- Products
- Learn
- Local User Groups
- Partners
- More
What's New in Check Point SASE
Wednesday, 9 September @ 5pm CET / 11am EDT
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Question.
We see that we have.
[CPUpdates]
BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE Take: 18
But none of our boxes we are able to run
[Expert@se-sec-fw001_n1:0]# cplp list
bash: cplp: command not found
Regards,
Magnus
hello magnus you can find it inside here:
Just run the command like this copy and paste : /usr/local/bin/cplp list
Ye that works 🙂
[Expert@se-sec-vsx030_n1:0]# /usr/local/bin/cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
vpn1:iked ready livepatch 0/0 2026-09-02 11:57:45
vpn1:vpnd ready livepatch 0/0 2026-09-02 11:57:45
And Mobile Access ??
Since the vulnerability was found internally, are there any indicators in logs which would allow to identify attempts?
We did not see any evidence of those vulnerabilities being exploited externally. IOCs are only relevant for existing exploits.
We discovered the existence of CPLP this morning with these announcements. We are a little confused on the functionality of this feature. When we ran the commands 'cplp list" on our gateways this morning it showed only the older iked and vpnd fixes in the list, and showed "ready" status for both of them. However when we ran the command again about 30 minutes later, it now shows several additional entries including the ones released today, and showing some as "armed" status, some as 'ready" status, and some as "jumbofix" status.
It is almost like CPLP was not actually fully functional until we entered the "cplp list" command?
It is possible you might have received the auto-update within that time frame. You can check the log on your gateway to verify.
T24 would be the new one.
Timestamps from our gateway.
more /opt/CPInstLog/AutoUpdater.log | grep urgent_security_updates_R81.20
*N* %2026-07-13 12:33:11% : Importing package urgent_security_updates_R81_20_Bundle_T10_AutoUpdate.tar for component urgent_security_updates version 10 branch urgent_security_update_R81_20_AutoUpdate
*N* %2026-07-13 12:33:17% : <action = install, component = urgent_security_updates, build = 10, package_name = urgent_security_updates_R81_20_Bundle_T10_FULL.tgz, source = INTERNAL>
*N* %2026-09-01 09:01:15% : Importing package urgent_security_updates_R81_20_Bundle_T18_AutoUpdate.tar for component urgent_security_updates version 18 branch urgent_security_update_R81_20_AutoUpdate
*N* %2026-09-01 09:01:20% : <action = install, component = urgent_security_updates, build = 18, package_name = urgent_security_updates_R81_20_Bundle_T18_FULL.tgz, source = INTERNAL>
unable to understand why take 24 not pushed....
I can see that the patch is downloaded and implementet for all processes except cpca and vpnrad.
Do we need to reboot the whole VSX-box to make it arm these processes aswell or will it happen automagically ?
[Expert@fw-vsxcluster-node1:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 5/5 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 7/7 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 6/6 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-09 15:25:33 CVE-2026-85102 CVE-2026-85103
vpn1:ike* armed livepatch 5/5 2026-07-09 09:25:04 sk185033
vpn1:vpn* armed livepatch 7/7 2026-07-09 09:25:04 sk185033
I believe "ready" state is because the process is actually not running on the box
Would be great if thats the case, Check Point should definately clarify some more in their sk`s :).
According to sk185114, "ready" means "The patch is installed and waiting. It will be applied automatically as soon as the target process starts."
On the box i cant find "cpca" process (and would not expect to since its a VSX gateway and not Management so you are probably correct 🙂
few Commands for autoudpatercli
autoupdatercli show urgent_security_updates
autoupdatercli update_component urgent_security_updates
Note:
autoupdatercli update_component command only downloads the package if the new one is "rolled out" to your device.
You just get ahead of the scheduled job
What controls "rolled out to your device?" I've manually installed the critical ones, but nothing has automatically advanced beyond version 17.
CPLP has a lot of potential, the need for patch will only increase - But I think this thread clearly highlights that cplp is early days.
The documentation is almost zero.
- cplp only works with full path
- why are new cplp versions needed for new live patches? When are these pushed?
- when does a proc go from ready to armed?
- how do I set 'frozen' periods on when arming is allowed? We have frozen periods for autoupdater (although very limited)
- do we have an audit log browsable in smartlog?
- when does a proc go from ready to armed?
Ready means the process is not running, otherwise it'd go "armed". That's my take
- how do I set 'frozen' periods on when arming is allowed? We have frozen periods for autoupdater (although very limited)
CPLP works via autoupdatercli so if you have a frozen period there the same applies to CPLP (it wouldnt download an update)
- do we have an audit log browsable in smartlog?
Search "live patch" in audit logs
Hey,
I have clusters that definitely have the procs running. I am yet to see armed go to ready - anywhere.
I see that CPLP documentation is evolving as we speak. Maybe to go to armed mode would need a reboot, it looks like it.
On the arming frozen periods, I am not so sure.
live patch - gives zero hits in audit logs in an MDM managing 40 clusters.
We are still using R81,10 and will not update for the next 4-5 weeks. How can I apply the suggested mitigation without affecting my remote users?
Val - please note the Quantum spark links need correcting, the image file for 2000 appliances is on the 2560 - 2590 link and the 2560 - 2590 image is on the 2000 link.
The 15x5/1575RIMG link is still the previous build as well.
I did a refresh of this page and the build was now correct.
One question I haven't seen answered: Do the live patch updates require any specific jumbo HFA to be installed first?
For example, I have an R82 host with JHF 107 that has the live patch installed and "armed". I have some other hosts with JHF 103 that haven't gotten the update yet. I have an R81.20 host with JHF 127 which does have the live patch armed. Many other R82 hosts with JHF 107 that don't yet have the live patch, nor do they have the latest "urgent_security_updates" components; I tried to update this component manually but nothing changed and no error was reported.
Seems like we don't have any way to influence these updates without manually installing packages, and that can be annoying to push out no matter how much Ansible tooling I have. 🙂 I haven't finished my draft version of the autoupdater Ansible modules yet. I started on it but got moved to another project. (maybe it's time... ?)
Thanks!
I am very ecstatic Check Point can close the gap so quickly with CPLP and thank you to all of those that worked on this feature. This is a big win! I think there is a marketing opportunity with some T-shirts that say, "I sure do love me... some CPLP!" Seriously though, it is a great feature.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY