did not work for External Dynamic List URLS due to a leak related to the devsrvr process.
## PAN-183166
Fixed an issue where system, configuration, and alarm logs were queued up on the logrcvr process and were not forwarded out or written to disk until an autocommit was passed.
@@ -0,0 +1,115 @@
---
type: Addressed
product: PAN-OS
version: 10.1.6-h6
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-196993
Fixed an issue where an incorrect regex key was generated to invalidate the completions cache, which caused the configd process to stop responding.
## PAN-195181
Added enhancements to improve the load on the pan_comm process during SNMP polling.
## PAN-194826
```caveat
WF-500 and WF-500-B appliances only
```
Fixed an issue where log system forwarding did not work over a TLS connection.
## PAN-194776
Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments with overlay routing enabled where intra-zone packets were re-encapsulated with the incorrect source/destination MAC address.
## PAN-194721
Fixed an issue where path monitor failure occurred, which caused slots to go down.
## PAN-194694
Fixed an issue where multiple SNMP requests being made to the firewall caused in the pan_comm process to stop responding.
## PAN-194645
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where the Data Processing Card status was incorrectly shown as **config=None**
## PAN-194601
Fixed an issue that caused the all_task process to stop responding.
## PAN-194406
Fixed an issue where the MTU from SD-WAN interfaces was recalculated after a configuration push from Panorama or a local commit, which caused traffic disruption.
## PAN-194097
Fixed an issue on firewalls in high availability (HA) active/passive configurations where _ha_d_session_msgbuf overflowed on the passive firewall during an upgrade, which caused the firewall to enter a non-functional state.
## PAN-193732
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where the firewall incorrectly handled internal transactions.
## PAN-193184
Fixed an issue where **IP-user-mapping** disappeared when login/logout events occurred at the same timestamp.
## PAN-193132
```caveat
PA-220 firewalls only
```
Fixed an issue where a commit and push from Panorama caused high dataplane CPU utilization.
## PAN-192999
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
## PAN-192758
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where files failed to upload to the Wildfire public cloud.
## PAN-192673
```caveat
PA-7050-SMC-B firewalls only
```
Fixed an issue where the LFC (log forwarding card) syslog-ng service failed to start after an upgrade.
## PAN-192551
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where the firewall incorrectly processed path monitoring packets, which caused a slot restart.
## PAN-192052
Fixed an issue where, when next hop MAC address entries weren't found on the offload processor for active traffic, update messages flooded the firewall, which caused resource contention and traffic disruption.
## PAN-182951
Fixed an issue where commits remained at 98% for an hour and then failed.
## PAN-173469
Fixed an intermittent issue where websites were blocked and categorized as not resolved.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 10.1.6-h7
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 10.1.6-h9
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-272809
A fix was made to address [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
@@ -0,0 +1,27 @@
---
type: Addressed
product: PAN-OS
version: 10.1.7-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-231771
Fixed an issue where the firewall issued /box/getserv/ requests with PAN-OS 7.1.0 and did not take device certificates.
## PAN-227568
When a device certificate is installed, renewed, or removed, the firewall will reconnect to the WildFire cloud to use the newest certificate.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,639 @@
---
type: Addressed
product: PAN-OS
version: 10.1.7
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-200771
Fixed an issue where syslog-ng was unable to start due to a design change in the syslog configuration file.
## PAN-199654
Fixed an issue where ACC reports did not work for custom RBAC users when more than 12 access domains were associated with the username.
## PAN-199311
Fixed an issue where the Log Forwarding Card (LFC) failed to forward logs to the syslog server.
## PAN-198509
Fixed an issue where commits failed due to insufficient CFG memory.
## PAN-198332
```caveat
PA-5400 Series only
```
Fixed an issue where swapping Network Processing Cards (NPCs) caused high root partition use.
## PAN-198244
Fixed an issue where using the load config partial CLI command to x-paths removed address object entries from address groups.
