diff --git a/web/data/issues/PAN-OS/addressed/11.1.10_2026-03-13.md b/web/data/issues/PAN-OS/addressed/11.1.10_2026-03-13.md index 361d2fc..e758d0b 100644 --- a/web/data/issues/PAN-OS/addressed/11.1.10_2026-03-13.md +++ b/web/data/issues/PAN-OS/addressed/11.1.10_2026-03-13.md @@ -1,5 +1,5 @@ --- -type: Known +type: Addressed product: PAN-OS version: 11.1.10 --- diff --git a/web/data/issues/PAN-OS/addressed/8.1.11_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.11_2026-04-01.md new file mode 100644 index 0000000..0a4b01f --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.11_2026-04-01.md @@ -0,0 +1,481 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.11 +--- + +## WF500-5137 + +Fixed an issue where the `show wildfire global last-device-registration all` CLI command incorrectly returned an error message: `Failed`, even when you registered the firewall correctly. + +## PAN-126547 + +Fixed an issue where a process (configd) stopped responding when an XML API call with `type=config&action=get` triggered during a commit. + +## PAN-126354 + +Fixed an issue where log in and commits took longer than expected when you used XML API calls to create new address objects. + +## PAN-125517 + +An enhancement was made to improve firewall performance for stream control transmission protocol (SCTP) flows. To enable this enhancement, run the `set sctp fast-sack yes` CLI command. + +## PAN-125346 + +An enhancement was made to enable you to configure IPv6 in the web interface and through a CLI command when you added IPv6 virtual addresses to a firewall in a high availability (HA) active/active configuration. + +## PAN-125069 + +An enhancement was made to enable you to delete the GTP-C tunnel with all GTP-U tunnel sessions after the firewall received a Delete Bearer Response message where default bearer ID=5. To enable this enhancement, run the `set gtp ebi5-del-gtpc [yes/no]` CLI command. + +## PAN-124996 + +Fixed an issue where a GlobalProtect™ daemon (rasmgr) stopped responding when you connected with an overlapping IPv6 address, which caused subsequent GlobalProtect connections to fail. + +## PAN-124658 + +Fixed an issue where the timer system call activated more frequently than expected, which caused higher than expected CPU usage. + +## PAN-124299 + +Fixed an issue on VM-Series firewalls in an HA active/passive configuration where the active firewall leaked packet buffers when links were disconnected from the hypervisor. + +## PAN-123850 + +```caveat +PA-5200 and PA-7000 Series firewalls only +``` + +Fixed an issue where conflicting GTP sessions were installed in short interval, which caused the firewall to queue GTP packets and deplete packet buffers. + +## PAN-123446 + +Fixed an issue where an administrator with a Superuser role could not reset administrator credentials. + +## PAN-123371 + +Fixed an issue where the **Wildfire Analysis Report** incorrectly displayed the following error message: `You are not authorized to access this page on the web interface`. + +## PAN-123030 + +Fixed an issue with a memory leak associated with a process (mgmtsrvr) when you pushed a commit. + +## PAN-122662 + +```caveat +PA-5260 firewalls only +``` + +Fixed an issue where a process (mpreplay) stopped responding after a commit when you configured the firewall with more than 200 virtual systems (vsys) running on PAN-OS® 8.1.9. + +## PAN-122601 + +Fixed a memory leak issue with a process (configd) when you performed device group related operations. + +## PAN-122550 + +Fixed an issue where VM-Series firewalls on Microsoft Azure experienced traffic latency due to an incompatible driver. + +## PAN-121911 + +Fixed an issue where a process (logrcvr) restarted during commits. + +## PAN-121523 + +Fixed an issue where an API call triggered memory errors, which caused a process (configd) to stop responding and triggered `SIGABRT` logs. + +## PAN-121447 + +Fixed an issue where the BGP did not remove the IPv6 default route from the forwarding table after the route was withdrawn. + +## PAN-121133 + +Fixed an issue on Panorama M-Series and virtual appliances where a validation job triggered a memory leak in a process (configd), which caused context switching between Panorama and the web interface to respond slower than expected. + +## PAN-121001 + +Fixed an issue where the firewall only reported a maximum of two logs when you configured more than two hardware security modules (HSM). + +## PAN-120901 + +Fixed an issue on Panorama M-Series and virtual appliances where partial commits did not apply configuration changes as expected. + +## PAN-120662 + +```caveat +PA-7000 Series firewalls using PA-7000-20G-NPC cards only +``` + +Fixed an intermittent issue where an out-of-memory (OOM) condition caused the dataplane or internal path monitoring to stop responding. + +## PAN-120361 + +Fixed an issue on Panorama M-Series and virtual appliances where objects were not compressed, which caused higher than expected CPU and memory usage. + +## PAN-120287 + +Fixed a JavaScript error due to an incorrect HTTP response, which prevented GlobalProtect Clientless VPN applications to load. + +## PAN-120151 + +Fixed an issue where the DNS packet parser incorrectly processed DNS packet headers when the QD count is 0, which caused the DNS server to stop responding. + +## PAN-119862 + +```caveat +PA-5050 firewalls only +``` + +Fixed an intermittent issue where an out-of-memory (OOM) condition caused the dataplane or internal path monitoring to stop responding. With this fix, session capacity is reduced by 400,000. + +## PAN-119765 + +Fixed an intermittent issue where the firewall dropped sessions that used a large number of predict sessions. + +## PAN-119680 + +Fixed a rare issue where the `show running` CLI commands for policy addresses caused file descriptor leaks. + +## PAN-119647 + +Fixed an issue where a process (mgmtsrvr) stopped responding due to an out-of-memory (OOM) condition. + +## PAN-119225 + +Fixed an issue where an inaccurate sequence number check for an RST packet caused the packet to drop. + +## PAN-119172 + +Fixed an issue where the firewall incorrectly enforced URL category policies and erroneously triggered **alert** instead of **block**. + +## PAN-118985 + +Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) experienced high memory utilization and a memory leak condition, which caused slower than expected performance. + +## PAN-118720 + +Fixed an issue on a firewall in an HA active/active configuration where Oracle traffic SYN packets dropped intermittently with the `flow_fpp_owner_err_no_predict` counter. + +## PAN-118583 + +Fixed a memory allocation issue that prevented URL filtering logs from displaying the full URL. + +## PAN-118509 + +Fixed an issue on Panorama M-Series and virtual appliances where shared policies were out of sync due to an empty stream control transmission protocol (SCTP) after you upgraded the firewall from PAN-OS 8.0.16 to PAN-OS 8.1.8. + +## PAN-118180 + +Fixed an issue on firewalls configured with authentication policies where UDP and ICMP packets matching an authentication policy did not generate traffic logs as defined in the Security policy when sessions were redirected or denied. + +## PAN-118057 + +Fixed an issue on a firewall in an HA active/passive configuration where a process (all_pkts) stopped responding and the dataplane restarted due to an internal path monitoring failure and an HA failover event. + +## PAN-118055 + +Fixed an issue where administrators were unable to export Security Assertion Markup Language (SAML) metadata files from virtual system (vsys) specific authentication profiles. + +## PAN-117959 + +Fixed an issue where LDAP authentication failed when you configured the authentication server with an FQDN. + +## PAN-117900 + +Fixed an issue where commits failed when you moved an object referenced in a policy to a shared group. + +## PAN-117888 + +Fixed an issue where the firewall was unable to detect the hardware security module (HSM), which caused the firewall to drop SSL traffic. + +## PAN-117738 + +```caveat +PA-3050 and PA-3060 firewalls only +``` + +Fixed an issue where a higher than expected number of `flow_fpga_flow_update` messages occurred when you configured QoS. + +## PAN-117727 + +Fixed an issue where job threads were deadlocked, which prevented log in attempts and displayed the following error message: `CONFIG_LOCK: write lock TIMEDOUT for cmd`. + +## PAN-117303 + +Fixed an issue where the BGP aggregate prefix, which is advertised to multiple BGP peers was removed from RIB OUT when you disabled one of the BGP peers. + +## PAN-117120 + +Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) restarted due to virtual memory issues. + +## PAN-117086 + +Fixed an issue where community attributes to BGP routes had a character limit of 31 characters, which caused expressions to take longer than expected to process. + +## PAN-117026 + +Fixed an issue where eBGP peers connected by a VPN tunnel failed to come up when you configured eBGP **Multi Hop** to **0**. + +## PAN-116949 + +Fixed a memory leak issue with a process (mprelay), which caused the dataplane to restart. + +## PAN-116903 + +Fixed an issue on Panorama M-Series and virtual appliances where you were unable to configure **Enable X-Auth Support** (**Network** > **GlobalProtect** > **Gateways** > **Template** > **** > **Agent** > **Tunnel Settings**) at the Template-stack level. + +## PAN-116772 + +Fixed an issue where the firewall sent empty attributes in the LDAP query when you did not configure **Alternate Username 1 - 3** (**Device** > **User Identification** > **Group Mapping Settings** > **** > **User and Group Attributes**) in the User Attributes web interface. + +## PAN-116729 + +Fixed an issue where you were unable to deploy bootstrapped content in offline environments due to content validity checks. + +## PAN-116611 + +Fixed an issue where an API call for correlated events did not return any events. + +## PAN-116473 + +Fixed an issue where the firewall logged URL categories configured for Allow in the URL filtering logs. + +## PAN-116384 + +An enhancement was made to enable firewalls, Panorama management servers, and log collectors running a PAN-OS 8.1 release to receive new App-ID™ signatures in the new ID signature range (7,020,001 to 7,040,000). To enable this enhancement, you must reinstall the current content update or install a later content update. + +## PAN-116334 + +Fixed an issue where a process (mgmtsrvr) leaked memory caused by SNMP traps. + +## PAN-116286 + +Fixed an issue where commits failed after you upgraded from PAN-OS 8.0.16 to PAN-OS 8.1.6 due to an invalid encryption state for a host information profile (HIP) object. + +## PAN-116274 + +Fixed an issue where the firewall was unable to authenticate when you pushed a public key from Panorama. + +## PAN-116123 + +Fixed an issue where a process (devsrvr) stopped responding when you performed a commit or a configuration validation when the proxy ID contained 24 or more characters. + +## PAN-115990 + +Fixed an issue where the FQDN address object (**Policy** > **Security** > **** > **Value**) displayed the following unrelated error: ` Not used`. + +## PAN-115959 + +Fixed an issue where DNS names with more than 63 characters did not resolve FQDN address objects during an FQDN refresh. + +## PAN-115890 + +Fixed an issue where the `show system info` CLI command incorrectly displayed `VMware ESXi` as `VMWare ESXi`. + +## PAN-115879 + +Fixed an issue on a firewall where a bypass switch sent heartbeat messages to the firewall, which triggered non-stop link status change interrupts through a Marvell switch. + +## PAN-115738 + +Fixed an issue where data logs were generated but the firewall did not forward the logs to the syslog server. + +## PAN-115697 + +Fixed CVE-2019-17437, see [PAN-SA-2019-0038](https://securityadvisories.paloaltonetworks.com/Home/Detail/201) for details. + +## PAN-115549 + +Fixed an issue where predict sessions were incorrectly created with a `captive-portal zone`, which caused the firewall to drop RTP traffic. + +## PAN-115349 + +Fixed an issue where an incorrect predict session was created when a policy-based forwarding (PBF) policy was used without a NAT in the parent session, which caused the firewall to drop RTP and RTCP packets. + +## PAN-115344 + +Fixed an issue where the Username Modifier **%USERDOMAIN%\%USERINPUT%** enabled you to log in to a locked out user account. + +## PAN-115287 + +Fixed an issue where commits failed and displayed the following error message: `Commit job was not queued. All daemons are not available`. + +## PAN-115282 + +Fixed an issue where temporary download files were deleted before a download job was completed, which caused the progress bar to remain at 0% and prevented a timeout when downloads fail. + +## PAN-115281 + +Fixed an issue where the firewall did not resolve an external dynamic list server address when the DNS proxy configured it as a static entry. + +## PAN-115108 + +Fixed an issue on Panorama M-Series and virtual appliances where scheduled uploading and installation of WildFire® content meta files to WF-500 appliances failed and displayed the following error message: `device not supported`. + +## PAN-114880 + +Fixed an issue where the `debug management-server summary-logs flush-options max-keys` CLI command did not persist through a system reboot. + +## PAN-114856 + +A change was made to limit debug log visibility to superusers only. + +## PAN-114771 + +Fixed an issue on Panorama M-Series and virtual appliances where **Decrypt Mirror** (**Objects** > **Decryption** > **Decryption Profile** > ****) did not appear in the **Interface** drop-down menu when you tried to configure a Decryption Profile. + +## PAN-114667 + +Fixed an issue on a firewall in an HA active/passive configuration where a split-brain condition occurred after you upgraded from PAN-OS 8.1.3 to PAN-OS 8.1.6. + +## PAN-114628 + +Fixed an issue where Panorama was unable to query logs forwarded from the firewall to the log collector. + +## PAN-114540 + +Fixed an issue where renaming a template stack did not change the value and reset to the original value after you commit the change. + +## PAN-114456 + +Fixed an issue where extended packet capture (pcap) for threat logs caused a process (mgmtsrvr) to stop responding. + +## PAN-114427 + +Fixed an issue where an empty host name in the HTTP header caused a web server process (websrvr) to stop responding when you accessed the captive portal redirect page. + +## PAN-114270 + +Fixed an issue where the firewall dropped TCP trace route traffic after you upgraded to PAN-OS 8.1.5. To leverage this fix, run the `set session tcp-reject-diff-syn no` CLI command. + +## PAN-114247 + +Fixed an issue where a larger than expected number of `Could not find entry for interface ethernet1/. in CPS table` filled the snmpd.log, which caused the log file to rotate more frequently than expected. + +## PAN-113610 + +Fixed an issue where Panorama incorrectly deleted valid device group directories and was unable to generate reports. + +## PAN-113606 + +Fixed an issue where the Throughput column (**Panorama** > **Managed Devices** > **Health**) was incorrectly labeled. + +## PAN-113261 + +```caveat +PA-5200 Series firewalls only +``` + +Fixed an issue where the total entries for the URL filtering allow list, block list, and custom categories was incorrectly changed to a 100,000 entries limit. + +## PAN-112661 + +Fixed an issue where you were unable to access a firewall due to a defective small form-factor pluggable (SFP)/SFP+ module inserted into the firewall. + +## PAN-112321 + +Fixed an issue where a daemon (sslmgr) caused an out-of-memory condition. + +## PAN-111850 + +Fixed an issue where the firewall did not capture the number of packets in the threat packet capture (pcap) as configured in the extended packet capture length setting. + +## PAN-111544 + +Fixed an issue on Panorama M-Series and virtual appliances configured as log collectors where SSH did not respond after you enabled SSH on ethernet1/1. + +## PAN-110685 + +Fixed a rare issue where an incorrect User-ID™ match to the respective LDAP group caused a security policy mismatch. + +## PAN-110098 + +Fixed an issue on a firewall in an HA active/passive configuration where you were unable to synchronize configurations or dynamic updates between HA pairs. + +## PAN-109874 + +Fixed a memory leak issue on a firewall during a commit, which prevented the firewall from generating GlobalProtect client configurations. + +## PAN-108876 + +Fixed an issue where the firewall dropped Session Initiation Protocol (SIP) registration packets, which caused SIP sessions to fail. + +## PAN-108488 + +Fixed an issue where a