<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282927#M47162</link>
    <description>&lt;P&gt;You've made some valid points here but are begining to dilute them.&lt;/P&gt;
&lt;P&gt;Please check your facts, we average 1 major release a year R81.20 was released back in 2022.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.checkpoint.com/support-services/support-life-cycle-policy/#software-support" target="_blank"&gt;https://www.checkpoint.com/support-services/support-life-cycle-policy/#software-support&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;3900 also wasn't the first special case of an appliance specific version as warranted by hardware / linux kernel requirements etc.&lt;/P&gt;</description>
    <pubDate>Sun, 27 Sep 2026 15:33:34 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2026-09-27T15:33:34Z</dc:date>
    <item>
      <title>Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282324#M47036</link>
      <description>&lt;P class="PDq2pG_selectionAnchorContainer" data-end="414" data-start="369"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-14T182137.278.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35287iA052FF723A20921E/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-14T182137.278.png" alt="imagem - 2026-09-14T182137.278.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="PDq2pG_selectionAnchorContainer" data-end="414" data-start="369"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="PDq2pG_selectionAnchorContainer lia-align-justify" data-end="696" data-start="651"&gt;Hi CheckMates community and Check Point team,&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="824" data-start="698"&gt;I would like to raise a concern regarding the current situation with &lt;STRONG data-end="801" data-start="767"&gt;Recommended Jumbo Hotfix Takes&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="1166" data-start="826"&gt;Recently, I have received questions and concerns from customers about the lack of a current Recommended Take. At the same time, there is growing concern about the reliability of Takes that receive the &lt;STRONG data-end="1042" data-start="1027"&gt;Recommended&lt;/STRONG&gt; status, as we have seen multiple cases where Recommended JH Takes introduced significant issues in production environments.&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="1565" data-start="1168"&gt;We always follow best practices and perform our own validation before permanently deploying a new JH Take in production. However, the &lt;STRONG data-end="1317" data-start="1302"&gt;Recommended&lt;/STRONG&gt; status from Check Point is an important part of our decision-making process. Customers and partners need to have confidence that a Take marked as Recommended has reached an appropriate level of maturity, testing, and validation for production use.&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="1788" data-start="1567"&gt;For R82, we recently tested the latest &lt;STRONG data-end="1618" data-start="1606"&gt;Take 126&lt;/STRONG&gt; because of the need to address recent CVEs. Unfortunately, during our validation, it did not behave as expected, so we decided not to move forward with it in production.&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="2070" data-start="1790"&gt;We are now waiting for the next &lt;STRONG data-end="1842" data-start="1822"&gt;Recommended Take&lt;/STRONG&gt;, but this situation is also generating questions from customers: &lt;STRONG data-end="2070" data-start="1908"&gt;when a Take is marked as Recommended, how confident can we be that it has undergone additional validation and is considered solid for production environments?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="2342" data-start="2072"&gt;The frequency of issues we have encountered with some Recommended Takes is beginning to affect customer confidence in the Recommended status itself. This is particularly concerning in critical environments, where upgrading a JH can have a significant operational impact.&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="2556" data-start="2344"&gt;I would appreciate some clarification from Check Point regarding the criteria and validation process used before a Take receives the &lt;STRONG data-end="2492" data-start="2477"&gt;Recommended&lt;/STRONG&gt; status, and whether there are plans to strengthen this process.&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="2745" data-start="2558"&gt;Ultimately, what we need as partners and customers is not simply a new "Recommended" Take, but a &lt;STRONG data-end="2744" data-start="2653"&gt;Recommended Take that we can confidently use as the baseline for production deployments&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 21:32:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282324#M47036</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-14T21:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282326#M47037</link>