## PAN-197484
```caveat
PA-5400 Series firewalls
```
Fixed an issue where the firewall forwarded packets to the incorrect aggregate ethernet interface when Policy Based Forwarding (PBF) was used.
## PAN-197244
Fixed an issue on firewalls with Forward Proxy enabled where the all_pktproc process stopped responding due to missed heartbeats.
## PAN-196993
Fixed an issue where an incorrect regex key was generated to invalidate the completions cache, which caused the configd process to stop responding.
## PAN-196953
```caveat
PA-5450 firewalls only
```
Fixed an issue where jumbo frames were dropped.
## PAN-196445
Fixed an issue where restarting the NPC or the Data Processing Card (DPC) did not bring up all the network interfaces.
## PAN-196227
Fixed an issue where the logd process stopped responding, which caused Panorama to reboot into maintenance mode.
## PAN-196005
```caveat
PA-3200 Series, PA-5200 Series, and PA-5400 Series firewalls only
```
Fixed an issue where GlobalProtect IPSec tunnels disconnected at half the inactivity logout timer value.
## PAN-195707
Fixed an issue on Panorama appliances configured as log collectors where Panorama repeatedly rebooted into maintenance mode.
## PAN-195628
Fixed an issue that caused the pan_task process to miss heartbeats and stop responding.
## PAN-195625
Fixed an issue where authd frequently created SSL sessions, which resulted in an out-of-memory (OOM) condition.
## PAN-195360
Fixed an issue with firewalls in Microsoft Azure environments where BGP flapping occurred due to the firewall incorrectly treating capability from BGP peering as unsupported.
## PAN-195223
Fixed an issue where the all_pktproc process restarted when receiving a GTPv2 Modify Bearer Request packet if the Serving GPRS Support Node (SGSN) used the same key as the Serving Gateway (SGW).
## PAN-195181
Added enhancements to improve the load on the pan_comm process during SNMP polling.
## PAN-194958
Fixed an issue where using the show routing protocol bgp loc-rib-detail CLI command caused the CLI to stop responding.
## PAN-194826
```caveat
WF-500 and WF-500-B appliances only
```
Fixed an issue where log system forwarding did not work over a TLS connection.
## PAN-194776
Fixed an issue on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments with overlay routing enabled where intra-zone packets were re-encapsulated with the incorrect source/destination MAC address.
## PAN-194601
Fixed an issue that caused the all_task process to stop responding.
## PAN-194481
Fixed an issue in ESXi where the bootstrapped VM-Series firewalls with the Software Licensing Plugin had :xxx appended to their hostnames.
## PAN-194472
A CLI command was added to address an issue where packets were discarded due to the QoS queue limit being reached. This command enables you to modify the QoS queue size to accommodate more users.
## PAN-194408
Fixed an issue where, when policy rules had the apps that implicitly depended on web browsing configured with the service application default, traffic did not match the rule correctly.
## PAN-194406
Fixed an issue where the MTU from SD-WAN interfaces was recalculated after a configuration push from Panorama or a local commit, which caused traffic disruption.
## PAN-193981
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where the firewall stopped monitoring high availability (HA) failure and floating IP addresses did not get moved to the newly active firewall.
## PAN-193765
Fixed an issue where commits failed the following error displayed in the configd log: Unable to populate ids into candidate config: Error: Error populating id for sg2+DMZ to FirstAM Scanner-1.
## PAN-193763
Fixed an issue on the firewall where the dataplane CPU spiked, which caused traffic to be affected during commits or content updates.
## PAN-193707
Fixed an issue where SAML authentication failed during commits with the following error message: revocation status could not be verified (reason: ).
## PAN-193483
```caveat
VM-Series firewalls only
```
Fixed an issue where, during Layer-7 packet inspection where traffic was being inspected for threat signature and data patterns, multiple processes stopped responding.
## PAN-193392
Fixed an issue where RTP packets dropped due to conflicting duplicate flows.
## PAN-193175
Fixed an issue where PBP Drops (8507) threat logs were incorrectly logged as SCTP Init Flood (8506).
## PAN-193132
```caveat
PA-220 firewalls only
```
Fixed an issue where a commit and push from Panorama caused high dataplane CPU utilization.
## PAN-192944
Fixed an issue where the logrcvr process caused an OOM condition.
## PAN-192758
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where files failed to upload to the WildFire public cloud.
## PAN-192726
Fixed an issue where the firewall dropped TCP traffic inside IPSec tunnels.
## PAN-192725
Fixed an issue where the firewall failed to forward logs to Panorama when configured with IPv6 addressing only.
## PAN-192666
```caveat
VM-Series firewalls only
```
Fixed an issue where uploading certificates via API failed within the first 30 minutes of a bootstrap.
## PAN-192551
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where the firewall incorrectly processed path monitoring packets, which caused a slot restart.
## PAN-192404
Fixed an issue where ARP broadcasts occurring in the same time interval and network segment as HA path monitoring pings triggered an ARP cache request, which prevented the firewall from sending ICMP echo requests to the monitored destination IP address and caused an HA path monitoring failover.
## PAN-192330
```caveat
Bootstrapped VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where the firewall did not automatically receive the Strata Logging Service license.
## PAN-192089
Fixed an issue on the web interface where the IPSec tunnel did not gray out after disabling it.
## PAN-191867
Fixed an issue where CPU stalls resulted in a slot restart.
## PAN-191847
Fixed an issue where the Panorama appliance was unable to generate scheduled custom reports due to the large number of files stored in the opt/pancfg/mgmt/custom-reports directory.
## PAN-191726
Fixed an issue where an SCP export of the device state from the firewall added single quotes ( ' ) to the filename.
## PAN-191558
Fixed an issue where, after an upgrade to PAN-OS 10.1.5, Global Find did not display all results related to a searched item.
## PAN-191381
Fixed an issue where multicast packets were dropped due to a large timeout value in the multicast FIB.
## PAN-191288
Fixed an issue where the firewall restarted due to a dnsproxy process crash.
## PAN-191269
Fixed an issue where the NAT pool leaked for passive mode FTP predict sessions.
## PAN-191218
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where the session log storage quota could not be changed via the web interface.
## PAN-191163
Fixed an issue where the logrcvr process stopped responding when processing threat logs with HTTP2 and data capture flagged.
## PAN-191022
Fixed an issue where a full routing table caused many dataplane messages, which resulted in packet buffer congestion and packet drops.
## PAN-190811
```caveat
PA-5450 firewalls only
```
Fixed an issue where logs were forwarded through the management interface instead of the configured log interface to be used for forwarding.
## PAN-190727
```caveat
PA-5450 firewall only
```
Fixed an issue where documentation for configuring the log interface was unavailable on the web interface and in the PAN-OS Administrators Guide.
## PAN-190493
Fixed an issue where decrypted VLAN traffic on Virtual Wire (V-Wire) changed to VLAN ID 0.
## PAN-190492
Fixed an issue where the Panorama log collector group level SSH settings were not migrated to the new format when upgrading from a PAN-OS 9.1 release to a PAN-OS 10.0 release.
## PAN-190448
Fixed an issue in ACC reports where IPv6 addresses were displayed instead of IPv4 addresses.
## PAN-190292
Fixed an issue where you could not configure a log interface as a service route **Device > Setup > Services > Service Route**
## PAN-190225
Fixed an issue on Panorama appliances in active/passive HA configurations where the passive appliance was unable to connect to the active appliance after resetting the secure connection state.
## PAN-189867
Fixed an issue where, when logging in to the GlobalProtect gateway, the authentication cookie was not reused.
## PAN-189861
Fixed an issue on firewalls in HA configurations where intermittent system alerts on the active firewall caused the pan_comm process to restart continuously.
## PAN-189762
Fixed an issue where a predict session didn't match with the traffic when both source NAT and destination NAT were enabled.
## PAN-189414
Fixed an issue where TCP packets were dropped during the first zone transfer when DNS security was enabled.
## PAN-189304
Fixed an issue where the Panorama appliance didn't display logs or generate reports for a device group containing MIPs platform that forwarded logs to Strata Logging Service.
## PAN-189225
Fixed an issue where BGP routes were lost or uninstalled after disabling jumbo frames on the firewall.
## PAN-189206
Fixed an issue where Device Group and Template administrator roles didn't support a context switch between the Panorama and firewall web interfaces.
## PAN-189114
Fixed an issue where the dataplane went down, which caused an HA failover.
## PAN-188942
Fixed an issue where, when modifying a DNS proxy configuration, the server port number was transparently changed to port 1080 if an administrator changed only the server IP address.
## PAN-188867
Fixed an issue where the firewall dropped packets when the session payload was too large.
## PAN-188338
Fixed an issue where canceling a commit caused the commit process to remain at 70% and the firewall had to be rebooted.
## PAN-188096
```caveat
VM-Series firewalls only
```
Fixed an issue where, on firewalls licensed with Software NGFW Credit (VM-FLEX-4 and higher), HA clustering was unable to be established.
## PAN-187890
Fixed an issue where the Strata Logging Service connection incorrectly displayed as disconnected when a service route was in use.
## PAN-187805
Fixed an issue where a process (all_pktproc) stopped responding and the dataplane restarted during certificate construction or destruction.
## PAN-187755
Fixed an issue where the maximum session timeout was not applied to the administrator as expected.
## PAN-187151
Fixed an issue where tunnel-monitoring interface was incorrectly shown as up instead of down.
## PAN-186995
Fixed an issue where the command to show IP address tags for Dynamic Address Groups displayed the error start-point should be equal to or between 1 and 100000 even when the maximum registered IP address limit was greater than 100,000. With this fix, the show command will display IP address tags up to the correct maximum limit.
## PAN-186957
Fixed an issue where, in **SAML Metadata Export**, a drop-down did not appear in the input field when **IP or Hostname** was selected for **Type**.
## PAN-186891
Fixed an issue where NetFlow packets contained incorrect octet counts.
## PAN-186807
Fixed an issue where RAID rebuild occurred after a reboot due to the RAID array not being populated during the firewall bootup.
## PAN-186658
Fixed an issue where Panorama console sessions were not cleared on the firewall after the idle-timeout value expired.
## PAN-186584
Fixed an issue where SNMPv3 CPU use didn't match the firewall output for show running resource-monitor on single dataplane firewalls.
## PAN-186418
Fixed an issue where Panorama displayed a discrepancy in RAM configured on the VMware host.
## PAN-186075
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall rebooted after receiving large packets while in DPDK mode on Azure virtual machines running CX4 (MLx5) drivers.
## PAN-185789
Fixed an issue where the show ntp CLI command resulted in a Rejected status for NTP servers that used auto-key authentication.
## PAN-185787
Fixed an issue where logging in to the Panorama web interface did not work and the following error message displayed: Timed out while getting config lock. Please try again.
## PAN-185286
```caveat
PA-5400 Series firewalls only
```
Fixed an issue on Panorama where device health resources did not populate.
## PAN-184902
Fixed an issue where the logd process stopped responding on Panorama and wasn't able to receive logs from the firewall due to the event manager returning a null pointer.
## PAN-184845
Fixed an issue where Address Resolution Protocol (ARP) packets dropped due to ARP throttle.
## PAN-184771
Fixed an issue where the threat category in a schedule report incorrectly displayed as unknown.
## PAN-184702
```caveat
M-700 appliances in Log Collector mode only
```
Fixed an issue on the Panorama management server where the Panorama appliance failed to connect to Panorama when added as a managed log collector.
## PAN-184342
Fixed an issue where the firewall dropped the second TCP packet as non-syn TCP if it was SYN/ACK/PSH due to the incorrect expectation that the second packet would be SYN/ACK.
## PAN-184068
```caveat
PA-5200 series firewalls only
```
Fixed an issue where the firewall generated pause frames, which caused network latency.
## PAN-183949
Fixed an issue on the firewall where a script to send XML API queries to update the block list caused the sslmgr process to restart.
## PAN-183888
Fixed an issue on Panorama appliances with PA-5400 Series managed firewalls where **Monitor > Traffic** did not display logs.
## PAN-183826
Fixed an issue where, after clicking **WildFire Analysis Report**, the web interface failed to display the report with the following error message: refused to connect.
## PAN-183664
```caveat
VM-Series firewalls only
```
Fixed an issue where set core operations failed during Software NGFW FLEX licensing.
## PAN-183603
```caveat
M-200 and M-600 appliances in Log Collector mode only
```
Fixed a disk issue that occurred after an upgrade to PAN-OS 10.2 which prevented the ElasticSearch process from starting, which resulted in the dedicated log collector being unable to write new logs to logging disks.
## PAN-183270
Fixed an issue where a bootstrapped firewall connected only to the first log collector in a log collector group.
## PAN-183184
Fixed an issue where enabling SSL decryption with a Hardware Security Model (HSM) caused a dataplane restart.
## PAN-183166
Fixed an issue where system, configuration, and alarm logs were queued up on the logrcvr process and were not forwarded out or written to disk until an autocommit was passed.
## PAN-182951
Fixed an issue where commits remained at 98% for an hour and then failed.
## PAN-182539
Fixed an issue with Panorama appliances in HA configurations where dedicated log collectors did not send local system or configuration logs to both Panorama appliances.
## PAN-182212
Fixed an issue where SNMP reported the panVsysActiveTcpCps and panVsysActiveUdpCps value to be 0.
## PAN-182173
```caveat
Panorama appliances in HA configurations only
```
Fixed an issue where, when using Prisma Access multitenancy, the passive appliance didn't correctly update the tenant information after the tenant was deleted on the active appliance.
## PAN-182087
Fixed an issue where commit failures occurred due to validity checks performed against self-signing certificates not evaluating **Authentication Key Identifier** and **Subject Key Identifier** fields.
## PAN-180863
Fixed an issue where the authentication key was mandatory on the firewall to remove Panorama server details.
## PAN-179750
A CLI command was added to set the virtual memory limit in dedicated log collectors.
## PAN-179543
Fixed an issue where the flow_mgmt process stopped responding when attempting to clear the session table, which caused the dataplane to restart.
## PAN-179295
Fixed an issue where report generation did not work as expected due to missed parameters being passed during inter-daemon communication.
## PAN-178243
Fixed an issue where **Shared Gateway** was not visible in the **Virtual System** drop down when configuring a Layer3 aggregate subinterface.
## PAN-178194
Fixed an issue with the web interface where, when only the Advanced URL Filtering license was activated, the message License required for URL filtering to function was incorrectly displayed and the **URL Filtering Profile > Inline ML** section was disabled.
## PAN-177861
Fixed an issue with User ID redistribution where a system log with severity of **High** was generated each time a commit was performed. This issue occurred due to all UIA agent connections being reset after each commit.
## PAN-177482
Fixed an issue where **ACC > App Scope > Threat Monitor** showed **NO DATA TO DISPLAY**.
## PAN-176703
Fixed an issue that occurred after upgrading to a PAN-OS 9.0 or later release where commits to the firewall configuration failed with the following error message: statistics-service is invalid.
## PAN-175236
Fixed an issue in the template stack where you were unable to add routes under **GlobalProtect > Gateway > Satellite > Network Settings**.
## PAN-174809
Fixed an issue where a process (all_pktproc) restarted.
## PAN-174489
Fixed a source user mismatch issue that occurred when the same name was set as the actual domain for the overriding domain.
