--- type: Addressed product: PAN-OS version: 10.2.16-h1 --- ## PAN-290996 Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections Per Second) per vsys on firewalls after upgrading to PAN-OS 11.1.6-h3, even when active connections were present. ## PAN-290803 ```caveat VM-Series firewalls on Microsoft Azure environments only ``` Fixed an issue where firewall failed to bootstrap with a custom image, and VM-Series plugin information was not displayed in the system information. ## PAN-290088 Fixed an issue where a memory leak occurred related to the configd process when pushing configurations from Panorama to a firewall. This occurred when the configurations contained shared policy rules. ## PAN-289763 ```caveat PA-5400f firewalls only ``` Fixed an issue where SD-WAN SaaS monitoring did not work with URL monitoring. ## PAN-288929 Fixed an issue where the preferred_wnd value provided by CTD (Content Threat Detection) was disregarded due to TCP bandwidth estimation, which prevented the window from closing. ## PAN-288363 Fixed an issue where the MIB ID returned an incorrect value via SNMP. ## PAN-287818 Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation _restore_timeout not initiating when the accumulation session_init failed. ## PAN-287601 Fixed an issue on Panorama where commits took longer than expected. ## PAN-287056 Fixed an issue where BGP export policy rules with next-hop matching failed to block the advertisement of static routes, and the firewall incorrectly matched the egress interface IP address instead of the original next-hop IP address of the static route, which caused the deny rule to fail. ## PAN-287035 Fixed an issue where, when an application stopped responding, a large file was created in the /opt/panlogs directory, which caused the partition to fill up. ## PAN-287023 Fixed an issue where a large number of logs caused the logrcvr process to stop responding. ## PAN-287002 A fix was made to address [CVE-2025-0133](https://security.paloaltonetworks.com/CVE-2025-0133). ## PAN-286306 Fixed an issue where, when getting transceiver information from ESCC for SFP 25G modules, the transceiver code was incorrectly updated with Unknown instead of 25GBase-SR. ## PAN-284744 A fix was made to address [CVE-2025-4229](https://security.paloaltonetworks.com/CVE-2025-4229). ## PAN-278288 Fixed an issue where IPv6 BGP peering established between virtual routers even without dataplane connectivity. This occurred because the firewall used the kernel for lookups instead of the dataplane. ## PAN-268787 Fixed an issue where users were unable to log in to Panorama and the following error message was displayed: Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of devices.