      <description>&lt;P&gt;&lt;SPAN&gt;From&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk95746" target="_self"&gt;Check Point Recommended Version and Release Terminology&lt;/A&gt;&amp;nbsp;which has recently changed:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Each Jumbo Hotfix Accumulator is considered Recommended from the day of its release,&amp;nbsp;as it contains important security, hardening, stability, and product fixes.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Customers should plan to adopt each latest Jumbo Hotfix Accumulator&amp;nbsp;as part of their regular maintenance and security update process, following their standard testing and change management procedures.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We also provide adoption-level information for each released Jumbo Hotfix Accumulator&amp;nbsp;(widely and early) and provide renumbers under each section, offering greater transparency and helping customers make informed deployment decisions.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;For more information about Jumbo and its Terminology, see &lt;/SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk98028" rel="noopener noreferrer" target="_blank"&gt;sk98028&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 22:24:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282326#M47037</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-14T22:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282327#M47038</link>
      <description>&lt;P&gt;This is particularly relevant when you look at the fix cadence in past jumbos. We'll typically get one with ~150 fixes, then a second a few weeks later with 2-3, and the second is the one which goes recommended. R82 jumbo 25: 206 fixes. R82 jumbo 33: 3. R82 jumbo 34: 2. Guess which ones went recommended.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 22:36:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282327#M47038</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-09-14T22:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282329#M47039</link>
      <description>&lt;P&gt;"We also provide adoption-level information" is incorrect, as the information isn't provided yet, even days after this change was announced. To be able to use it, we will need data going back a year or two so we can see when things went recommended in the past.&lt;/P&gt;
&lt;P&gt;All of our internal processes are worded such that we're not allowed to install a jumbo when it's newly released, only when it is moved to a separate recommended state. They were built this way after somebody deployed a jumbo too early and hit a new bug. Recommended from day 1 doesn't fit this, so now on top of multiple hair-on-fire emails telling us to install a security fix everywhere, then multiple more hair-on-fire emails telling us to install a new version of the fix everywhere, you've made a mountain of internal process work with zero reference we can use to build new processes.&lt;/P&gt;
&lt;P&gt;There should really have been a transition period for this change.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 22:50:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282329#M47039</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-09-14T22:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282330#M47040</link>
      <description>&lt;P class="PDq2pG_selectionAnchorContainer" data-end="372" data-start="273"&gt;Thanks for the clarification. After reviewing sk98028, I think this actually reinforces my concern.&lt;/P&gt;
&lt;P data-end="575" data-start="377"&gt;If &lt;STRONG data-end="453" data-start="380"&gt;every Jumbo Hotfix Accumulator is considered Recommended from day one&lt;/STRONG&gt;, what additional level of validation, maturity, or production readiness does the “Recommended” status actually represent?&lt;/P&gt;
&lt;P data-end="1024" data-start="580"&gt;I completely agree that customers must perform their own testing and change management, we always do. However, deploying a JHA to a critical environment may require significant planning, maintenance windows, backups, reboots and rollback procedures. If a Take officially marked as &lt;STRONG data-end="877" data-start="862"&gt;Recommended&lt;/STRONG&gt; introduces serious issues affecting the Check Point solution itself, the operational impact can be significant even with proper change management.&lt;/P&gt;
&lt;P data-end="1301" data-start="1029"&gt;From a customer perspective, when the vendor officially marks a release as &lt;STRONG data-end="1119" data-start="1104"&gt;Recommended&lt;/STRONG&gt;, there is a reasonable expectation that the vendor considers it sufficiently validated and reliable for production, with customer testing providing an additional layer of assurance.&lt;/P&gt;
&lt;P data-end="1576" data-start="1306"&gt;If every new Take is automatically Recommended regardless of its field maturity, perhaps the terminology should be reconsidered: call it simply &lt;STRONG data-end="1460" data-start="1450"&gt;Latest&lt;/STRONG&gt;, and reserve &lt;STRONG data-end="1489" data-start="1474"&gt;Recommended&lt;/STRONG&gt; for a Take that has reached an additional level of validation and production maturity.&lt;/P&gt;
&lt;P data-end="1687" data-start="1581"&gt;Otherwise, &lt;STRONG data-end="1687" data-start="1592"&gt;what practical assurance does “Recommended” provide beyond simply being the latest release?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 23:03:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282330#M47040</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-14T23:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282331#M47041</link>