## PAN-173373
```caveat
VM-Series firewalls in NSX-T deployments only
```
Fixed an issue where deployments dropped packets with the counter pan_netx_send_pkt error.
## PAN-172834
Fixed a memory leak issue related to the useridd process that occurred when processing IP-address-to-username mappings.
## PAN-172501
Fixed an issue where you were unable to revert HA mode settings to the default values from the web interface.
## PAN-171714
Fixed an issue where, when NetBIOS format (domain\user) was used for the IP address-to-username mapping and the firewall received the group mapping information from the Cloud Identity Engine, the firewall did not match the user to the correct group.
## PAN-171690
Fixed an issue where logs were not displayed in **GlobalProtect Deployment Activity** with the message No data to display even though they were displayed in the **Monitor** tab.
## PAN-171497
Fixed an issue where, after a local user group was updated by adding or removing users, the local user group was removed from groupdb.
## PAN-171159
Fixed a memory leak on the configd process on Panorama caused during multi-clone operations for rules.
## PAN-169153
Fixed an issue where LDAP connections over TLS failed with untrusted certificates error even though **Verify Server Certificate for SSL sessions** option was not selected.
## PAN-168005
Fixed an issue where GlobalProtect was unable to connect to the gateway and displayed the error message Could not connect to the gateway. The device or features requires a GlobalProtect subscription license even though the gateway firewall had a valid gateway license.
## PAN-163906
Fixed an issue where commits failed due to a non-configuration error.
## PAN-163828
Fixed an issue where path MTU discovery did not work when the MTU was not configured manually on the tunnel interface.
## PAN-163261
Fixed an intermittent issue where the firewall dropped GTPv2 Modify Bearer Request packets with the following error message: Abnormal GTPv2-C message with missing mandatory IE.
## PAN-160238
Fixed an issue where intermittent VXLAN packet drops occurred if the TCI was not configured for inspecting VXLAN traffic. This issue occurred when traffic was migrated from a firewall running a PAN-OS version earlier than PAN-OS 9.0 to a firewall running PAN-OS 9.0 or later.
## PAN-157215
Fixed an issue that occurred when two FQDNs were resolved to the same IP address and were configured as the same src/dst of the same rule. If one FQDN was later resolved to a different IP address, the IP address resolved for the second FQDN was also changed, which caused traffic with the original IP address to hit the incorrect rule.
## PAN-151469
Fixed an issue where packets were dropped unexpectedly due to errors parsing the IP version field.
@@ -0,0 +1,171 @@
---
type: Addressed
product: PAN-OS
version: 10.1.8-h2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-208724
Fixed an issue where port pause frame settings did not work as expected and incorrect pause frames occurred.
## PAN-208718
Additional debug information was added to capture internal details during traffic congestion.
## PAN-206658
Fixed a timeout issue in the Intel ixgbe driver that resulted in internal path monitoring failure.
## PAN-206251
```caveat
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
```
Fixed an issue where the logrcvr process did not send the system-start SNMP trap during startup.
## PAN-205735
Fixed an issue where the mgmtsrvr process stopped responding, which caused the Panorama web interface to become inaccessible and return a **504 Gateway Not Reachable** page.
## PAN-205030
Fixed an issue where, when a session hit policy based forwarding with symmetric return enabled was not offloaded, the firewall received excessive return-mac update messages, which resulted in resource contention and traffic disruption.
## PAN-204335
Fixed an issue where Panorama became unresponsive, and when refreshed, the error **504 Gateway not Reachable** was displayed.
## PAN-203851
Fixed an issue with firewalls in high availability (HA) configurations where host information profile (HIP) sync did not work between the active primary firewall and the active secondary firewall.
## PAN-203653
Fixed an issue where dynamic updates were completed even when configuration commits failed, which caused the all_task process to stop responding.
## PAN-203453
Fixed an issue on Panorama where the log query failed due to a high number of User-ID redistribution messages.
## PAN-203402
Fixed an intermittent issue where forward session installs were delayed, which resulted in latencies.