typo in the MIB definition file caused an error message: `ERROR: Cannot find symbol panSctpDIamAvpCode` when you loaded a PAN-TRAPS.my file. + +## PAN-108234 + +Fixed an issue on a firewall configured with a GlobalProtect gateway where after you upgraded from a PAN-OS 7.1 release to a PAN-OS 8.0 or later release and committed the configuration, the following error message displayed: `SSLVPN: Invalid access-routess (null) in tunnel GPgateway-N`. + +## PAN-107330 + +Fixed an issue where when you configured the **URL Filtering Profile** (**Objects** > **URL Filtering** > **** > **Categories**) to **Shared** all custom URL categories pushed displayed on the web interface and returned the following error message: `test -> credential-enforcement -> allow 'Blocked-Category-Exceptions' is not valid reference test -> credential-enforcement -> allow is invalid`. + +## PAN-107207 + +Fixed an issue where the VPN tunnel operational status incorrectly displayed “`up`" even though the VPN tunnel is down. + +## PAN-106889 + +Fixed a rare issue on a firewall in an HA active/passive configuration running in FIPS-CC mode where the passive firewall rebooted in to maintenance mode. + +## PAN-106434 + +Fixed an issue where a process (keymgr) stopped responding due to missed heartbeats, which caused IPSec tunnels to stop responding. + +## PAN-105806 + +Fixed an issue where the firewall did not detect duplicate Destination/Source IP Addresses entered into the **Security Policy Rule**. + +## PAN-105437 + +Fixed an issue where a process (useridd) ran out of file descriptors and stopped responding due to the rate of concurrent Security Assertion Markup Language (SAML) requests initiated by Authentication policy rules. + +## PAN-104178 + +Fixed an issue on Panorama M-Series and virtual appliances where CLI commands returned the following error message: `Error: Timed out while getting config lock. Please try again` when a commit job was not pending. + +## PAN-103500 + +An enhancement was made to enable the firewalls and Panorama M-Series and virtual appliances to set the SameSite attribute to **Strict** and the GlobalProtect portal to set the SameSite attribute to **Lax**. + +## PAN-102195 + +Fixed an issue where the firewall did not detect all threat sessions while the App and Threat content installation was processed. + +## PAN-100977 + +```caveat +VM-Series NSX edition firewalls only +``` + +Fixed an issue where the existing logs for dynamic address updates had insufficient information to debug the root cause of a bug and where the dynamic address update logs were larger than expected, which caused the file to roll over every five minutes and did not provide a sufficient log history to debug issues. + +## PAN-98584 + +```caveat +PA-5200 Series and PA-3200 Series firewalls only +``` + +Fixed a rare issue where invalid packets caused the firewall to stop responding as expected when you configured the dataplane port to traverse HA3 traffic. + +## PAN-97784 + +Fixed an issue on a firewall where repeated failed validation errors were reported for validated configurations due to a race condition. + +## PAN-97232 + +Fixed an issue on a firewall in an HA active/passive configuration where a process (pan_comm) stopped responding when you configured an external dynamic list, which caused commits to fail and displayed the following error message: `failed to handle CONFIG_UPDATE_START`. + +## PAN-95230 + +Fixed an issue where the Security Assertion Markup Language (SAML) schema size limit (100,000 characters) prevented the SAML Identity Provider Server Profile Import (**Device** > **Server Profiles** > **SAML Identity Provider** > **Import**) from importing SAML metadata. + +## PAN-90738 + +Fixed an issue where a process (configd) exceeded the virtual memory usage limit and caused the firewall to restart. With this fix, you must run the `debug management-server system globalfind disable-db-lookup` and `debug management-server system appweb-thread-count enhance` commands. + +## PAN-89649 + +Fixed an issue where Panorama did not send the preference list to managed firewalls, which caused logs to be forwarded to the CMS instead of the log collector. diff --git a/web/data/issues/PAN-OS/addressed/8.1.14_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.14_2026-04-01.md new file mode 100644 index 0000000..bb679ae --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.14_2026-04-01.md @@ -0,0 +1,257 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.14 +--- + +## WF500-5185 + +```caveat +WF-500 appliances only +``` + +Fixed an issue where inadequate rotation of log files caused unusually high disk usage. + +## PAN-140270 + +Added debugging task to periodically collect output (in the Tech Support File (TSF) from the `debug dataplane internal pdt bcm counters graphical` CLI command. + +## PAN-139555 + +Fixed an issue in a high availability (HA) configuration where, after upgrading the passive firewall, the outer UDP sessions synced from the active firewall did not retain rule information and GPRS tunneling protocol (GTP) inspection failed after failover. + +## PAN-137673 + +Fixed an issue where a memory leak associated with the (devsrvr) process caused an out-of-memory (OOM) condition on the firewall. + +## PAN-136820 + +Fixed an issue where an HA failover occurred after the firewall reported the following error message in the System log: `Dataplane down: controlplane exit failure`. + +## PAN-136470 + +Fixed an issue where a process (all_pktproc) restarted and caused the dataplane to restart after processing packets with 0.0.0.0 and destination protocol 251 that internally mapped to GTP-C traffic. + +## PAN-135909 + +Fixed an issue where connections to the web interface were abruptly interrupted due to a double free condition (gPanUiPhpGlobal_secure_config_reset), which led to unexpected process restarts. + +## PAN-135684 + +Fixed an issue with log collectors on Panorama where large indexes caused higher than expected CPU usage when disk space usage was high. + +## PAN-134707 + +Fixed an issue where a commit took longer than expected after upgrading when **Negate** was enabled for addresses in a rule. + +## PAN-134547 + +Fixed an issue where the passive firewall in an active/passive HA configuration deleted BGP-learned routes that were synchronized from the active firewall when the BGP configuration included the redistribution of the learned routes. + +## PAN-134431 + +Fixed an issue with Security Assertion Markup Language (SAML) authentication where the firewall used old `authd_id` values, which resulted in failed authentication. + +## PAN-134370 + +Fixed an issue where a process (mp-relay) restarted due to missing routes or next hops. + +## PAN-133289 + +Fixed an issue where improper parsing of the URL database caused high device-server CPU usage. + +## PAN-132898 + +Fixed an intermittent issue where logs were missing with `log_index` debug messages due to merging of the index. + +## PAN-131939 + +Fixed an issue where the dataplane restarted during file transfer due to one or more content updates being installed at the same time. + +## PAN-131922 + +Fixed an issue where the certificate was not automatically pushed to the firewall until you manually fetched the certificate from the firewall. + +## PAN-131517 + +Fixed an issue with a memory corruption error that caused a process (all_pktproc) to restart. + +## PAN-131501 + +Fixed an issue when configuring Clientless VPN and executing the `portal-getconfig` CLI command where user groups were retrieved but were not freed, which caused a memory leak in the sslvpn process. + +## PAN-130750 + +Fixed an issue where a commit failed on the firewall after disabling **Pre-Defined Reports** from Panorama. + +## PAN-130361 + +A fix was made to address an external control of filename vulnerability in the SD-WAN component of Palo Alto Networks Panorama ([CVE-2020-2009](https://security.paloaltonetworks.com/CVE-2020-2009)). + +## PAN-129328 + +Fixed an issue where packet descriptor (on-chip) usage reached 100% even though buffers, throughput, and session counts were not elevated. + +## PAN-129289 + +Fixed an issue where export failed for a large running-config.xml file using the XML API. + +## PAN-128568 + +Fixed a rare issue where a process (pan_task) restarted due to a NULL pointer exception. + +## PAN-128330 + +Fixed an issue where the response for the XML API call for the `show object registered-ip all` operational CLI command included extra appended content. + +## PAN-127614 + +Fixed an issue where SNMPv3 monitoring of the firewall failed from the Zabbix server after a firewall reboot or SNMP process restart on the firewall. + +## PAN-127189 + +Fixed an issue where images displayed through the Clientless VPN were corrupted. + +## PAN-127118 + +A fix was made to address an OS command line injection vulnerability in the PAN-OS management server where authenticated users were able to inject arbitrary shell commands with root privileges ([CVE-2020-2014](https://security.paloaltonetworks.com/CVE-2020-2014)). + +## PAN-127004 + +Fixed an issue where a process (sysd) restarted due to missing heartbeats. + +## PAN-126817 + +Fixed an issue where Security Assertion Markup Language (SAML) response validation failed with a certificate mismatch error even when the firewall had the same certificate on the identity provider. + +## PAN-126362 + +A fix was made to address a command injection vulnerability in the PAN-OS management interface where an authenticated administrator was able to execute arbitrary OS commands with root privileges ([CVE-2020-2010](https://security.paloaltonetworks.com/CVE-2020-2010)). + +## PAN-126205 + +Fixed an issue where role-based administrators were unable to import certificate private keys onto firewalls. + +## PAN-125934 + +Fixed an issue on Panorama where a commit failed when bootstrapping a firewall to a configuration with a serial number of "unknown." The commit failed with the following error message: `mgt-config -> devices -> unknown unknown is invalid`. + +## PAN-125889 + +```caveat +PA-7000 Series firewalls only +``` + +Fixed an issue where auto-tagging failed for log forwarding. + +## PAN-125794 + +Fixed an issue where a role-based adminstrator with CLI access was unable to successfully execute the `commit-partial` CLI command to commit only changes made by themselves. + +## PAN-125730 + +Fixed an issue where packets tagged with IP protocol 252 were incorrectly treated as GPRS tunneling protocol (GTP) traffic, which caused the packet processor to terminate. + +## PAN-125534 + +```caveat +PA-5200 Series and PA-7000 Series firewalls only +``` + +Fixed an issue where firewalls experienced high packet descriptor (on-chip) usage during uploads to the WildFire Cloud or WF-500 appliance. + +## PAN-125527 + +Fixed an issue where multilayer ZIP-file inspection caused software buffer corruption and caused the all_pktproc process to restart. + +## PAN-125410 + +Fixed an issue where a new GPRS tunneling protocol version 2 control plane (GTPv2-C) session reused GTP-C tunnel parameters within two seconds after deleting the old GTP-C session, which caused a session conflict on the firewall. + +## PAN-124039 + +A fix was made to address an issue where the GlobalProtect Portal feature in PAN-OS did not set a new session identifier after a successful user login ([CVE-2020-1993](https://security.paloaltonetworks.com/CVE-2020-1993)). + +## PAN-123637 + +```caveat +PA-3200 Series firewalls only +``` + +Fixed an issue where configuring 1G small form-factor pluggable (SFP) ports on a firewall with forced speed mode (of 1G) enabled made the link unusable when forced speed mode (of 1G) was also enabled on the peer firewall. + +## PAN-122432 + +Fixed an issue where the firewall failed to correctly read the virtual system (vsys), which eventually resulted in a management server process restart. + +## PAN-121626 + +```caveat +PA-3200 Series firewalls only +``` + +Fixed an intermittent issue where firewalls dropped packets, which caused issues such as traffic latency, slow file transfers, reduced throughput, internal path monitoring failures, and application failures. + +## PAN-119806 + +Fixed an issue where the dataplane restarted due to internal packet path monitoring failure. + +## PAN-118226 + +A fix was made to address an improper input validation vulnerability in the configuration daemon of Palo Alto Networks Panorama ([CVE-2020-2011](https://security.paloaltonetworks.com/CVE-2020-2011)). + +## PAN-117955 + +A fix was made to address a missing authorization vulnerability in the Panorama management server ([CVE-2020-1996](https://security.paloaltonetworks.com/CVE-2020-1996)). + +## PAN-117480 + +A fix was made to upgrade Nginx software included with PAN-OS ([PAN-SA-2020-0006](https://security.paloaltonetworks.com/PAN-SA-2020-0006) / CVE-2016-4450 and CVE-2013-0337). + +## PAN-116480 + +Fixed an issue in Panorama where the `show system search-engine-quota` CLI command, the `show log-collector serial-number ` CLI command, and **Statistics** (**Panorama > Managed Collectors > Statistics**) showed incorrect log retention data. + +## PAN-116189 + +Fixed an issue where Session Initiation Protocol (SIP) calls failed and displayed the following error message: `end-reason : resources-unavailable`. + +## PAN-102688 + +A fix was made to address an OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS ([CVE-2020-2008](https://security.paloaltonetworks.com/CVE-2020-2008)). + +## PAN-102682 + +A fix was made to address an OS command injection vulnerability in the management component of PAN-OS where an authenticated user was able to potentially execute arbitrary commands with root privileges ([CVE-2020-2007](https://security.paloaltonetworks.com/CVE-2020-2007)). + +## PAN-100855 + +A fix was made to address a stack-based buffer overflow vulnerability in the management server component of PAN-OS where an authenticated user was able to execute arbitrary code with root privileges ([CVE-2020-2006](https://security.paloaltonetworks.com/CVE-2020-2006)). + +## PAN-100415 + +A fix was made to address an external control of filename vulnerability in the command processing of PAN-OS ([CVE-2020-2003](https://security.paloaltonetworks.com/CVE-2020-2003)). + +## PAN-100006 + +```caveat +PA-200 firewalls only +``` + +Fixed an issue where the User-ID™ process caused an out-of-memory (OOM) condition when the number of IP address tags monitored from Amazon Web Services (AWS) VM Monitoring was greater than the maximum supported number. + +## PAN-96104 + +Fixed an issue in the web interface where the language preference reverted to English after logging out from a session that was authenticated by Security Assertion Language Markup (SAML) single sign-on (SSO). + +## PAN-88136 + +Fixed a rare issue where a URL update caused the dataplane to restart. + +## PAN-82052 + +A fix was made to address an open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS ([CVE-2020-1997](https://security.paloaltonetworks.com/CVE-2020-1997)). + +## PAN-71148 + +Fixed an issue on Panorama where the **ACC** tab did not show data for the period before the daylight saving time (DST) change. diff --git a/web/data/issues/PAN-OS/addressed/8.1.16_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.16_2026-04-01.md new file mode 100644 index 0000000..6b1e75a --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.16_2026-04-01.md @@ -0,0 +1,277 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.16 +--- + +## WF500-5466 + +Fixed an issue where the timeout for downloading a PDF of a WildFire analysis report was too short, which caused missing reports and 404 errors. + +## PAN-151978 + +A fix was made to address an insecure configuration of a daemon (appweb) that allowed a remote unauthenticated user to send a specifically crafted request to the device that caused the Appweb service to crash. Repeated attempts to send this request resulted in denial of service to all PAN-OS services by restarting the device and putting it into maintenance mode ([CVE-2020-2041](https://security.paloaltonetworks.com/CVE-2020-2041)). + +## PAN-150243 + +Fixed an issue where after a successful commit, the candidate configuration was not updated to running configuration when initiated by an API-privileges-only custom role based administrator. + +## PAN-150172 + +Fixed an issue where dataplane processes restarted when attempting to access websites that had the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled. + +## PAN-150170 + +```caveat +and PAN-149822 +``` + +A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)). + +## PAN-150013 + +```caveat +and PAN-149822 +``` + +A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)). + +## PAN-149813 + +Fixed an issue where the reply to an XML API call from Panorama was in a different format after upgrading to PAN-OS 8.1.14-h1 and later releases, which caused automated systems to fail the API call. + +## PAN-149325 + +Fixed an issue on Panorama where the web interface took more time than expected to load changes when the virtual router was large or when there was a large configuration change request from the web interface. + +## PAN-149005 + +Fixed an issue where XML API failed to fetch logs larger than 10MB. + +## PAN-148806 + +A fix was made to address an uncontrolled resource consumption vulnerability in PAN-OS that allowed for a remote unauthenticated user to upload temporary files through the management web interface that were not properly deleted after the request was finished. An attacker could disrupt the availability of the management web interface by repeatedly uploading files until available disk space was exhausted ([CVE-2020-2039](https://security.paloaltonetworks.com/CVE-2020-2039)). + +## PAN-148676 + +Fixed an issue where the `panlogs` directory reached 100% utilization on the firewall due to early calculation of the .size file. + +## PAN-148522 + +Fixed an issue for PAN-DB where certain situations caused performance issues. + +## PAN-147424 + +Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high. + +## PAN-147258 + +Fixed an issue with one-way audio for inbound voice calls due to incorrect source port translation. + +## PAN-147203 + +Fixed an issue where API calls did not return the output for the operational command for running configurations. + +## PAN-146878 + +Fixed an issue where TCP traffic dropped due to TCP sequence checking in a high availability (HA) active/active configuration where traffic was asymmetric. + +## PAN-146837 + +A fix was made to address a vulnerability involving information exposure through log files where sensitive fields were recorded in the configuration log without masking on PAN-OS software when the `after-change-detail` custom syslog field was enabled for configuration logs and the sensitive field appeared multiple times in one log entry. The first instance of the sensitive field was masked but subsequent instances were left in clear text ([CVE-2020-2043](https://security.paloaltonetworks.com/CVE-2020-2043)). + +## PAN-145942 + +After upgrading to certain PAN-OS 8.1 and 9.0 versions, for certain configurations using dynamic routing without graceful restart and with Bidirectional Forwarding Detection (BFD) enabled, there was a longer traffic hit after an HA failover compared to previous versions. This was due to BFD incorrectly timing admin-down messages for the failover event. + +## PAN-145929 + +Fixed an issue where, after upgrading the passive firewall, the stream control transmission protocol (SCTP) sessions synced from the active firewall did not retain the rule information, and, after failover, SCTP stateful inspection did not work. + +## PAN-145422 + +Fixed an issue where a process (all_pktproc) restarted while processing SSL VPN sessions. + +## PAN-145302 + +Fixed an issue where the HA peer device did not preserve its import configuration when the mode was active/active and VR sync was disabled. + +## PAN-144804 + +Fixed an issue where the firewall generated GPRS tunneling protocol (GTP) logs for invalid GTP packets. This fix also implements a counter, `flow_gtp_invalid_ver`, where the invalid packets are counted. + +## PAN-144232 + +Fixed an issue where, when any change was made to an authentication profile, the LDAP server or local user database in a shared context removed the user group mapping information from the firewall. + +## PAN-143686 + +Fixed an issue where a firewall running in FIPS mode was unable to download the GlobalProtect datafile even when a GlobalProtect license was installed and valid. + +## PAN-143493 + +Fixed an memory issue associated with a process (mgmtsrvr) due to a large number of ACK packets in logs on Panorama or the log collector. + +## PAN-142927 + +Fixed an issue where the locked users list grew too large, which caused 100% CPU usage on a process (authd). With this fix, locked users will be purged hourly if the lockout time for that user has expired. + +## PAN-142853 + +Fixed an issue on Panorama where commits failed, referring to a portion of the configuration that was not changed. + +## PAN-142674 + +Fixed an issue where a process (brdagent) failed in an HA configuration using High Speed Chassis Interconnect (HSCI) ports due to a memory leak. + +## PAN-142302 + +Fixed an issue where the firewalls faced connection issues with Cortex Data Lake. + +## PAN-141239 + +Fixed an issue where dataplane free memory was depleted, which affected new GlobalProtect connections to the firewall. + +## PAN-140982 + +```caveat +PA-7000 Series firewalls only +``` + +Fixed an issue where a process (mprelay) on the control plane was restarted due to an internal heartbeat miss. + +## PAN-140494 + +Added a mechanism to detect corrupted or incorrect formats received on dataplane CPU. Such packets are dropped, and a counter, `pkt_recv_bad_group`, is incremented. + +## PAN-140373 + +```caveat +PA-5250, PA-5260, and PA-5280 firewalls only +``` + +Fixed an issue where, when you deployed the firewall in a network that used Dynamic IP and Port (DIPP) NAT translation with PPTP, the generic routing encapsulation (GRE) packet in the PPTP connection from the server was sent back to its ingress interface in some connections. + +## PAN-139764 + +Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak, which caused a process (configd) to restart. + +## PAN-139172 + +Fixed an issue where response pages generated from the firewall used the SMAC and DMAC addresses from the original packet, which caused a MAC flap on connected switches. + +## PAN-138037 + +Fixed an issue where the host information profile (HIP) match message was automatically enabled when modifying the GlobalProtect Agent settings. + +## PAN-137639 + +Fixed an issue where the log export query was slower than expected when exporting one million lines of logs. + +## PAN-137138 + +Fixed an issue where a process (configd) consistently restarted with the following error message: `virtual memory limit exceeded, restarting` due to a dynamic updates push from Panorama to multiple firewalls. + +## PAN-136957 + +Fixed an issue where access was denied if a password contained more than 63 characters. + +## PAN-136844 + +Fixed an issue for S11 traffic where if the Modify Bearer Request message came after 30 seconds of Create Session Response message, the firewall dropped the Modify Bearer Request packet. This fix increases this time to 90 seconds. + +## PAN-136726 + +Fixed an issue on the firewall where the dataplane pan-task process (all_pktproc) stopped responding while inspecting Server Message Block (SMB) traffic. + +## PAN-136623 + +Fixed an issue where a process (useridd) failed due to internal user groups that were loading from the disk taking over the lock. + +## PAN-136304 + +Fixed an issue where clientless VPN rewrite failed due to incorrect parsing of the HTML webpage. + +## PAN-135418 + +Fixed an issue on the firewall where configuring uppercase **User Domain** values in authentication profiles led to a failure in GlobalProtect Agent configuration selection based on the domain user match condition. + +## PAN-135356 + +Fixed an issue where policies that contained objects did not display correctly when exported to CSV or PDF format. + +## PAN-135262 + +A fix was made to address a vulnerability involving information exposure through log files where an administrator's password or other sensitive information was logged in cleartext while using the CLI in PAN-OS software. The `opcmdhistory.log` file was introduced to track operational command (op-command) usage but did not mask all sensitive information ([CVE-2020-2044](https://security.paloaltonetworks.com/CVE-2020-2044)). + +## PAN-134624 + +```caveat +VM-Series firewalls only +``` + +Fixed an issue where the VLAN interface failed to obtain the MAC address when the interface was used as a DHCP relay agent. + +## PAN-134488 + +Fixed an issue where a process (all_pktproc) restarted while processing Clientless VPN traffic. + +## PAN-133880 + +Fixed an issue where RADIUS authentication failed due to an FQDN resolution failure after the VM-Series firewall rebooted. + +## PAN-131973 + +Fixed an issue where both firewalls in an HA active/passive configuration stopped responding at the same time. + +## PAN-130564 + +Fixed an issue where the session ID did not display correctly in the debug logs related to the hardware security module (HSM). + +## PAN-130168 + +Fixed an issue where a process (pan_comm) stopped responding due to operation commands run during a commit. + +## PAN-129461 + +Fixed an issue where excessive next hop FPGA exceptions occurred when an ARP request or response was lost in the network in an ECMP configuration, which blocked subsequent ARP learning due to a full queue. + +## PAN-129277 + +Enhanced a daemon (dnsproxy) to support DNS compression for query strings. + +## PAN-128761 + +A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2037](https://security.paloaltonetworks.com/CVE-2020-2037)). + +## PAN-125466 + +Fixed an issue where, during Antivirus or Threat Content update downloads or install, some show commands in the CLI, API calls, and web interface pages gave information output with significant delay (15-60 seconds). + +## PAN-123279 + +Fixed an issue where a process (configd) stopped responding after upgrading Panorama to 8.1.9 from 8.0.16 due to 8.0 WildFire appliance register requests. + +## PAN-118098 + +Fixed an issue where a process (useridd) restarted while updating user groups. This issue occurred when multiple group mapping profiles were used to fetch the same group information while using different domain override settings. + +## PAN-116720 + +A fix was made to address a reflected cross-site scripting (XSS) vulnerability in the PAN-OS management web interface where, if a remote attacker was able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link, the attacker could execute arbitrary code JavaScript code in the administrator's browser and perform administrative actions ([CVE-2020-2036](https://security.paloaltonetworks.com/CVE-2020-2036)). + +## PAN-112539 + +Fixed an issue where the firewall stopped forwarding logs to the log collector from the Log Processing Card (LPC) after a commit push from Panorama due to a race condition. + +## PAN-100757 + +Fixed an issue where the TCP timestamp was stripped from the Client Hello when SSL Forward Proxy decryption was enabled. + +## PAN-93184 + +Fixed an intermittent issue where the firewall reported `Validation of Local client certificate failed resulting in error 58, Problem with the local SSL certificate` in the system log due to management plane out-of-memory errors when a process (varrcvr) attempted to register to the cloud. + +## PAN-84211 + +In accordance with the latest NIST Revision, PAN-OS FIPS-CC mode releases prior to 9.0 used unsupported ciphers within the UserID Agent connections. With this fix, we removed all the cipher combinations, TLS server, and TLS clients in PAN-OS 8.0.5-h1 and later releases for FIPS-CC mode of operation to meet recent NIAP requirement and policy. diff --git a/web/data/issues/PAN-OS/addressed/8.1.18_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.18_2026-04-01.md new file mode 100644 index 0000000..0f44544 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.18_2026-04-01.md @@ -0,0 +1,113 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.18 +--- + +## PAN-155453 + +Fixed an issue in the configuration logs where the destination zone was masked by asterisks. + +## PAN-153673 + +Fixed an issue where traffic logs were not shown due to a thread timeout that was causing the reading of the logs from the dataplane to slow. + +## PAN-153440 + +Fixed an issue where firewalls repeatedly connected and disconnected to Cortex Data Lake due to a probing issue. + +## PAN-153111 + +Fixed an issue where packet buffer unavailability caused host-bound sessions to remain in an opening state in the dataplane. + +## PAN-152743 + +Fixed an issue where, when initial flows from both directions reached the firewall at the same time, a race condition occurred, which caused the firewall to display the following error message: `Duplicate flows detected while inserting , flow with the same key`. The flow keys were identical due to the flows having the same SRC and DST ports. + +## PAN-152706 + +Fixed an intermittent issue where Panorama did not retrieve firewall logs from Cortex Data Lake. + +## PAN-152282 + +Fixed an issue where platforms using AHO for content and application inspection run into dataplane process (all_pktproc) restarts. + +## PAN-151483 + +Fixed an issue where, when an out-of-order stream of TCP packets was subjected to HTTP header insertion, the packets were duplicated. + +## PAN-151149 + +Fixed an issue where certificates, custom logos, and Security Assertion Markup Language (SAML) metadata were unable to be uploaded from the web interface using a Chromium-based browser running version 84 or later. + +## PAN-149377 + +A fix was made to address a vulnerability regarding information exposure through log files in PAN-OS that made it possible for configuration secrets for HTTP, email, and SNMP trap v3 log forwarding server profiles to be logged to the logrcvr.log system log ([CVE-2021-3032](https://security.paloaltonetworks.com/CVE-2021-3032)). + +## PAN-148818 + +Fixed an issue where the decryption profile was configured without the **Block sessions with expired certificates** option, but the firewall still blocked websites that were signed by an Expired AddTrust Root CA (certificate authority). + +## PAN-147529 + +Fixed an issue where **ValidateAll** jobs were incorrectly logged as **CommitAll** in the configuration log of the firewall. + +## PAN-146236 + +Fixed an issue where the firewall was unable to properly create stream control transmission protocol (SCTP) sessions for multi-homed environments when multiple endpoints on the same SCTP associations sent INIT/INIT-ACK chunks during handshakes. + +## PAN-144410 + +Debug logs were added to detect an out-of-memory (OOM) condition that caused the management server to restart. + +## PAN-140669 + +Fixed a memory leak issue caused by a process (mgmtsrvr). + +## PAN-140492 + +Fixed an issue on the firewall where, with SSL forward proxy feature enabled, random file downloads over a decrypted session would stall or hang in the middle. + +## PAN-139007 + +Fixed an issue where **URL Filtering** logs were misaligned when exported from the firewall due to the presence of a comma in the **User-Agent** field of the logs. + +## PAN-137233 + +Fixed an issue where authenticating to GlobalProtect via expired SAML requests (waiting more than 10 minutes) still sent authentication to the SAML server. This invalidated the previously connected gateway and connected users to the second best gateway. + +## PAN-134981 + +Fixed an issue with a memory leak in a process (user-id) due to failed LDAP over SSL (LDAPS) requests. + +## PAN-134840 + +Fixed an issue where pre-logon users failed authentication if the cookie was expired, instead of using certificate authentication. + +## PAN-134663 + +Fixed an issue where the running configuration on the firewall changed after an upgrade from a Panorama Virtual Appliance in a VMware NSX environment. + +## PAN-134029 + +Fixed an intermittent issue on the firewall where H.225 VOIP signaling packets dropped. + +## PAN-132055 + +Fixed an issue where a process (mgmtsrvr) was unresponsive when the number of active file descriptors was greater than 1024. + +## PAN-129234 + +Fixed an issue where syslog connection failures were frequently reported in system logs. + +## PAN-126938 + +Fixed an issue where multiple daemons restarted due to MP ARP overflow. + +## PAN-124681 + +A fix was made to address a vulnerability where Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls were not cleared before the data frame was created ([CVE-2021-3031](https://security.paloaltonetworks.com/CVE-2021-3031)). + +## PAN-110720 + +Fixed an issue where a high volume of traffic over SSL VPN caused a process (all_pktproc) to unexpectedly stop responding. diff --git a/web/data/issues/PAN-OS/addressed/8.1.20-h1_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.20-h1_2026-04-01.md new file mode 100644 index 0000000..a4fe831 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.20-h1_2026-04-01.md @@ -0,0 +1,25 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.20-h1 +--- + +## PAN-176661 + +Fixed an issue in Simple