      <description>&lt;P&gt;That part I kind of understand. If the latest has security fixes, and the recommended is an earlier one, are they recommending we skip security fixes? That would be really bad optics for a security company. They obviously have to recommend we install security fixes, but those aren't separated from bugfixes and feature updates; it's all just one jumbo.&lt;/P&gt;
&lt;P&gt;Raw adoption data (ideally with data about new bugs seen in a jumbo) is definitely better than an opaque recommended/not flag. But we really need the data &lt;EM&gt;&lt;STRONG&gt;before&lt;/STRONG&gt;&lt;/EM&gt; the old pattern is no longer available.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 23:16:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282331#M47041</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-09-14T23:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282341#M47044</link>
      <description>&lt;P&gt;Check Point will use CPLP (LivePatch) to fix security fixes/CVEs (without reboot/cpstop). These security packages will be&amp;nbsp;independent from Jumbo Take. Until next "Latest" Jumbo is released (minimum once per month), you will be already protected by&amp;nbsp; CPLP package.&lt;/P&gt;
&lt;P&gt;If there will be some critical bug in Jumbo which you are supposed to install (since it is already recommended from day 1 of release), new Jumbo will be released with only 1 bugfix. It will end up having too many&amp;nbsp;maintenance windows in very short period of time. Too many work for every administrator (doing rollback or updating to latest Jumbo + long processes and approvals by corporates). Not saying that there are many freeze periods where changes are not allowed. If someone prepares change to install Take X in 3 weeks from now, it might happen that once the change is approved and released for implementation, next Take Y will be released (already recommended) ...&lt;/P&gt;
&lt;P&gt;Or maybe the intention is just to keep our firewalls clean and fresh as every reboot clears cache, memory consumption and temp files ...&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 06:46:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282341#M47044</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2026-09-15T06:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282343#M47045</link>
      <description>&lt;P&gt;Can you share what sort of issues you are having with take 126?&lt;/P&gt;
&lt;P&gt;Andhave you eveluated if this could in part be because you deviate from Best Practises? Having said that, finding all the Best Practises is .... painful. So yes, it would be nice if there is a clear set of Best Practises.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 07:28:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282343#M47045</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2026-09-15T07:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282353#M47050</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp; and all&lt;/P&gt;
&lt;DIV&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; mentioned, we have updated our terminology.&lt;/P&gt;
&lt;P&gt;Regarding adoption visibility, this information is already available and visible to all users. On the download page of each Jumbo SK, you can see the current adoption status, such as &lt;STRONG&gt;Initial Adoption&lt;/STRONG&gt; or &lt;STRONG&gt;Wide Adoption&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;For reference, all of the latest Jumbo releases were promoted to &lt;STRONG&gt;Wide Adoption&lt;/STRONG&gt; yesterday.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 08:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282353#M47050</guid>
      <dc:creator>MeravAlon</dc:creator>
      <dc:date>2026-09-15T08:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282374#M47051</link>
      <description>&lt;P&gt;Thanks, I understand the new terminology and the adoption visibility now.&lt;BR /&gt;However, my main concern is still different. We are seeing JH causing significant issues with Check Point products in production, and this is becoming a recurring concern for customers.&lt;BR /&gt;Customers are starting to question the level of testing and validation performed before these Takes are released. Regardless of whether the terminology is Recommended, Latest, Initial Adoption or Wide Adoption, what we really need is confidence that a released JH has been thoroughly tested by Check Point across Check Point products and their core functionalities before customers are asked to deploy it.&lt;BR /&gt;My intention with this post is mainly to bring visibility to this issue. The recent experience with problematic JH is creating operational impact and reducing customer confidence. I hope Check Point can take a closer look at the validation and release process, because ultimately, terminology is secondary. What customers and partners need most is reliable JH.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 12:50:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282374#M47051</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-15T12:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282377#M47053</link>