## PAN-203244
Fixed a path monitoring issue that caused traffic degradation.
## PAN-202783
```caveat
PA-7000 Series firewalls with 100G NPC (Network Processing Cards) only
```
Fixed an issue where sudden, large bursts of traffic destined for an interface that was down caused packet buffers to fill, which stalled path monitor heartbeat packets.
## PAN-202544
An enhancement was made to collect CPLD register data after a path monitor failure.
## PAN-202543
An enhancement was made to improve path monitor data collection by verifying the status of the control network.
## PAN-202535
Fixed an issue where the Device Telemetry configuration for a region was unable to be set or edited via the web interface.
## PAN-202361
Fixed an issue where packets queued to the pan_task process were still transmitted when the process was not responding.
## PAN-202101
Fixed an issue where firewalls stopped responding after an upgrade due to configuration corruption.
## PAN-202012
A debug command was introduced to control Gzip encoding for the GlobalProtect Clientless VPN application.
## PAN-201900
Fixed an internal path monitoring failure issue that caused the dataplane to go down.
## PAN-201858
Fixed an issue where the SD-WAN interface Maximum Transmission Unit (MTU) led to incorrect fragmentation of IPSec traffic.
## PAN-201627
Fixed an issue in next-generation firewall deployments where, when SD-WAN was configured, the dataplane restarted if all SD-WAN member links were down due to an out-of-memory (OOM) condition or during a reboot when all SD-WAN tunnels were down.
## PAN-198718
```caveat
PA-5280 firewalls only
```
Fixed an issue where memory allocation failures caused increased decryption failures.
## PAN-197582
Fixed an issue where, after upgrading to PAN-OS 10.1.6, the firewall reset SSL connections that used policy-based forwarding.
## PAN-196261
Fixed an issue where inter-lc disconnected once every minute in the system logs.
## PAN-194704
Fixed an issue with SIP ALG where improper NAT was applied when Destination NAT ran out of IP addresses.
## PAN-194068
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the firewall unexpectedly rebooted with the log message Heartbeat failed previously.
## PAN-193928
Fixed an intermittent issue where GlobalProtect logs were not visible under device groups (**Mobile_User_Device_Group**).
## PAN-192456
Fixed an issue where GlobalProtect SSL VPN processing during a high traffic load caused the dataplane to stop responding.
## PAN-191408
Fixed an issue where the firewall did not correctly receive dynamic address group information from Panorama after a reboot or initial connection.
## PAN-184766
```caveat
PA-5450 firewalls only
```
Fixed an issue where the control packets for BGP, OSPF, and Bidirectional Forwarding Detection (BFD) were not assigned a QoS value of 5.
## PAN-183757
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an issue where uneven distribution of sessions caused packet latency.
## PAN-172452
Fixed an issue where the log file did not include all logs.
## PAN-171143
Fixed an issue where tech support files didn't collected DP3 logs.
## PAN-167288
Fixed an issue with the pan_task process that caused the queue to build up.
@@ -0,0 +1,27 @@
---
type: Addressed
product: PAN-OS
version: 10.1.8-h7
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-237876
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
## PAN-231771
Fixed an issue where the firewall issued /box/getserv/ requests with PAN-OS 7.1.0 and did not take device certificates.
## PAN-227568
When a device certificate is installed, renewed, or removed, the firewall will reconnect to the WildFire cloud to use the newest certificate.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 10.1.8-h8
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-272809
A fix was made to address [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
@@ -0,0 +1,143 @@
---
type: Addressed
product: PAN-OS
version: 10.1.8
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-204830
Fixed an issue where logging in via the web interface or CLI did not work until an auto-commit was complete.
## PAN-203598
Fixed an issue where, when tunnel content inspection was enabled for VXLAN, ARP over VXLAN packets were dropped.
## PAN-201872
Fixed an issue where SMB performance caused overall network latency after an upgrade.