Certificate Enrollment Protocol (SCEP) ([CVE-2021-3060](https://security.paloaltonetworks.com/CVE-2021-3060)). + +## PAN-176655 + +A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)). + +## PAN-158334 + +A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)). + +## PAN-176653 + +A fix was made to address an OS command injection vulnerability in the PAN-OS web interface that enabled an authenticated administrator with permissions to use XML API to execute arbitrary OS commands to escalate privileges ([CVE-2021-3058](https://security.paloaltonetworks.com/CVE-2021-3058)). + +## PAN-176618 + +A fix was made to address an OS command injection vulnerability in PAN-OS that existed when performing dynamic updates ([CVE-2021-3059](https://security.paloaltonetworks.com/CVE-2021-3059)). diff --git a/web/data/issues/PAN-OS/addressed/8.1.21-h1_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.21-h1_2026-04-01.md new file mode 100644 index 0000000..f59ae5e --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.21-h1_2026-04-01.md @@ -0,0 +1,9 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.21-h1 +--- + +## PAN-183767 + +Fixed an issue where downloading Dynamic Updates files failed when connected to the static update server at `us-static.updates.paloaltonetworks.com`. diff --git a/web/data/issues/PAN-OS/addressed/8.1.21-h2_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.21-h2_2026-04-01.md new file mode 100644 index 0000000..ab3bf72 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.21-h2_2026-04-01.md @@ -0,0 +1,17 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.21-h2 +--- + +## PAN-202450 + +Fixed an issue where the `device-client-cert` was set to expire on December 31, 2023. With this fix, the expiration date has been extended. + +## PAN-198372 + +Fixed an issue where the `root-cert` was set to expire on December 31, 2023. With this fix, the expiration date has been extended. + +## PAN-193004 + +Fixed an issue where `/opt/pancfg` partition utilization reached 100%, which caused access to the Panorama web interface to fail. diff --git a/web/data/issues/PAN-OS/addressed/8.1.22_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.22_2026-04-01.md new file mode 100644 index 0000000..82b422d --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.22_2026-04-01.md @@ -0,0 +1,25 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.22 +--- + +## PAN-176097 + +Fixed an issue in an active/active HA configuration where the V-wire interface on the active primary firewall forwarded the ICMP error code packet that was received by the active secondary firewall. + +## PAN-174709 + +Fixed an out-of-memory condition that occurred due to multiple parallel jobs being created by the scheduled log export feature. + +## PAN-172243 + +Fixed an issue where NetFlow traffic triggered a packet buffer leak. + +## PAN-161496 + +Fixed an issue when calculating the incremental checksum after a post-NAT translation where the arguments to `pan_in_cksm32_diff` overflowed the 32-bit integer. + +## PAN-136007 + +Fixed an issue where generating subordinate ECDSA Certificate Authority (CA) certificates from the web interface failed if the **Common Name** field contained a space. diff --git a/web/data/issues/PAN-OS/addressed/8.1.23_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.23_2026-04-01.md new file mode 100644 index 0000000..e9a4b3c --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.23_2026-04-01.md @@ -0,0 +1,25 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.23 +--- + +## PAN-190175 + +A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)). + +## PAN-190223 + +A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)). + +## PAN-177551 + +A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)). + +## PAN-162600 + +Fixed an issue where, when the GlobalProtect client sent UDP/4501 traffic that was destined for the GlobalProtect gateway inside the GlobalProtect tunnel, the firewall still processed the traffic, which caused routing loops. + +## PAN-158328 + +Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups. diff --git a/web/data/issues/PAN-OS/addressed/8.1.24-h1_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.24-h1_2026-04-01.md new file mode 100644 index 0000000..bea1bf2 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.24-h1_2026-04-01.md @@ -0,0 +1,9 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.24-h1 +--- + +## PAN-132593 + +Fixed an issue on the firewall where radius authentication to CLI failed with the error message Invalid user. Please login using a valid account. diff --git a/web/data/issues/PAN-OS/addressed/8.1.24-h2_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.24-h2_2026-04-01.md new file mode 100644 index 0000000..a2b0e45 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.24-h2_2026-04-01.md @@ -0,0 +1,21 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.24-h2 +--- + +## PAN-208218 + +```caveat +Releases earlier than PAN-OS 8.1.24-h2 +``` + +Due to a component change, versions earlier than PAN-OS 8.1.24-h2 are no longer supported on later hardware revisions of the PA-5200 Series. + +## PAN-204830 + +Fixed an issue where logging in via the web interface or CLI did not work until an auto-commit was complete. + +## PAN-159697 + +Fixed an issue where, after rebooting the firewall, authenticating using LDAP credentials did not work. diff --git a/web/data/issues/PAN-OS/addressed/8.1.24_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.24_2026-04-01.md new file mode 100644 index 0000000..a68c7bf --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.24_2026-04-01.md @@ -0,0 +1,33 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.24 +--- + +## PAN-195571 + +A fix was made to address an authentication bypass vulnerability in the PAN-OS 8.1 web interface that allowed a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privileged actions ([CVE-2022-0030](https://security.paloaltonetworks.com/CVE-2022-0030)). + +## PAN-181759 + +```caveat +Firewalls in active/active HA configurations only +``` + +Fixed an issue where firewall configuration files were not synced. + +## PAN-168514 + +Fixed an issue where authentication failed when the destination service route was used to reach the RADIUS server. + +## PAN-163030 + +Fixed an issue where restarting the devsrvr process caused new GlobalProtect connections to fail with the error message required client certificate not found. This issue occurred due to a key mismatch between the dataplane and the management plane. + +## PAN-159578 + +Fixed an issue on the firewall where the varrcvr process stopped responding. + +## PAN-126210 + +Fixed an issue where a role based administrator with the appropriate permissions was unable to run the CLI command show config.... diff --git a/web/data/issues/PAN-OS/addressed/8.1.25-h2_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.25-h2_2026-04-01.md new file mode 100644 index 0000000..5c80a0e --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.25-h2_2026-04-01.md @@ -0,0 +1,13 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.25-h2 +--- + +## PAN-237871 + +```caveat +WF-500 appliances and PAN-DB private cloud deployments only +``` + +Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended. diff --git a/web/data/issues/PAN-OS/addressed/8.1.26_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.26_2026-04-01.md new file mode 100644 index 0000000..2b09896 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.26_2026-04-01.md @@ -0,0 +1,37 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.26 +--- + +## BLANK-000000 + +This release includes bug and performance fixes. + +## PAN-237876 + +Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024. + +## PAN-237871 + +```caveat +WF-500 appliances and PAN-DB private cloud deployments only +``` + +Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended. + +## PAN-217493 + +Fixed an issue where superusers with read-only privileges were unable to view SCEP object configurations. + +## PAN-215576 + +Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032. + +## PAN-202450 + +Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended. + +## PAN-198372 + +Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended. diff --git a/web/data/issues/PAN-OS/addressed/8.1.4-h2_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.4-h2_2026-04-01.md new file mode 100644 index 0000000..8c96d15 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.4-h2_2026-04-01.md @@ -0,0 +1,9 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.4-h2 +--- + +## PAN-107271 + +Fixed an issue on a PA-3200 Series firewall running PAN-OS 8.1.4 in an HA configuration where the HA1-B (backup) port did not come up as expected. diff --git a/web/data/issues/PAN-OS/addressed/8.1.6_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.6_2026-04-01.md new file mode 100644 index 0000000..1487110 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.6_2026-04-01.md @@ -0,0 +1,403 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.6 +--- + +## WF500-4901 + +Fixed an issue where files sent by Traps™ to WildFire® were referenced for trusted signers in the incorrect database, which resulted in a malicious file verdict and caused conflicting post detection events. + +## WF500-4893 + +```caveat +RADIUS server profile configurations only +``` + +Fixed an issue where the RADIUS authentication protocol was incorrectly changed to CHAP authentication when you pushed a commit from a Panorama™ appliance running a PAN-OS® 8.1 release to a WF-500 appliance running a PAN-OS 8.0 release. + +## WF500-4869 + +Fixed an issue on a WF-500 appliance where the sample analysis failed when using FIPS-CC mode. + +## WF500-4815 + +Fixed an intermittent issue on WF-500 appliances where the Redis command line interface (CLI) failed to execute during master node re-balancing. + +## WF500-4747 + +Fixed an issue on a WF-500 appliance where the Panorama™ management server ran unrelated Logging Service threads. + +## WF500-4636 + +```caveat +WF-500 Appliances only +``` + +Fixed a rare issue that occurred after upgrading from a PAN-OS 8.0 release to a PAN-OS 8.1 release where the disk partition became full due to the amount of data on the drive and, when you tried to delete the backup database to free up space, the `debug wildfire reset backup-database-for-old-samples` CLI command failed and resulted in the following error: `Server error : Client wf_devsrvr not ready.` + +## PAN-111305 + +Fixed an issue where you were unable to reference certificate profiles from the External Dynamic Lists (**Objects** > **External Dynamic Lists** > **Add** > **Create List**) but instead, you had to type in the certificate profile. + +## PAN-110448 + +Fixed an issue on PA-3200 Series firewalls where the dataplane took longer than expected to respond or intermittently stopped responding after a firewall reboot. + +## PAN-109594 + +Fixed an issue where the dataplane restarted when an IPsec rekey event occurred and caused a tunnel process (tund) failure when one--but not both--HA peer is running PAN-OS 8.0.14 or PAN-OS 8.1.5. + +## PAN-109124 + +A security-related fix was made to address an issue where you were unable to retrieve GlobalProtect™ cloud service threat packet captures from the Logging Service on Panorama M-Series and virtual appliances. + +## PAN-108785 + +Fixed an intermittent issue on a firewall in an HA active/passive configuration where a ping test stopped responding on Ethernet 1/1, 1/2, and 1/4 due to input errors on the corresponding switch port after an HA failover. + +## PAN-108241 + +Fixed an issue on a PA-3200 Series firewall where multiple dataplane processes (all_pktproc, flow_mgmt, flow_ctrl, and pktlog_forwarding) stopped responding when overloaded with traffic. + +## PAN-108165 + +Fixed memory issues on Palo Alto Networks hardware and virtual appliances that caused intermittent management plane instability. + +## PAN-108161 + +Fixed an issue on an HA active/passive configuration where GTP sessions did not properly sync to the passive firewall, which caused a failure on the passive firewall during a failover. + +## PAN-107895 + +Fixed an issue where PDP Delete Response packet did not match the GTPv1-C tunnel session, which caused the generated GTP log to display incorrect session data. + +## PAN-107893 + +Fixed an issue where a **Delete PDP Context Response** (**Monitor** > **Logs** > **GTP**) did not correlate with a **Delete PDP Context Request** and appeared as a new session. + +## PAN-107790 + +Fixed an issue where Application incorrectly displayed as `unknown-udp` instead of `gtp-c` for the **GTPv1-C tunnel management message** GTP Event Type. + +## PAN-107734 + +Fixed an intermittent issue where IPSec Tunnels failed due to a race condition between the (pan_task) process and (tund) process. + +## PAN-107694 + +Fixed an issue on Panorama M-Series and virtual appliances where after you selected **Allow with Ticket** (**Networks** > **GlobalProtect** > **Portals ** > **App**) the web interface **Generate Ticket** did not display. + +## PAN-107290 + +Fixed an issue where a single API call failed to locate a Device Group node and create a device node for the Device Group when necessary. + +## PAN-107262 + +A security-related fix was made to prevent cross-site scripting (XSS) attacks through the PAN-OS Management Web Interface (CVE-2019-1566). + +## PAN-106947 + +Fixed an intermittent issue where a large number of out-of-order TCP packets caused packet buffer depletion. + +## PAN-106776 + +A security-related fix was made to prevent a cross-site scripting (XSS) vulnerability in PAN-OS External Dynamic Lists (CVE-2019-1565). + +## PAN-106759 + +Fixed an issue in an HA active/passive configuration where a process (configd) restarted due to a memory error. + +## PAN-106253 + +Fixed an issue where the GTP Message Type **Modify Bearer Response** and GTP Event Code **124223** were denied due to failed stateful inspections. + +## PAN-106251 + +Fixed an issue where the list of Panorama Managed Devices did not display (**Panorama** > **Device** > **Deployment** > **Licenses**). + +## PAN-105928 + +Fixed an issue on a firewall where server side data packets dropped after a terminated challenge ACK session was reused. + +## PAN-105759 + +Fixed an issue on PA-3200 Series and PA-5200 Series firewalls in an HA active/active configuration where the SNMP notification did not report the HA interfaces. + +## PAN-105570 + +```caveat +PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only +``` + +Fixed an issue where the QoS profile rule did not match non-offloaded traffic as expected. + +## PAN-105567 + +Fixed an intermittent issue on Panorama M-Series and virtual appliances where a cloned security or NAT policy used the incorrect **Rule order**. + +## PAN-105348 + +Fixed an issue on Panorama M-Series and virtual appliances where Dynamic Updates (**Device** > **Dynamic Updates**) did not allow local overrides on an existing template. + +## PAN-105281 + +```caveat +PAN-OS 8.1.6 and later +``` + +Fixed an issue where a SAML based GlobalProtect re-authentication portal displayed an authentication error after you have previously logged in. + +## PAN-105157 + +Fixed an intermittent issue on Panaoram M-Series and virtual appliances where logs did not display due to a file descriptor limit by the process (Elasticsearch). + +## PAN-105103 + +Fixed an intermittent issue where GTP logs did not display due to GTP packets with an APN > 14 bytes caused the traffic log to reach the limit and stopped generating logs. + +## PAN-105012 + +Fixed an issue on Panorama M-Series and virtual appliances where a log migration from an old-disk pair to a new-disk pair failed with the following error message: `Error restoring disks from RMAed device`, which caused the (configd) process to fail. + +## PAN-104463 + +Fixed an intermittent issue where the DNS resolution stopped responding when the firewall acted as a DNS proxy and the DNS request volume was higher than expected. + +## PAN-104361 + +Fixed an issue on a firewall in an HA active/passive configuration where a process (all_task) failed due to a (bad_gtp_header) code on the passive firewall after upgrading from PAN-OS 8.0.12. + +## PAN-104300 + +Fixed an issue on a firewall where a process (mprelay) stopped responding while the (`> debug dataplane internal pdt`) command was processed. + +## PAN-104165 + +Fixed an issue on a VM-Series firewall configured to use the i40e single-root input/output virtualization (SR-IOV) virtual function (VF) with VLAN tagging dropped Ethernet frames exceeding 1496 bytes. + +## PAN-104077 + +Fixed an intermittent issue where User-ID™ stopped responding, which caused the user IP mapping