I would monitor and check the systems with this command:
- On a Security Gateway / ClusterXL member: cplp list
- On a Scalable Platform Security Group: g_all cplp list
Then you are for sure if it is active. Note: sometimes it says ready. This means that this system does not use for example IKE daemon (management server). The patch is ready, so if ever the daemon get's enabled the patch is also there and will change from ready to armed. In here you can also see patches that are active that are already solved by a higher jumbo take. Here is an example output of a mgmt:
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpca:cpca* jumbofix livepatch 0/0 2026-09-01 09:06:07 sk185152
cpcert:cpca* armed livepatch 1/1 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:iked* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:vpnd* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-10 00:28:11 CVE-2026-85102 CVE-2026-85103
cpm:fwm* jumbofix livepatch 0/0 2026-09-01 09:06:07 sk185152 sk185169
-------
Please press "Accept as Solution" if my post solved it 🙂