## PAN-201818
Fixed an issue where INIT SCTP packets were dropped after being processed by the CTD, and silent drops occurred even with SCTP no-drop function enabled.
## PAN-201627
Fixed an issue in next-generation firewall deployments where, when SD-WAN was configured, the dataplane restarted if all SD-WAN member links were down due to an out-of-memory (OOM) condition or during a reboot when all SD-WAN tunnels were down.
## PAN-201357
The CLI command debug dataplane set pow no-desched yes was added to address an issue where the all_pktproc process stopped responding and caused traffic issues.
## PAN-199726
Fixed an issue with firewalls in HA configurations where both firewalls responded with gARP messages after a switchover.
## PAN-199570
Fixed an issue where uploading certificates using a custom admin role did not work as expected after a context switch.
## PAN-199099
Fixed an issue where, when decryption was enabled, Safari and Google Chrome browsers on Apple Mac computers rejected the server certificate created by the firewall because the Authority Key Identifier was copied from the original server certificate and did not match the Subject Key Identifier on the forward trust certificate.
## PAN-198871
Fixed an issue when both URL and Advanced URL licenses were installed, the expiry date was not correctly checked.
## PAN-198733
```caveat
PA-5450 firewalls only
```
Fixed an issue where tcpdump was hardcoded to eth0 instead of bond0.
## PAN-198266
Fixed an issue where, when predicts for UDP packets were created, a configuration change occurred that triggered a new policy lookup, which caused the dataplane stopped responding when converting the predict. This resulted in a dataplane restart.
## PAN-198078
Fixed an issue where VXLAN keepalive packets were dropped randomly.
## PAN-197576
Fixed an issue where commits pushed from Panorama caused a memory leak related to the mgmtsrvr process.
## PAN-197386
Fixed an issue where traffic that was subject to network packet broker inspection entered a looping state due to incorrect session offload.
## PAN-196704
Fixed an issue where **Preview Changes on Panorama Push to Devices** incorrectly displayed changes to encrypted entries.
## PAN-196583
Fixed an issue where the Cisco TrustSEc plugin triggered a flood of redundant register/unregister messages due to a failed IP address tag database search.
## PAN-196558
Fixed an issue where IP address tag policy updates were delayed.
## PAN-196131
Fixed an issue where the comm process stopped responding when a show command was executed in two sessions.
## PAN-195107
```caveat
PA-7000s Series firewalls with LFCs only
```
Fixed an issue where the IP address of the LFC displayed as **unknown**.
## PAN-194795
Fixed an issue where a dataplane 1 VCCIO voltage fluctuation triggered the chassis master alarm.
## PAN-194615
Fixed an issue where the packet broker session timeout value did not match the master sessions timeout value after the firewall received a TCP FIN or RST packet. The fix ensures that Broker session times out within 1 second after the master session timed out.
## PAN-194441
Fixed an issue where the dataplane CPU usage was higher than expected due to packet looping in the broker session when the network packet broker was enabled.
## PAN-189720
Fixed an issue where commits failed when downgrading a Panorama appliance running a PAN-OS 10.1 release to a PAN-OS 10.0 release.
## PAN-189429
Fixed a memory leak that occurred when enabling XFF (x-forwarded-for) logging in a Security policy.
## PAN-189270
Fixed an issue that caused a memory leak on the reportd process.
## PAN-188118
Fixed an issue with firewalls in FIPS mode that prevented device telemetry from connecting.
## PAN-181759
```caveat
Firewalls in active/active HA configurations only
```
Fixed an issue where firewall configuration files were not synced.
## PAN-180039
Fixed an issue in 10.0.9, where executing the CLI command show transceiver-detail all resulted in the following error message: An error occurred. See dagger.log for information..
## PAN-178613
```caveat
PA-400 Series firewalls only
```
Fixed an issue where multiple restarts related to the all_task process occurred.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 10.1.9-h6
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-222712
```caveat
PA-5450 firewalls only
```
Fixed a low frequency DPC restart issue.