to not display. + +## PAN-104042 + +Fixed an issue where directly connected IPv4 routes do not display in the routing table after the firewall was restarted. + +## PAN-104041 + +Fixed an issue where the web interface management session failed to time out as expected when you set the **Idle Timeout** (**Device** > **Setup** > **Management** > **Authentication Settings** > **Edit**) to more than five minutes. + +## PAN-103665 + +Fixed an issue on an HA active/active configuration where the active primary LLDP profile could not be copied to the active secondary firewall. + +## PAN-103224 + +Fixed an issue on a VM-Series firewall where the initialization buffer caused the firewall to stop responding when five or more interfaces were active. + +## PAN-102954 + +A security-related fix was made to address a code parameter in the clientless VPN portal. + +## PAN-102625 + +Fixed an issue on a firewall where traffic stopped passing due to higher than normal duplicate TCP ACK packets sent from the client side, which caused a spike in packet buffers and packet descriptor usage. + +## PAN-102338 + +Fixed an issue where you were unable to configure **Maximum Egress** (**Network** > **QoS**) to 10000 Mbps on a 10000 Mbps port. + +## PAN-101990 + +Fixed an issue on Panorama M-Series and virtual appliances in an HA active/passive configuration where you were unable to edit the template variables (**Panorama** > **Summary**). + +## PAN-101973 + +Fixed an issue where you were unable to configure IPv6 variables (**Network** > **Virtual Routers** > **Add** > **Static** > **Routes** > **IPv6**). + +## PAN-101882 + +Fixed an issue on Panorama M-Series and virtual appliances where a partial Commit and Push for one or more administrators incorrectly sets the Push scope to all relevant firewalls as if a full Commit and Push was performed. + +## PAN-101851 + +Fixed an intermittent issue on PAN-OS 8.1.3 and later releases, where downloading files from email services were allowed when the file blocking profile was configured to block email service file downloads. + +## PAN-101800 + +Fixed an issue where the parent session stopped responding during a file transfer using a decryption enabled FTP server with the following error message: `Lost connection`. + +## PAN-101692 + +Fixed an issue where the (`show session all filter nat-rule`) command did not respond with destination NAT rules. + +## PAN-101684 + +Fixed an issue on Panorama M-Series and virtual appliances where adding a threat exception for a child Device Group caused existing rules to be removed from the Global Device Group. + +## PAN-101614 + +Fixed an issue on a firewall where SSL/TLS Service Profile (**Device** > **SSL/TLS Service Profile**) values failed to change after an override. + +## PAN-101607 + +Fixed an issue where template administrators with the required permission made configuration changes on shared objects and the Commit failed with the following error message: `No pending change to commit`. + +## PAN-101401 + +Fixed an issue where a DNS App-ID™ security policy allowed non-DNS traffic to flow through. + +## PAN-101202 + +Fixed an issue on a firewall where the TFC padding parameter was set to **null** when negotiating with a peer device capable of TFC padding during IKEv2 negotiations. + +## PAN-101185 + +Fixed an issue on Panorama M-Series and virtual appliances where the Decrypt Mirror (**Network** > **Interfaces** > **Ethernet** > **Interface Type**) template setting did not Push to a firewall. + +## PAN-101031 + +Fixed an issue where you were unable to select existing certificates after you created an IKE gateway on a template stack and changed Authentication to Certificate. + +## PAN-101029 + +Fixed an issue where routing traffic dropped due to an increased activity in global counter (`flow_fpga_rcv_egr_L3_NH_NF`) when an interface is moved from one virtual router to another. + +## PAN-100962 + +Fixed an issue on Panorama M-Series and virtual appliances where the disk quota configuration exceeded a combined total of 100 percent when a Push was performed from Panorama due to value discrepancies between Panorama and the firewall. + +## PAN-100717 + +Fixed an issue where the (configd) process depleted memory when you deleted multiple security rules with an XML API call. + +## PAN-100623 + +Fixed an issue on a firewall in an HA active/passive configuration where a higher than normal rate of HA session update messages caused higher than normal CPU usage on both active and passive nodes. + +## PAN-100381 + +Fixed an issue on a firewall in an HA configuration where a path monitoring variable was not available for Destination IP (**Device** > **High Availability** > **Link and Path Monitoring** > **Add Virtual Router Path**). + +## PAN-100173 + +Fixed an issue where H.323 based calls had audio issues due to the predicted RTP session not following the policy-based forwarding (PBF) rules that sends traffic from the client to servers, which caused RTP traffic to be forwarded incorrectly by route. + +## PAN-99924 + +Fixed an issue where the Panorama management server web and CLI stopped responding after a partial configuration load (**Panorama** > **Setup** > **Operations**). + +## PAN-99764 + +Fixed an issue on VM-Series firewalls where CPU calculations for additional vCPUs in the dataplane did not display correctly. + +## PAN-99742 + +Fixed an issue on a PA-500 Series firewall where SSL Forward Proxy was denied due to insufficient shared memory. + +## PAN-99621 + +Fixed an issue on a firewall where Captive Portal sessions matched incorrect policies and were incorrectly logged in the traffic log. + +## PAN-99504 + +Fixed an issue on a firewall where Group Mapping (**Device** > **User Identification** > **Group Mapping Settings**) did not display the list of LDAP server profile users when a Domino server with an empty distinguished name (DN) was used. + +## PAN-99079 + +Fixed an issue on Panorama M-Series and virtual appliances where Logging Service was enabled, traffic log filters with a variable length subnet mask did not display any logs. + +## PAN-99058 + +Fixed an issue where threat log messages (`SCAN: UDP Port Scan`) appeared when the UDP port scan traffic rate was less than the Reconnaissance Protection UDP port scan threshold. + +## PAN-99002 + +Fixed a rare issue where XML files with random file sizes failed to upload through API calls. + +## PAN-99000 + +Fixed an issue where the packet capture option did not display (**Monitor** > **Traffic**) when administrators switched context from Panorama to a managed firewall. + +## PAN-98861 + +Fixed an issue where shadowed rule warnings did not display during commits. + +## PAN-98811 + +Fixed an issue on Panorama M-Series and virtual appliances where Group Mapping Settings (**Object** > **Security Profile** > **URL Filtering** > **User Credential Detection**) did not display profile names. + +## PAN-98786 + +Fixed an issue where websites were not accessible when you configured a decryption policy Action to **No Decrypt** and enabled **Block sessions with expired certificates**. + +## PAN-98625 + +Fixed an issue where the Threat Category (**Monitor** > **Threat**) did not display as expected on Panorama M-Series and virtual appliances when it received logs from PA-200, PA-220, PA-500, and PA-800 Series firewalls. + +## PAN-97898 + +Fixed a rare issue where the traffic log did not generate data due to a negative log counter reading. + +## PAN-97743 + +Fixed an issue where the firewall did not recognize the small form-factor pluggable (SFP) port, which caused the dataplane to restart when the path monitor process stopped responding. + +To ensure a successful upgrade to PAN-OS 8.1.6 for this fix, re-seat all connected SFP transceivers and then follow the [upgrade path](https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/upgrade-to-pan-os-81/upgrade-the-firewall-to-pan-os-81/determine-pan-os-upgrade-path.html) described in the PAN-OS 8.1 upgrade procedure ([PAN-OS 8.1 New Features Guide](https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features.html)). + +## PAN-97672 + +Fixed an issue where polled SNMP object identifiers (OID) stopped responding after the firewall was restarted. + +## PAN-97670 + +Fixed an issue on a VM-Series firewall in an HA active/passive configuration where after a reboot, the passive firewall sent ARP packets during the initialization state, which caused a traffic conflict with the active firewall. + +## PAN-97496 + +Fixed an issue on a firewall where the (`show running resource-monitor ingress-backlogs`) CLI command displayed invalid session IDs. + +## PAN-97298 + +```caveat +PAN-OS 8.1.1 and later releases only +``` + +Fixed an issue where **Address Groups** (**Objects** > **Address Groups**) search results were cleared from the web interface when you switched between tabs. + +## PAN-97223 + +Fixed an issue where an administrator with superuser access was unable to remove a configuration lock from a logged out administrator whose username contained a backslash (" \ "). + +## PAN-97139 + +Fixed an issue where the GlobalProtect Data File (**Device** > **Dynamic Updates** > **GlobalProtect data File**) version did not update after a PAN-OS 8.1 upgrade. + +## PAN-95975 + +Fixed an issue on a firewall in an HA active/passive configuration where the scheduled antivirus content update failed due to a process (mgmtsrvr) failure. + +## PAN-95121 + +Fixed an issue where applications gets disabled after you enabled them during the install or revert of application and threat signatures. + +## PAN-93112 + +Fixed an issue on a PA-5200 Series firewall where small form-factor pluggable (SFP) ports only linked in auto negotiation mode. + +## PAN-91059 + +Fixed an issue where GTP log query filters did not work when you filtered based on a value of **unknown** for the message type or GTP interface fields (**Monitor** > **Logs** > **GTP**). + +## PAN-90096 + +Fixed an issue where Threat logs recorded incorrect IMSI values for GTP packets when you enabled **Packet Capture** in Vulnerability Protection profiles (**Objects** > **Security Profiles** > **Vulnerability Protection** > **** > **Rules**). + +## PAN-88461 + +Fixed an issue on PA-3050 and PA-3060 firewalls in an HA active/passive configuration with link state pass-through enabled in virtual wire (vwire) where the Aggregate Ethernet (AE) interface communication failed during an HA failover event. + +## PAN-84292 + +Fixed an issue on a firewall where the (`show system state browser`) command window displayed live traffic values toggle between zero and other incorrect values. diff --git a/web/data/issues/PAN-OS/addressed/8.1.7_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.7_2026-04-01.md new file mode 100644 index 0000000..3da4707 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.7_2026-04-01.md @@ -0,0 +1,349 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.7 +--- + +## WF500-4093 + +Fixed an issue on a WF-500 appliance cluster where a firewall failed to join the cluster with a large data set of previously processed files. + +## PAN-113536 + +Fixed an issue where the automatic refresh of external dynamic lists (EDLs) did not update the URL or Domain EDLs. + +## PAN-112540 + +Fixed an issue on a VM-Series firewall where traffic stopped processing and resumed processing only after the firewall was restarted. + +## PAN-112428 + +```caveat +Panorama™ running PAN-OS® 8.1.6 only +``` + +Fixed an intermittent issue where autocommits failed and Panorama stopped displaying device groups when managing a WildFire® appliance running PAN-OS 8.1.5 or an earlier PAN-OS 8.1 release. + +## PAN-112305 + +Fixed an issue where source URLs (**Objects** > **External Dynamic Lists** > **** > **Create List** > **Source URL**), which contained double escape characters caused external dynamic list entries to display incorrect values in the policies. + +## PAN-112098 + +Fixed an intermittent issue on a firewall where outbound traffic failed with an error message: (`proxy decrypt failure`) when configured with HTTP Header Insertion (**Objects** > **Security Profiles** > **URL Filtering** > **** > **HTTP Header Insertion**). + +## PAN-111866 + +Fixed an issue where the push scope selection on the Panorama web interface displayed incorrectly even though the commit scope displayed as expected. This issue occurred when one administrator made configuration changes to separate device groups or templates that affected multiple firewalls and a different administrator attempted to push those changes. + +## PAN-111817 + +Fixed an intermittent issue on Panorama M-Series and virtual appliances where elastic search queries to Cortex Data Lake did not display logs. + +## PAN-111638 + +Fixed an issue where the external dynamic list did not update after a scheduled refresh of the list. + +## PAN-111593 + +```caveat +PA-3200 Series and PA-5200 Series firewalls only +``` + +Fixed an issue where a firewall dropped generic routing encapsulation (GRE) version 1 traffic. + +## PAN-110526 + +Fixed an issue where Captive Portal authentication required two log-in attempts when the authentication sequence was configured as an authentication profile. + +## PAN-110341 + +Fixed an issue where the firewall sent RIP updates more frequently than expected. + +## PAN-110293 + +Fixed an issue where GTP-U traffic dropped when the GTP tunnel endpoint ID (TEID) was not updated correctly during a GTP-C update. + +## PAN-110262 + +Fixed an issue on VM-Series firewalls Dynamic Address Groups did not display all the tags and labels for registered IPs. + +## PAN-109668 + +A security related fix was made to limit the amount of information returned from an API call error message. + +## PAN-109506 + +Fixed an issue where a process (useridd) stopped responding when the firewall received excessive Security Assertion Markup Language (SAML) requests received. + +## PAN-109336 + +```caveat +PA-500 and PA-800 Series firewalls only +``` + +Fixed an issue where commits failed after you imported a device state from Panorama the template configuration referenced Bidirectional Forwarding Detection (BFD). + +## PAN-109187 + +Fixed an issue where an administrator with a custom configuration role could not export reports. + +## PAN-109096 + +Fixed an issue where the firewall did not remove the 4-Byte AS Format number when **Remove Private AS** was enabled. + +## PAN-109003 + +Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) stopped responding during a local commit. + +## PAN-108990 + +Fixed an intermittent issue on a firewall where configuring **Force Template Values** (**Network** > **Interfaces** > **Commit** > **Push to Devices** > **Templates**) deleted the zone assigned to an interface. + +## PAN-108642 + +Fixed an issue where P2MP OSPF static neighbor did not display in the run-time neighbor table. + +## PAN-108542 + +Fixed an issue where the DHCP client interface was configured with an incorrect subnet mask value instead of the value provided by DHCP option 1. + +## PAN-108374 + +Fixed an issue on GlobalProtect™ where you were unable to authenticate when the domain name included the ampersand ( `&` ) character. + +## PAN-108123 + +Fixed an issue where applications took longer than expected to load when accessed through a Clientless VPN. + +## PAN-107989 + +Fixed an issue where the Strict IP Address Check incorrectly triggered when you enabled ECMP (**Network >Virtual Routers** > **Add** > **Router settings** > **ECMP**). + +## PAN-107922 + +Fixed an issue on a VM-Series firewall where packet sizes more than 1,500 bytes caused the firewall to stop transmitting and receiving packets. + +## PAN-107848 + +Fixed an issue where commits failed after a BGP aggregate route configuration modification. + +## PAN-107729 + +Fixed an issue on a VM-Series firewall where the PCI-PT interface did not receive VLAN tagged traffic after a system boot up. + +## PAN-107659 + +```caveat +PA-5000 Series firewalls only +``` + +Fixed an issue where extra byte (1 to 7) padding were appended to the initial SYN and UDP packets, which caused the server to stop responding. + +## PAN-107636 + +```caveat +Panorama M-Series and virtual appliances only +``` + +Fixed a rare issue where the web interface did not display new logs as expected because Elasticsearch (ES) stopped working when the Raid drives reached maximum capacity and the purge script to remove old ES indices failed to execute and make room for new indices. However, this issue also resulted in creation of new ES indices that were empty because the appliance could not read or write to them. With this fix, old indices are purged as expected; however, empty ES indices created before you upgraded to this release with this fix