      <description>&lt;P class="PDq2pG_selectionAnchorContainer" data-end="606" data-start="328"&gt;Regarding R82 JH Take 126, initially everything appeared to be working normally after installation. This was already an improvement compared to Take 122, where we had an issue with Mobile Access rule processing, which was later addressed by Check Point with a specific portfix.&lt;/P&gt;
&lt;P data-end="731" data-start="611"&gt;However, after running Take 126 for some time, the gateway started repeatedly displaying the following message over SSH:&lt;/P&gt;
&lt;P data-end="794" data-start="736"&gt;&lt;CODE data-end="794" data-start="736"&gt;Kernel: watchdog: BUG: soft lockup - CPU23 stuck for 22s&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-end="1028" data-start="799"&gt;After that, we also started experiencing VPN instability. Based on this behavior, I decided not to move Take 126 into full production for this customer and kept them on &lt;STRONG data-end="983" data-start="968"&gt;JH Take 91&lt;/STRONG&gt;, which has been stable in their environment.&lt;/P&gt;
&lt;P data-end="1374" data-start="1033"&gt;Another important issue occurred during the rollback. After reverting Take 126 on the Security Management Server, the SMS did not recover properly. &lt;STRONG data-end="1274" data-start="1181"&gt;CPM and API processes entered a loop, attempting to start and returning to Stopped state.&lt;/STRONG&gt; Fortunately, I had taken a VM snapshot before the change, so I was able to restore the SMS quickly.&lt;/P&gt;
&lt;P data-end="1464" data-start="1379"&gt;Because of experiences like these, my current approach before deploying a new JH is:&lt;/P&gt;
&lt;OL data-end="2616" data-start="1469"&gt;
&lt;LI data-end="1513" data-start="1469" data-section-id="y9681c"&gt;&lt;STRONG data-end="1513" data-start="1472"&gt;Always schedule a maintenance window.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="1740" data-start="1516" data-section-id="1g0itur"&gt;&lt;STRONG data-end="1575" data-start="1519"&gt;Back up as much as possible before the installation.&lt;/STRONG&gt; For virtual Open Servers, whenever possible I take a VM snapshot, System Backup and &lt;CODE data-end="1676" data-start="1660"&gt;migrate export&lt;/CODE&gt;. For gateways, I keep a System Backup and &lt;CODE data-end="1739" data-start="1719"&gt;show configuration, and any relevant file like fwkern.conf,trac.client,ipassignment,fastaccel ...&lt;/CODE&gt;.&lt;/LI&gt;
&lt;LI data-end="1977" data-start="1743" data-section-id="b1owtz"&gt;&lt;STRONG data-end="1808" data-start="1746"&gt;For ClusterXL HA, I upgrade only the Standby member first.&lt;/STRONG&gt; I then promote it to Active and validate the customer's services and normal production traffic with the new JHA while keeping the other member on the known stable Take.&lt;/LI&gt;
&lt;LI data-end="2149" data-start="1980" data-section-id="7ta717"&gt;&lt;STRONG data-end="2053" data-start="1983"&gt;I keep this validation running during 1 day or 1 week before upgrading the second member.&lt;/STRONG&gt; If abnormal behavior appears, I can fail back to the member running the previously stable Take.&lt;/LI&gt;
&lt;LI data-end="2427" data-start="2152" data-section-id="nlnr4m"&gt;&lt;STRONG data-end="2248" data-start="2155"&gt;For virtual Security Management Servers, I consider the VM snapshot especially important.&lt;/STRONG&gt; If the upgrade or revert leaves management processes unable to start, restoring the snapshot can be significantly faster than rebuilding the SMS and restoring from backup/export.&lt;/LI&gt;
&lt;LI data-end="2614" data-start="2430" data-section-id="h2ggzv"&gt;&lt;STRONG data-end="2503" data-start="2433"&gt;For Maestro, I start with a small number of Security Group Members&lt;/STRONG&gt;, following the recommended procedure, validate the behavior, and only then proceed with the remaining members.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-end="2870" data-start="2619"&gt;This approach obviously requires more planning, but after the issues we have experienced with recent JH, I prefer to treat every new Take as something that must prove stable under the customer's real production traffic before completing the rollout.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 13:16:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282377#M47053</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-15T13:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282386#M47054</link>
      <description>&lt;P&gt;&lt;BR /&gt;I completely understand your concern, but unfortunately the rapidly accelerating risks due to advanced AI finding vulnerabilities in security platforms in a *very* short period of time, means the slower, more cautious patching and testing pattern that we previously used, is no longer adequate to provide the protections we need today.&lt;/P&gt;&lt;P&gt;If we look back a few years, it was much the same with Microsoft patches: a slow adoption after careful testing, but nobody can afford the time to do this anymore - and yes, sometimes things break after the monthly cumulative update, but the world has changed - and end users (and managers), now accept the monthly patching ritual and organisations have mandated policies and procedures which reflect this pratice.&lt;/P&gt;&lt;P&gt;I personally welcome CheckPoint’s move to provide frequent ‘Recommended’ updates - previously, it could be *months* before a ‘Recommended’ update became available, and many of us work in environments where policies prevent us installing updates before they reach ‘Recommended’ status even when they are considered critical - the idea of having a patch that is critical, but not recommended is nonsensical in my opinion - it sends out the wrong message to the community, so I’m very pleased this is changing.&lt;/P&gt;&lt;P&gt;For many of us,&amp;nbsp;&lt;SPAN&gt;predictability and the ability to quickly uninstall a patch if it does cause a problem is of the highest priority.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 18:51:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282386#M47054</guid>
      <dc:creator>ccsjnw</dc:creator>
      <dc:date>2026-09-15T18:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282387#M47055</link>
      <description>&lt;P&gt;I agree with you. The current security landscape, especially with AI accelerating vulnerability discovery, definitely requires a much faster response.&lt;BR /&gt;In fact, I think Check Point Live Patch (CPLP) is a fantastic step in this direction. Being able to address critical CVEs independently of the normal Jumbo Hotfix cycle is a major improvement.&lt;BR /&gt;My concern is that faster patching should not come at the cost of JH quality. There is little benefit in releasing a security update quickly if the JH introduces another serious issue in the product and, as a result, we cannot keep it in production.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 16:22:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282387#M47055</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-15T16:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282398#M47056</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":hundred_points:"&gt;💯&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 04:32:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282398#M47056</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2026-09-16T04:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282688#M47099</link>
      <description>&lt;P&gt;Agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/93117"&gt;@israelfds95&lt;/a&gt;.&amp;nbsp;Our customesr are facing same issues &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; applying fast JHFs and sometimes even with some custom hotfix wrapper is becoming a nightmare with a lot of customer issues after, services crashing, cluster failing over with fwk dumps etc . Security is of concern, but stability cannot be put aside.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 08:48:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282688#M47099</guid>
      <dc:creator>Stephen_Vella</dc:creator>
      <dc:date>2026-09-23T08:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282901#M47145</link>
      <description>&lt;P data-pm-slice="1 1 []"&gt;&lt;SPAN&gt;This is exactly what I have been talking about.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I had issues with R82 JH Take 122. I had issues with R82 JH Take 126. And now, after installing the recently released R82 JH Take 127, I am experiencing issues again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In all three cases, I had to uninstall the Jumbo Hotfix because of problems identified on the cluster during our maintenance and testing window. This environment belongs to an extremely important customer here in Brazil.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This is precisely my point: there is little benefit in releasing Jumbo Hotfixes quickly if it appears that they are not being tested thoroughly enough before release.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In our case, keeping critical customer environments compliant requires a significant operational effort. Obtaining a maintenance window can take weeks or even months of planning, including management approval and coordination across multiple teams. Having to roll back the update at the end of that process creates significant operational challenges, especially when management is also demanding compliance, CVE remediation, and an up-to-date environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For this reason, I strongly believe Jumbo Hotfixes need more extensive testing, and that Check Point needs to ensure the quality and stability of these packages, not only for customers but also for the engineers and teams responsible for maintaining these environments.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;With JH Take 127, I am now seeing a serious issue during policy installation. At approximately 75% of the Install Policy process, the firewall starts experiencing severe packet loss affecting Internet-bound traffic, VPN traffic, and internal traffic. Once the policy installation finishes, traffic returns to normal. This behavior was not occurring before installing Take 127.