are not removed as expected (see [known issue PAN-114041](/content/techdocs/en_US/pan-os/8-1/pan-os-release-notes/pan-os-8-1-release-information/known-issues/known-issues-related-to-pan-os-8-1-releases.html#id1787F0E08SZ_id6f06b6f6-f9fb-4b15-a7f2-e0a9a42e1032)). + +## PAN-107607 + +Fixed an issue where the `test security-policy-match` XML API command returned invalid XML responses. + +## PAN-107240 + +Fixed an issue where you were unable to retrieve the external dynamic list for URLs that included the ampersand ( `&` ) character in the URL string. + +## PAN-107120 + +Fixed an intermittent issue on a firewall where the (all_pktproc) stopped responding and caused the dataplane to restart. + +## PAN-107006 + +Fixed an issue where you were unable to search for service objects by destination port numbers. + +## PAN-106963 + +Fixed an issue where the firewall did not display the full URL information in the URL Filtering log (**Monitor** > **URL Filtering**) after a (“ ’\r’ “) return character. + +## PAN-106922 + +A security-related fix was made to address a denial of service (DoS) vulnerability in PAN-OS SNMP (CVE-2018-18065 / PAN-SA-2019-0007). + +## PAN-106865 + +Fixed an issue where DNS proxy memory leaks occurred during the FQDN refresh process. + +## PAN-106857 + +Fixed an issue where the dataplane restarted due to an internal path monitoring failure caused by large SSL decrypted file transfer sessions. + +## PAN-106724 + +Fixed an intermittent issue on a firewall where the log receiver leaked memory after 24 hours of runtime, which caused the firewall to stop responding. + +## PAN-106548 + +Fixed an issue where MIB attributes caused MIB compilation failures when using a third-party compiler. + +## PAN-106426 + +Fixed an issue where GlobalProtect did not authenticate and displayed the following error message: `search failed 32`. + +## PAN-106356 + +Fixed an issue where you could not log in to GlobalProtect from a mobile device when the mobile ID contained a hyphen (`-`) character in the mobile ID string. + +## PAN-106274 + +Fixed an issue on a firewall where a Layer 2 interface that contained a VLAN sub-interface in conjunction with policy based forwarding (PBF) caused the firewall to forward the return traffic to the incorrect web interface. + +## PAN-105966 + +A security-related fix was made to address the Linux Kernel Local Privilege Escalation vulnerability (CVE-2018-14634 / PAN-SA-2019-0006). + +## PAN-105849 + +A security-related fix was made to address an issue with the `wf_curl.log` file in WF-500 appliances (WildFire). + +## PAN-105792 + +Fixed an issue where NetFlow server profile traffic did not route over IPSec tunnels when the service route was configured to use the dataplane interface. + +## PAN-105747 + +Fixed an issue where correlated events forwarded as email alerts displayed the incorrect date and time. + +## PAN-105684 + +Fixed an issue on a firewall in a high availability (HA) active/passive configuration where OSPF and BGP running on an Aggregate Ethernet (AE) interface with LACP enabled took longer than expected to restart after a failover. + +## PAN-104866 + +Fixed an issue on a VM-Series firewall where the dataplane interface continuously flapped when **PCI passthrough** was enabled with DPDK. + +## PAN-104738 + +Fixed an intermittent issue where octet values were incorrect for random flows in the NetFlow traffic. + +## PAN-104466 + +Fixed an issue on a VM-50 firewall where an out-of-memory event caused the firewall to restart. + +## PAN-104354 + +Fixed an issue in an HA active/passive configuration where the passive firewall ran a configuration out-of-sync after a restart. + +## PAN-104263 + +Fixed an issue where the real-time clock (RTC) battery voltage exceeded the maximum threshold value. + +## PAN-104078 + +Fixed an issue where BGP conditional advertisements did not respond, the BGP conditional advertisements did not match the suppress condition policy even when the prefix in the non-exist filter condition matched. + +## PAN-103857 + +Fixed an issue in an HA active/passive configuration where a suspended firewall processed traffic. + +## PAN-103497 + +Fixed an issue on PA-3200 Series firewalls where an SNMP OID (sysObjectID) reported the incorrect model (for example, PA-2020 instead of PA-3260). + +## PAN-103285 + +Fixed an issue where an API call (`show system disk details`), responded with the following error message: `An error occurred. See dagger.log for information`. + +## PAN-103225 + +Fixed an issue on Panorama M-Series and virtual appliances where the Task Manager did not display progress after you pushed a configuration to a firewall. + +## PAN-103140 + +Fixed an issue where a newly deployed VM-Series firewall in the VMware NSX environment did not display on the summary web interface (**Panorama** > **Summary**) after a partial commit. + +## PAN-103023 + +Fixed an intermittent issue where a job type (content) caused a firewall configuration failure and the firewall to stop responding. + +## PAN-102745 + +Fixed an intermittent issue on a firewall where a commit and FQDN refresh took longer than expected. + +## PAN-102526 + +Fixed an issue on Panorama M-Series and virtual appliances where disk quota edits failed and resulted in the following error message: `quota-settings -> disk-quota is invalid`. + +## PAN-101527 + +Fixed an issue on a PA-5200 Series firewall where enhanced small form-factor pluggable (SFP+) ports were unable to detect link-fault events on the transmission side. + +## PAN-101451 + +Fixed an issue where SNMP queries displayed incorrect values. + +## PAN-101365 + +Fixed an intermittent issue where the session ID did not clear when the session ID was set to 0. + +## PAN-101341 + +Fixed an issue where administrators configured with **Device Group** and **Template Admin** type were unable to perform a global search and returned the following message: `Unauthorized request`. + +## PAN-101224 + +Fixed an intermittent issue on VM-Series firewalls in an AWS environment where packets were dropped due to a longer than expected delay in transmission. + +## PAN-101068 + +Fixed an issue where the object identifier (OID) `ifAdminStatus` incorrectly displayed "up" when it was configured to be configured "down." + +## PAN-100761 + +A security-related fix was made to address a development configuration file issue. + +## PAN-100408 + +Fixed an issue where the IPv6 flow label was set to 0 when decryption was configured, which caused the firewall to drop IPv6 traffic during the SSL handshake. + +## PAN-98420 + +Fixed an issue on Panorama M-Series and virtual appliances where TCP port 28 was accessible on management plane. + +## PAN-98128 + +Fixed an issue where SYN-ACK packets with low time-to-live (TTL) values were sent, which caused a connection failure. + +## PAN-97385 + +An enhancement was made to enable you to monitor connections between a firewall and Cortex Data Lake on the web interface. + +## PAN-96344 + +Fixed an issue on a firewall where TCP reset packets were sent even after you set the vulnerability profile action to drop the packets. + +## PAN-96038 + +```caveat +PA-200 , PA-220, and PA-220R firewalls only +``` + +Fixed an issue with the Ethernet driver that caused the firewall to reboot when experiencing heavy broadcast traffic on the management interface. + +## PAN-95034 + +Fixed an issue where a firewall stopped responding when a NAT Dynamic IP and Port (DIPP) was configured as a NAT dynamic IP fallback. + +## PAN-94342 + +Fixed an issue where the GlobalProtect Gateway host information profile (HIP) notification operation failed to execute and returned the following message: `GP-EX-GW-21 -> hip-notification - > win-fw-is-not-enable -> not-match-message -> message is invalid`. + +## PAN-84670 + +Fixed an issue where firewalls that were not configured to decrypt HTTPS services and applications traffic allowed users without valid authentication timestamps to access those resources regardless of Authentication Policy settings. To prevent such access, either configure the firewall to decrypt traffic or run the `debug device-server cp-deny-encrypted on` command and execute the `commit force` CLI command (this command will persist across reboots). + +## PAN-82421 + +Fixed an issue where the new connection did not get established after you changed the IP address of a log collector. diff --git a/web/data/issues/PAN-OS/addressed/8.1.8-h5_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.8-h5_2026-04-01.md new file mode 100644 index 0000000..923ce89 --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.8-h5_2026-04-01.md @@ -0,0 +1,17 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.8-h5 +--- + +## PAN-119745 + +A security-related fix was made to address the Netflix Linux kernel TCP SACK vulnerability ([PAN-SA-2019-0013](https://securityadvisories.paloaltonetworks.com/Home/Detail/151) / CVE-2019-11477,CVE-2019-11478,CVE-2019-11479, and CVE-2019-5599). + +## PAN-118869 + +A security-related fix was made to address an issue where the php-debug log incorrectly displayed non-sanitized data ([PAN-SA-2019-0019](https://securityadvisories.paloaltonetworks.com/Home/Detail/157) / CVE-2019-1575). + +## PAN-107239 + +A security-related fix was made to address cleartext passwords and keys that were visible in the logs for XML API calls ([PAN-SA-2019-0019](https://securityadvisories.paloaltonetworks.com/Home/Detail/157) / CVE-2019-1575). diff --git a/web/data/issues/PAN-OS/addressed/8.1.8_2026-04-01.md b/web/data/issues/PAN-OS/addressed/8.1.8_2026-04-01.md new file mode 100644 index 0000000..3e67c2b --- /dev/null +++ b/web/data/issues/PAN-OS/addressed/8.1.8_2026-04-01.md @@ -0,0 +1,509 @@ +--- +type: Addressed +product: PAN-OS +version: 8.1.8 +--- + +## WF500-5023 + +Fixed an issue on WF-500 appliances where the cluster service took longer than expected to start due to a large number of queued sample data. + +## WF500-4974 + +Fixed an issue on WF-500 appliances where the static analysis results displayed in the PDF report but did not display in the WildFire® analysis summary of the web interface. + +## WF500-4844 + +Fixed an issue on WildFire appliance clusters where the passive-controller responded with the incorrect Common Name (CN) in the certificate, which caused the registration to fail. + +## WF500-4838 + +Fixed an intermittent issue on a WF-500 appliance where WildFire reports took longer than expected to generate, which caused the task to automatically timeout. + +## WF500-4785 + +Fixed a rare issue on WF-500 appliances where the firewall did not respond after you upgraded the appliance from a PAN-OS® 8.0.1 release to a PAN-OS 8.0.10 or later release. With this fix, you can run the new `debug software raid fixup auto` CLI command to recover the RAID controller. + +## WF500-4784 + +Fixed an issue on a WF-500 appliance where during a reboot, the following error message displayed: `FATAL: module nbd not found`. + +## WF500-4743 + +Fixed an intermittent issue on a WF-500 appliance where the CLI command `debug wildfire reset global-database fix` stopped responding. + +## PAN-116316 + +Fixed an issue where RTP and RTCP predict sessions failed, which caused RTSP based video streaming to stop processing. + +## PAN-116084 + +Fixed a file descriptor issue that caused an interface on a VM-Series firewall on Azure to stop receiving traffic. + +## PAN-114984 + +Fixed OpenSSL vulnerability CVE-2019-1559, see [PAN-SA-2019-0039](https://securityadvisories.paloaltonetworks.com/Home/Detail/202) for details. + +## PAN-114403 + +Fixed an issue on Panorama™ M-Series and virtual appliances where serial numbers for deployed firewalls did not display in the web interface with the exception of GlobalProtect™ cloud service firewalls. + +## PAN-114181 + +Fixed an issue where the firewall incorrectly triggered Reverse Path Forwarding (RPF), which caused packet leaks. + +## PAN-113692 + +Fixed an intermittent issue on a firewall in a high availability (HA) active/passive configuration where five minutes after a failover test IP routes disappeared, which caused traffic interruptions. + +## PAN-113446 + +Fixed an issue where the firewall unintentionally generated the following system log: `Installed content package WildFire is newer than available package, skipping,` when you checked for WildFire updates. + +## PAN-112815 + +Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) did not respond to the alternate user attribute (**Device** > **User Identification** > **Group Mapping Settings** > **** > **User and Group Attributes**) on the passive firewall during a restart. + +## PAN-112814 + +Fixed an issue where H.323-based calls lost audio because the predicted H.245 session was not converted to Active status, which caused the firewall to drop the H.245 traffic. + +## PAN-112729 + +Fixed an issue on Panorama M-Series and virtual appliances where Decrypted Sessions Info (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **** > **Sessions**) did not display as expected for VM-Series firewalls. + +## PAN-112445 + +Fixed an issue on a firewall in an HA active/passive configuration where a race condition caused the firewall to stop responding after an HA1 link flap. + +## PAN-112194 + +Fixed an issue where packet buffers did not release GlobalProtect clientless VPN packets, which caused the firewall to stop responding. + +## PAN-112187 + +Fixed an issue where a process (report_gen) ran out-of-memory, which caused the dataplane to restart. + +## PAN-111897 + +Fixed an issue where the tags were not set on OSPFv3 routes redistributed to BGP-3. + +## PAN-111844 + +```caveat +VM-50 and VM-50 Lite firewalls only +``` + +Fixed a rare out-of-memory (OOM) condition. + +## PAN-111822 + +```caveat +PA-3200, PA-5200, and PA-7000 Series firewalls only +``` + +Fixed an intermittent issue on a firewall configured with policy-based forwarding (PBF) and symmetric return, where traffic dropped because the ARP table did not get updated. + +## PAN-111679 + +Fixed an issue where URL filtering profiles were being incorrectly applied to security policies during a commit. + +## PAN-111653 + +Fixed an issue on PA-7000 Series firewalls where an internal packet buffer leak caused heartbeat failures. + +## PAN-111052 + +Fixed an issue where a firewall silently dropped TCP packets when you enabled the Antivirus profile while the software deterministic finite automation (DFA) option is disabled (DFA is disabled by default). + +## PAN-111048 + +Fixed an issue where the `show object dynamic address group` XML API command returned an invalid error message: `You must specify a valid Device Group`. + +## PAN-110996 + +Fixed an issue where the dataplane stopped responding due to an incorrectly calculated offset when you configured **Exclude video traffic from the tunnel** (**Network** > **GlobalProtect** > **Gateways** > **** > **Agent** > **Video Traffic**). + +## PAN-110873 + +Fixed an issue where member interfaces of the aggregate interface did not display on web interface (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **** > **Interfaces**). + +## PAN-110796 + +Fixed an issue on PA-3200 and PA-5200 Series firewalls where an erroneous dataplane error (`power status is bad, shutting system down`) caused the firewall to shutdown. + +## PAN-110758 + +Fixed an issue on Panorama M-Series and virtual appliances where you were unable to configure the firewall to disable the portal log-in page. + +## PAN-110628 + +Fixed an issue where user groups were deleted from the Group Include List (**Device** > **User identification** > **Group Mapping Settings** > **** > **Group Include List**) if you changed the LDAP server profile account password. + +## PAN-110441 + +```caveat +PA-5200 Series firewall only +``` + +Fixed an intermittent issue where the internal path monitoring failed, which caused the firewall to unexpectedly restart. + +## PAN-110390 + +Fixed an issue on PA-7000 Series firewalls where invalid filters caused the device management server to stop responding when you generated a database (DB) report from a remote firewall. + +## PAN-110336 + +```caveat +PA-3000, PA-3200, PA-5000, PA-5200, and PA-7000 Series firewalls only +``` + +Fixed an issue where a process (mpreplay) restarted and caused the offload traffic to drop. + +## PAN-110273 + +Fixed an issue where you were unable to establish OSPF neighborship when an OSPF routing protocol was configured with MD5 authentication and one of the firewalls was restarted. + +## PAN-109966 + +Fixed an issue where the content update threshold downloaded and installed an older content version after you manually installed a newer content version. + +## PAN-109954 + +Fixed an issue where a commit failed with an error message: `cluster is missing 'encryption'` when HA Traffic Encryption (**Panorama** > **Managed WildFire Clusters** > **** > **Communication**) was not configured and after upgrading from PAN-OS 8.0.12 to PAN-OS 8.1.4. + +## PAN-109944 + +Fixed an intermittent issue where a process (configd) restarted due to a race condition when generating custom reports. + +## PAN-109837 + +Fixed an issue where a race condition occurred when a configuration push and Netflow update occurred simultaneously, which caused the dataplane to restart. + +## PAN-109803 + +Fixed an issue where credential phishing prevention did not detect user or password phishing when passwords, which contained two discontiguous character spaces were used. + +## PAN-109759 + +Fixed an issue where the firewall did not generate a notification for the GlobalProtect client when the firewall denied unencrypted TLS sessions due to an authentication policy match. + +## PAN-109757 + +Fixed an issue on Panorama M-Series and virtual appliances where the management server stopped responding when the log collector disconnected and reconnected to Panorama. + +## PAN-109665 + +Fixed an issue where you were unable to disable the Graceful Restart (**Network** > **Virtual Routers** > **** > **BGP** > **Advanced**) configuration. + +## PAN-109619 + +Fixed an issue where a physical or Aggregate Ethernet (AE) Layer 3 configuration edit (**Network** > **Interfaces** > ****) removed the DHCP Client setting when it was configured in the subinterface. + +## PAN-109575 + +Fixed an issue where you were unable to configure more than one device certificate (**Device** > **Certificate Management** > **Certificates** > ****) with **Trusted Root CA**. + +## PAN-109344 + +Fixed an issue where service objects did not import into Panorama when you configured them identically but with different names. + +## PAN-109101 + +Fixed an issue where you were unable to override IKE Gateway configurations (**Network** > **IKE Gateways** > ****) in the template stack. However, with this fix, you still cannot override template stacks when you configure any value with "none." Additionally, to override the Local Identification, select **Authentication** in the pop-up dialogue. + +## PAN-108878 + +Fixed an issue where host traffic ICMP packets larger than 9,180 bytes dropped when you configured a jumbo frame with a maximum MTU value of 9,216 bytes and with the DF option enabled. + +## PAN-108846 + +Fixed an issue where a higher than expected rate of tunnel resolution packets occurred due to an internal loop, which caused a spike in dataplane CPU usage for firewalls that support distributed tunnel ownership. + +## PAN-108715 + +Fixed an issue where the firewall did not update the dataplane DNS cache after the management plane (MP) DNS entries expired, which caused evasion signatures to erroneously trigger a `Suspicious TLS/HTTP Evasion Found` event. + +## PAN-108620 + +Fixed an issue where Traps ESM (**Monitor** > **Traps ESM**) logs were sent to the Log Collector but did not display in the web interface. + +## PAN-108459 + +Fixed an issue where Network Activity (**ACC** > **Network Activity**) incorrectly displayed no session activity at random time points. + +## PAN-108409 + +Fixed an issue on a firewall in an HA active/passive configuration where scheduled dynamic updates pushed from Panorama to the managed firewalls failed. + +## PAN-108215 + +Fixed an issue where the `test security-policy-match` CLI command ignored `source-user` when matching security policies. + +## PAN-108164 + +Fixed an issue where a process (tund) caused the dataplane to restart during a commit. + +## PAN-107998 + +Fixed an issue where you could not log-in to GlobalProtect and resulted in the following error message: `The client certificate is invalid. Please contact your IT administrator`. + +## PAN-107662 + +Fixed an issue on a firewall in an HA active/active configuration where client-bound DHCPv6 packets dropped when you configured the firewall as a DHCPv6 relay agent. + +## PAN-107370 + +Fixed an issue where IPv6 traffic throughput reduced more than expected after you updated a static ND entry (**Network** > **Interfaces** > **** > **Advanced** > **ND Entries**) by moving the interface to a different virtual router. + +## PAN-107126 + +Fixed an issue where an SSL inbound session cache corruption caused a process (all_pktproc) to stop responding. + +## PAN-106950 + +Fixed an intermittent issue where authd CPU usage is higher than expected during RADIUS authentication. + +## PAN-106861 + +Fixed an issue where stale route entries remained in the FIB after the routes were removed from the routing table when you used a redistribution rule without a profile. + +## PAN-106783 + +Fixed an issue where after a SAML authentication an incorrect query was sent to the web browser. + +## PAN-106746 + +Fixed an issue where VoIP traffic dropped when policy-based forwarding (PBF) was configured as a rule. + +## PAN-106735 + +Fixed an issue where the firewall incorrectly set the FPGA, which caused the dataplane to stop responding. + +## PAN-106695 + +Fixed an issue on a firewall in an HA active/passive configuration where the Panorama management server enabled the administrator to clone a rule on the passive firewall. + +## PAN-106433 + +Fixed an issue where after you configured Packet Buffer Protection on a firewall, a process (all_pktproc) stopped responding. + +## PAN-106259 + +Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall reported a higher number of GlobalProtect user accounts than the active firewall. + +## PAN-106249 + +```caveat +PA-200, PA-220, and PA-800 Series firewalls only +``` + +Fixed an issue where the **Block IP List** option, which is not supported, displayed in the administrator role profile (**Device** > **Admin Role** > **Web UI**). + +## PAN-106069 + +Fixed an issue on a firewall in an HA active/active configuration where the iBGP peer default route did not get added to the routing table after a reboot of either firewall. + +## PAN-105925 + +Fixed an issue where the GlobalProtect Gateway web interface did not display the list of previous users. + +## PAN-105466 + +Fixed an issue where the **Allow matching usernames without domain** (**Device** > **User Identification** > **User-ID Agent Setup** > **Cache**) configuration did not respond without a domain when you used the PAN-OS XML API. + +## PAN-105397 + +Fixed an issue where a firewall incorrectly processed path monitoring, which originated from a NAT firewall on the same network segment. + +## PAN-105252 + +Fixed an intermittent issue on a firewall where dataplane CPU spikes occurred, which caused an LACP flap. + +## PAN-105086 + +Fixed an issue where the firewall incorrectly calculated the password expiry time for admin accounts, which caused Panorama to push locked user accounts. + +## PAN-104578 + +```caveat +PA-800 Series firewalls only +``` + +Fixed an issue on a firewall in an HA active/passive configuration where the HA failover took longer than expected. + +## PAN-104568 + +Fixed an issue where the firewall did not send emails when you configured the email gateway with an FQDN. + +## PAN-104274 + +Addressed an issue where in a slow network environment the firewall displayed an error message: `error on line 1 at column 1: document is empty` when you used an API call to fetch a license even when the auth code was successfully applied. Extremely slow networks may still see this issue. + +## PAN-104264 + +Fixed an issue where the Panorama management server stopped responding when you upgraded from PAN-OS 8.0.9 to PAN-OS 8.1.3. + +## PAN-104007 + +Fixed an issue where the WildFire signatures sent Windows Server Updates Services (WSUS) traffic when the virus identification was incorrectly enabled in the ms-sms app definition. + +## PAN-103863 + +Fixed an issue where the IPSec tunnel restart (**Network** > **IPSec Tunnels** > **IKE Info**) did not display properly on the web interface. + +## PAN-103844 + +Fixed an issue where Global Find incorrectly returned the query when there were more than one users or groups listed in the security rule. + +## PAN-103367 + +Fixed an issue where Detailed Log View (**Monitor** > **Traffic** > **Detailed Log View**) did not display the file blocking logs as expected. + +## PAN-103061 + +Fixed an issue where special characters contained in the comment field of the Ethernet Interface web interface caused a process (devsrvr) to stop responding. + +## PAN-102979 + +Fixed an issue where Dynamic Updates did not display expired threat prevention licenses when you tried to install an application from Panorama. + +## PAN-102595 + +Fixed an intermittent issue on a firewall in an HA active/active configuration where fragmented ICMP and UDP packets dropped from the packet transmission. + +## PAN-102532 + +Fixed an issue where the firewall used an expired certificate, which caused connecting to Cortex Data Lake to fail. + +## PAN-102327 + +Fixed an issue on PA-3200 Series firewalls in an HA active/passive configuration where the copper ports of passive firewall were active when the passive link state was set to **shutdown**. + +## PAN-102145 + +Fixed an issue where the API keys did not update after you changed the master key. + +## PAN-102029 + +Fixed an issue on a firewall where the DNS resolution routed through the dataplane and configured with a service route, stopped responding when the management interface was not configured. + +## PAN-101764 + +Fixed an issue where a process (slmgr) stopped responding during an auto-commit. + +## PAN-101391 + +Fixed an issue where the scheduled nightly custom report was not generated or emailed as expected. + +## PAN-101379 + +Fixed an issue where an invalid Captive Portal authentication policy was successfully pushed to managed firewalls, which caused autocommits to fail. + +## PAN-100832 + +Fixed an issue where, when you performed a Commit from Panorama to bring a firewall back to sync, the rule order displayed a random distribution instead of reflecting the order configured in Panorama. + +## PAN-100742 + +Fixed an issue on Panorama M-Series and virtual appliances where scheduled reports generated more than one DNS lookups, which caused inconsistent name resolutions for DNS deployments. + +## PAN-100693 + +Fixed an issue where you were unable to process Address Group match criteria when the match name included the double quotation ( " ) character. + +## PAN-99976 + +Fixed an issue where a process (pan_threatvault_reports) caused the elastic search script and another process (configd) to stop responding. + +## PAN-99707 + +Fixed an issue where the command-line interface (CLI) displayed an error message when you used a parenthesis character in a Global Protect External Gateway name. + +## PAN-99640 + +A security-related fix was made to address a denial of service (DoS) vulnerability in PAN-OS Linux Kernel (CVE-2017-8890). + +## PAN-99478 + +Fixed an issue where a daemon (authd) took longer than expected to fetch group mapping, which caused commits to take longer than expected. + +## PAN-99354 + +Fixed an issue where the firewall incorrectly denied URL access when the URL filtering profile was configured to alert. + +## PAN-98746 + +Fixed an issue where GlobalProtect clientless VPN did not get redirected to the application URL when you used Internet Explorer as a web browser. + +## PAN-98386 + +Fixed an issue where a security rule with an "Any" destination address did not shadow rules with IPv6 destination addresses when you performed a commit or configuration validation. + +## PAN-98107 + +Fixed an issue on PA-7000 Series firewalls where Encapsulating Security Payload (ESP) sequence numbers were reused when multiple proxy IDs were in use, which caused ESP traffic to drop while you conducted an ESP sequence check. + +## PAN-97953 + +Fixed an issue where Threats (**Monitor** > **Reports** > **Threat Reports** > **Threats**) did not display resolved Threat IDs to Threat/Content Names for disabled signatures as expected. + +## PAN-97862 + +Fixed an issue where an administrator with a custom configuration role could not export custom reports and returned the following error message: `Error enqueuing export job`. + +## PAN-97700 + +Fixed an issue where administrators could not view Managed Collectors (**Panorama** > **Managed Collectors**) web interface. + +## PAN-97488 + +Fixed an issue on Panorama M-Series and virtual appliances where the commit preview did not display as expected. + +## PAN-97288 + +Fixed an issue on GlobalProtect Clientless VPN where the URL gets truncated when you exclude the domain from the `rewrite exclude domain` list. + +## PAN-97187 + +Fixed an issue on VM-Series firewalls where a configuration commit failed due to a reversed bootstrapping process where the configuration was applied before the auth code. + +## PAN-96036 + +Fixed an issue on Panorama M-Series and virtual appliances where the Group Include List (**Device** > **User Identification** > **** > **Group Include List**) search function did not respond as expected. + +## PAN-95644 + +Fixed an issue on a firewall where the web interface did not display traffic and unified logs due to a race condition. + +## PAN-94475 + +```caveat +Panorama virtual appliances only +``` + +Improved a condition where a disk calculation error resulted in an erroneous opt/panlogs/ partition full condition and caused a process (CDB) to stop responding. + +## PAN-94161 + +Fixed an issue where the log collector mode did not display logs as expected after you rebooted Panorama. + +## PAN-92872 + +Fixed an intermittent issue where the firewall sent packets incorrectly to an outgoing interface. + +## PAN-92161 + +Fixed an issue where an internal power status reported as `abnormal` caused the firewall to shutdown. + +## PAN-92155 + +Fixed an issue where administrators were unable to configure an IP address using templates for HA2 (**Device** > **High Availability** > **Data Link (HA2)**) after setting the configuration to **IP** or **Ethernet** for Panorama management servers in an HA configuration. + +## PAN-81778 + +Fixed an issue where scheduled reports did not generate as expected due to a race condition. + +## PAN-79640 + +Fixed an issue where the firewall intermittently logged incorrect actions for WildFire submissions and reports. diff --git a/web/data/issues/PAN-OS/known/11.2.10_2026-03-16(1).md b/web/data/issues/PAN-OS/known/11.2.10_2026-03-16(1).md deleted file mode 100644 index ff27598..0000000 --- a/web/data/issues/PAN-OS/known/11.2.10_2026-03-16(1).md +++ /dev/null @@ -1,301 +0,0 @@ ---- -type: Known -product: PAN-OS -version: 11.2.10 ---- - -## WF500-6271 - -A WildFire cluster node that has been configured with an IPv6 management port might not display the signature status when using the following CLI: show wildfire global signature-status sha256 equal - -Workaround: Gracefully restart the affected Wildfire cluster nodes. - -## WF500-6259 - -When a WildFire cluster node configured as a server or worker node is rebooted, issuing the CLI command, global sample-status does not update the samples processed list on the active controller and non-server worker nodes. - -Workaround: Gracefully restart the affected WildFire active controller and passive controller in the cluster. - -## WF500-6270 - -The WildFire cluster server and worker nodes might disconnect from the Wildfire cluster management network, resulting in a notifier process exit on WildFire cluster controllers. - -Workaround: Gracefully restart the WildFire cluster node where the process exit occurred. - -## WF500-6222 - -When WildFire secure cluster communication is enabled using a custom DNS, the cluster formation might fail due to cluster management communication issues. - -Workaround: Do not configure a custom DNS when WildFire secure cluster communication is enabled. - -## WF500-6176 - -When Panorama is used to manage a WildFire cluster, switchover functionality for active and passive controller roles is not available. - -## PAN-308507 - -Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss. - -## PAN-308418 - -When Advanced DNS Security is enabled and experiences unusually high loads, DNS traffic sessions may be impacted, resulting in DNS resolution failures. Traffic logs for these sessions show an end-reason of resources-unavailable. - -Workaround: Disable Advanced DNS Security telemetry (DeviceSetupContent-IDAdvanced DNS Security and uncheck Telemetry Enable). - -## PAN-304756 - -After you disable the shared optimization feature in Panorama, ensure that you perform a full configuration push to all managed multi-vsys devices to re-establish a baseline. Failure to include every device group associated with the multi-vsys