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For now, I am remaining on JH Take 91.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;At least I have enabled Check Point Live Patch (CPLP), which helps reduce some of the exposure. However, the latest CVE is not covered by CPLP. I have implemented all applicable mitigation measures to reduce the exposure to these CVEs and keep my customers' environments as protected as possible while maintaining the stability of their production systems.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2026 03:03:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282901#M47145</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-26T03:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282902#M47146</link>
      <description>&lt;P&gt;Did you face issue with installing policy when Take was installed on management or gateway ?&lt;/P&gt;
&lt;P&gt;The latest CVEs (CVE-2026-91843 +&amp;nbsp;CVE-2026-93616) are relevant only for management.&lt;/P&gt;
&lt;P&gt;You can also try to request from Check Point portix just to fix CVEs on your current Take.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2026 12:15:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282902#M47146</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2026-09-26T12:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282903#M47147</link>
      <description>&lt;P&gt;I installed JH 127 on both the SMS and the Security Gateway. However, I kept JH 127 installed only on the SMS and removed it from the Gateway due to this serious issue. After removing JH 127 from the Gateway and rolling back to JH 91, which had been stable in this customer environment, everything returned to normal.&lt;/P&gt;
&lt;P&gt;On the production Gateways, I am currently staying on JH 91, with CPLP enabled and the IKEv1 CVE hotfix installed. Given the criticality of this customer environment, I could not keep JH 127 installed on the production Gateways.&lt;/P&gt;
&lt;P&gt;I had issues with JH 122, which broke Mobile Access in this environment, and I reported it here. Some time later, Check Point released a hotfix for that issue. JH 126 was also unstable in my testing, and now I am seeing problems with JH 127 as well.&lt;/P&gt;
&lt;P&gt;Even though JH 127 includes fixes for CVEs that primarily affect the SMS, it is still a full JH. In this particular case, I think Check Point could have released the relevant fixes as a dedicated hotfix for the SMS instead.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2026 12:42:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282903#M47147</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-26T12:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282904#M47148</link>
      <description>&lt;P&gt;I fully agree with you.&lt;/P&gt;
&lt;P&gt;Instead of including fixes for critical CVEs into new Take, they should have created portfixes for last XY Takes for each version. But they will argue that CPLP is the solution ...&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2026 12:56:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282904#M47148</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2026-09-26T12:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns About the Reliability of Recommended Jumbo Hotfix Takes</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282905#M47149</link>
      <description>&lt;P&gt;I have been frustrated with the quality of recent JHs, and this is not something new. Since R81.20, I have seen several cases where we install a JH to fix one problem and end up introducing another serious issue, and we need to uninstall.&lt;/P&gt;
&lt;P&gt;CPLP has been an excellent solution, and my customers are very happy with the faster response to critical CVEs. However, these recent CVEs that required a JH instead of CPLP have brought this concern back again.&lt;/P&gt;
&lt;P&gt;Unfortunately, it gives the impression that JHs are not being tested enough before release, leaving customers responsible for finding issues in production. In the real world, a customer environment cannot be a test lab. The impact of not being able to deploy security fixes is significant, but deploying a JH that causes production issues can be even worse.&lt;/P&gt;
&lt;P&gt;In this case, JH 127 was released mainly to address two CVEs. A dedicated hotfix for the affected SMS/MDS systems could potentially have avoided the need to deploy a full JH. I could keep JH 127 on the SMS, but not on the production Gateways due to the issues we experienced, and other engineers on my team are also reporting problems with it.&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;continue to believe that Check Point needs to improve JH testing and quality before release, rather than transferring this risk to customers.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2026 13:08:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-About-the-Reliability-of-Recommended-Jumbo-Hotfix-Takes/m-p/282905#M47149</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-26T13:08:01Z</dc:date>
    </item>
  </channel>
</rss>