device during this push may result in incomplete or inconsistent configurations across virtual systems. - -## PAN-304576 - -Traffic interruption may occur when inspection of HTTP/2 traffic is enabled. - -Workaround: Disable HTTP/2 server push using the set deviceconfig setting http2 server-push no CLI command. - -## PAN-303959 - -Traffic that is incorrectly identified as unknown-tcp/unknown-udp eventually drops due to an App-ID resource limitation issue. - -## PAN-302927 - -After an upgrade, the Push to Devices window fails to populate the list of devices automatically. If you manually select devices by clicking Edit Selections, the OK button becomes unresponsive and fails to save or close the selection window. Additionally, clicking Cancel might incorrectly show the device list as empty while retaining the selections in the background. - -## PAN-297610 - -A firewall may become unresponsive after an upgrade due to the fsck command scanning drive partitions in parallel with the root partition, causing the process to take an extended amount of time. - -## PAN-295803 - -A configd memory leak occurs post commit (during Panorama connectivity check), potentially leading to OOM (out of memory condition) and device reboot. - -## PAN-295645 - -When a WildFire cluster is configured centrally using Panorama, it initiates a series of processes, including a software install and reboot, in an order that will leave the resulting WildFire cluster in an unusable state. - -## PAN-294179 - -On the Panorama Config Audit page, some commit versions might display incorrect or missing data. Fields such as, COMMITTED BY , COMMIT DATE , and OBJECT CHANGES might not be visible for some commit versions. Sometimes, commit versions can disappear after a refresh and the commit description field might display corrupted characters. - -## PAN-288525 - -When the Enterprise DLP data filtering profile is configured with a Block action and is used in conjunction with Advanced Threat Prevention, which is configured with an action of reset-both, reset-server, reset-client, or drop for the HTTP Command and Control detector, Dropbox file uploads that exceed the maximum configured file size action will fail. - -Workaround: Configure the Advanced Threat Prevention Inline Cloud analysis (ObjectsSecurity ProfilesAnti-Spyware) action for the HTTP Command and Control detector to alert. - -## PAN-285061 - -When Enterprise DLP is enabled, file uploads might unexpectedly fail when 100 continue response is received from the server during file uploads. - -## PAN-284700 - -File downloads for content encoded with zstd (Zstandard), such as specific content from box.com, fail when using Enterprise DLP because zstd decompression is not supported in PAN-OS. - -## PAN-283429 - -When you use custom certificates for the connection between Panorama and a log collector, the automated renewal for the predefined ElasticSearch certificates gets disrupted. - -Workaround: Remove the custom certificates before the ElasticSearch certificates expire. This allows the system to correctly identify and renew the predefined ElasticSearch certificates. After the renewal is complete, re-install the custom certificates. - -## PAN-278688 - -```caveat -PA-7500, PA-5500, and PA-3500 firewalls only -``` - -When DNS Security packet capture is enabled and a domain name has a length of 62 characters, the DNS Security threat log entry is not generated. On the affected platforms, this condition can also trigger a pan_task crash due to shared memory corruption. - -Workaround: Disable DNS Security packet capture in anti-spyware profiles (ObjectsSecurity ProfilesAnti-Spyware) and in the DNS Policies tab, set Packet Capture to disable. - -## PAN-273158 - -```caveat -PA-7000 Series firewalls only -``` - -Due to an incorrect configuration on the ASIC, receiving a mix of jumbo and non-jumbo packets may cause silent packet drops or application slowness. - -## PAN-260851 - -From the NGFW or Panorama CLI, you can override the existing application tag even if Disable Override is enabled for the application (ObjectsApplications) tag. - -## PAN-260212 - -When viewing Applications (ObjectsApplications), child App-IDs may be listed under the incorrect container App-ID. - -## PAN-259853 - -When the DHCP server is enabled for GlobalProtect, the commit error message is not properly displayed when Any is selected as the source interface in the service router configuration ( DeviceSetupServiceService Router Configuration). - -## PAN-259423 - -When the GlobalProtect DHCP feature is enabled with two primary DHCP servers on the GlobalProtect gateway, the gpsvc gets stuck during renewal and after HA failover. - -## PAN-254236 - -TLSv1.3 hybridized Kyber support in the latest versions of Chrome and Edge browsers results in dropped Client Hello packets when SSL/TLS handshake inspection is enabled. - -Workaround: Disable SSL/TLS handshake inspection. - -## PAN-254108 - -when upgrading or downgrading a Panorama management server (PanoramaSoftware), managed device (PanoramaDevice DeploymentSoftware), or standalone firewall (DeviceSoftware), Base Releases and Preferred Releases settings are checked (enabled) by default and cause no PAN-OS software images to display. - -Workaround: Uncheck (disable) Base Releases or Preferred Releases to display either the available base PAN-OS or preferred PAN-OS releases available to download and install. - -## PAN-253963 - -The auto commit job may take longer than expected to complete when the Panorama management server is in Panorama or Log Collector mode. - -## PAN-252661 - -If you change the service route of gp-ip-mgmt in Device > Setup > Services > Service Features > gp-ip-mgmt and Commit, the change won’t take effect. gp-ip-mgmt continues to use the last committed service route. - -Workaround: After you change the service route interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or gateway, click OK to save the configuration, and Commit the changes. This commit will include the service route change. - -## PAN-250246 - -Panorama and the firewall display inconsistent IP addresses for dynamic address group members after manually syncing. - -## PAN-250062 - -Device telemetry might fail at configured intervals due to bundle generation issues. - -## PAN-248836 - -The Advanced DNS Security trial license and trial license information cannot be activated and viewed, respectively, on a managed firewall (with expired or active status) from Panorama. These tasks can only be performed on the firewall. - -## PAN-247728 - -When Advanced Routing is enabled, IP multicast is not supported. An upcoming version will provide support for this feature. Customers who have multicast configured or who plan to deploy multicast routing should not upgrade to 11.2.0. Additionally, when Advanced Routing is enabled, the BGP dampening configuration isn't applied to any peers or peer group; the configuration is preserved but has no effect on BGP. Customers can use BGP even if they have applied a Dampening profile to a specific set of peers. The issue doesn't affect any other BGP features. - -## PAN-241994 - -The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards. Palo Alto Networks recommends that you upgrade your ESXi version if it is less than 6.7 U2. For more information, see the compatibility matrix. - -## PAN-239612 - -When the firewall is running PAN-OS 11.2.0 and Advanced Routing is enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay agent doesn't work. - -## PAN-237106 - -LSVPN satellite certificates may be generated with serial numbers exceeding 40 hexadecimal characters. This causes certificate revocation and deletion operations to fail with the following error messages: - -db-serialno can be at most 40 characters - -db-serialno is invalid - -To resolve this issue, use the following CLI commands with the LSVPN satellite serial number to manually delete or revoke the affected certificates: - -Delete certificate information:delete sslmgr-store certificate-info portal name serialno - -Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal serialno - -## PAN-236649 - -If you change the configuration of a firewall acting as a PPPoEv4 or PPPoEv6 client, old routes from the Forwarding Information Base (FIB) and route table for an inherited configuration with dynamic-identifier or client remain visible. Old routes also remain visible for an inherited interface when you execute the CLI command, show interface all. - -Workaround: Unconfigure and configure the Inherited Interface. - -## PAN-234015 - -The X-Forwarded-For (XFF) value is not displayed in traffic logs. - -## PAN-207442 - -For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the active-primary HA peer configuration sync to the secondary-passive HA peer may fail. When the config sync fails, the job Results is Successful (Tasks), however the sync status on the Dashboard displays as Out of Sync for both HA peers. - -Workaround: Perform a local commit on the active-primary HA peer and then synchronize the HA configuration. - -Log in to the Panorama web interface of the active-primary HA peer. - -Log in to the Panorama web interface of the active-primary HA peer. - -Select Commit and Commit to Panorama. - -Select Commit and Commit to Panorama. - -In the active-primary HA peer Dashboard, click Sync to Peer in the High Availability widget. - -In the active-primary HA peer Dashboard, click Sync to Peer in the High Availability widget. - -## PAN-206909 - -The Dedicated Log Collector is unable to reconnect to the Panorama management server if the configd process crashes. This results in the Dedicated Log Collector losing connectivity to Panorama despite the managed collector connection Status (PanoramaManaged Collector) displaying connected and the managed colletor Health status displaying as healthy. - -This results in the local Panorama config and system logs not being forwarded to the Dedicated Log Collector. Firewall log forwarding to the disconnected Dedicated Log Collector is not impacted. - -Workaround: Restart the mgmtsrvr process on the Dedicated Log Collector. - -Log in to the Dedicated Log Collector CLI. - -Log in to the Dedicated Log Collector CLI. - -Confirm the Dedicated Log Collector is disconnected from Panorama.admin> show panorama-status Verify the Connected status is no. - -Confirm the Dedicated Log Collector is disconnected from Panorama. - -admin> show panorama-status Verify the Connected status is no. - -admin> show panorama-status - -admin> show panorama-status - -Verify the Connected status is no. - -Restart the mgmtsrvr process.admin> debug software restart process management-server - -Restart the mgmtsrvr process. - -admin> debug software restart process management-server - -admin> debug software restart process management-server - -admin> debug software restart process management-server - -## PAN-197588 - -The PAN-OS ACC (Application Command Center) does not display a widget detailing statistics and data associated with vulnerability exploits that have been detected using inline cloud analysis. - -## PAN-197419 - -```caveat -PA-1400 Series firewalls only -``` - -In NetworkInterfaceEthernet, the power over Ethernet (PoE) ports do not display a Tag value. - -## PAN-196758 - -On the Panorama management server, pushing a configuration change to firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP configurations for SD-WAN as being edited or deleted despite no edits or deletions being made when you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections). - -## PAN-195968 - -```caveat -PA-1400 Series firewalls only -``` - -When using the CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI prints an error depending on whether an interface type was selected on the non-PoE port or not. If an interface type, such as tap, Layer 2, or virtual wire, was selected before PoE was configured, the error message will not include the interface name (eg. ethernet1/4). If an interface type was not selected before PoE was configured, the error message will include the interface name. - -## PAN-187685 - -On the Panorama management server, the Template Status displays no synchronization status (PanoramaManaged DevicesSummary) after a bootstrapped firewall is successfully added to Panorama. - -Workaround: After the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and select CommitPush to Devices. - -## PAN-187407 - -The configured Advanced Threat Prevention inline cloud analysis action for a given model might not be honored under the following condition: If the firewall is set to Hold client request for category lookup and the action set to Reset-Both and the URL cache has been cleared, the first request for inline cloud analysis will be bypassed. - -## PAN-184406 - -Using the CLI to add a RAID disk pair to an M-700 appliance causes the dmdb process to crash. - -Workaround: Contact customer support to stop the dmdb process before adding a RAID disk pair to a M-700 appliance. - -## PAN-183404 - -Static IP addresses are not recognized when "and" operators are used with IP CIDR range. - -## PAN-181933 - -If you use multiple log forwarding cards (LFCs) on the PA-7000 series, all of the cards may not receive all of the updates and the mappings for the clients may become out of sync, which causes the firewall to not correctly populate the Source User column in the session logs. diff --git a/web/data/issues/PAN-OS/known/11.2.10_2026-03-16.md b/web/data/issues/PAN-OS/known/11.2.10_2026-03-16.md index d318d2a..ff27598 100644 --- a/web/data/issues/PAN-OS/known/11.2.10_2026-03-16.md +++ b/web/data/issues/PAN-OS/known/11.2.10_2026-03-16.md @@ -4,6 +4,34 @@ product: PAN-OS version: 11.2.10 --- +## WF500-6271 + +A WildFire cluster node that has been configured with an IPv6 management port might not display the signature status when using the following CLI: show wildfire global signature-status sha256 equal + +Workaround: Gracefully restart the affected Wildfire cluster nodes. + +## WF500-6259 + +When a WildFire cluster node configured as a server or worker node is rebooted, issuing the CLI command, global sample-status does not update the samples processed list on the active controller and non-server worker nodes. + +Workaround: Gracefully restart the affected WildFire active controller and passive controller in the cluster. + +## WF500-6270 + +The WildFire cluster server and worker nodes might disconnect from the Wildfire cluster management network, resulting in a notifier process exit on WildFire cluster controllers. + +Workaround: Gracefully restart the WildFire cluster node where the process exit occurred. + +## WF500-6222 + +When WildFire secure cluster communication is enabled using a custom DNS, the cluster formation might fail due to cluster management communication issues. + +Workaround: Do not configure a custom DNS when WildFire secure cluster communication is enabled. + +## WF500-6176 + +When Panorama is used to manage a WildFire cluster, switchover functionality for active and passive controller roles is not available. + ## PAN-308507 Strata Logging Service (SLS) log-forwarding streams intermittently show as inactive. When checking the status of log-forwarding connections, one or more streams are reported as inactive. Restarting the log-receiver process temporarily resolves the issue, but the streams become inactive again after approximately 1-2 hours. This intermittent inactivity results in log loss. diff --git a/web/data/products.json b/web/data/products.json index 8abeec8..1e3ef3c 100644 --- a/web/data/products.json +++ b/web/data/products.json @@ -535,26 +535,45 @@ "8.1.2_2026-03-16.md", "8.1.3_2026-03-16.md", "8.1.4_2026-03-16.md", + "8.1.4-h2_2026-04-01.md", "8.1.5_2026-03-16.md", + "8.1.6_2026-04-01.md", "8.1.6-h2_2026-03-16.md", + "8.1.7_2026-04-01.md", + "8.1.8_2026-04-01.md", + "8.1.8-h5-h2_2026-04-01.md", "8.1.9_2026-03-16.md", "8.1.9-h4_2026-03-16.md", "8.1.10_2026-03-16.md", + "8.1.11_2026-04-01.md", "8.1.12_2026-03-16.md", "8.1.13_2026-03-16.md", + "8.1.14_2026-04-01.md", "8.1.14-h2_2026-03-16.md", "8.1.15_2026-03-16.md", "8.1.15-h3_2026-03-16.md", + "8.1.16_2026-04-01.md", "8.1.17_2026-03-16.md", + "8.1.18_2026-04-01.md", "8.1.19_2026-03-16.md", "8.1.20_2026-03-16.md", + "8.1.20-h1_2026-04-01.md", "8.1.21_2026-03-16.md", + "8.1.21-h1_2026-04-01.md", + "8.1.21-h2_2026-04-01.md", "8.1.21-h3_2026-03-16.md", + "8.1.22_2026-04-01.md", + "8.1.23_2026-04-01.md", "8.1.23-h1_2026-03-16.md", + "8.1.24_2026-04-01.md", + "8.1.24-h1_2026-04-01.md", + "8.1.24-h2_2026-04-01.md", "8.1.25_2026-03-16.md", "8.1.25-h1_2026-03-16.md", + "8.1.25-h2_2026-04-01.md", "8.1.25-h3_2026-03-16.md", "8.1.25.2_2026-03-16.md", + "8.1.26_2026-04-01.md", "8.1.26-h1_2026-03-16.md" ], "known": []