- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
@_Val_: Yes, i am fine with having to login to download the fixes.
But i would expect to have a link in the SK, which then forces me to login.
Not just a page without any working link.
E.g: sk185114 - Check Point Live Patch (CPLP) has a download link, even if you are not logged in.
(you then are forced to do a login, to retreive the download.)
The Live Patch download links work here.
I have already applied Urgent Take 24 and it works well. Better than the jumbo approach for sure.
CaseyB, that page is blank when I open (and fresh it) from the UK...
Strange. Here are the direct links (R81.20, R82, R82.10 probably not in order):
https://support.checkpoint.com/results/download/145415
https://support.checkpoint.com/results/download/145416
https://support.checkpoint.com/results/download/145417
Still not working here:
See the above screenshot...
Are you positive that these links have been made available to customers, and not just internally?
That's what I used as a customer. ¯\_(ツ)_/¯
The WebUI in Gaia is now showing the full update packages for both R82 and R82.10, so I'm using that method...
Question.
We see that we have.
[CPUpdates]
BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE Take: 18
But none of our boxes we are able to run
[Expert@se-sec-fw001_n1:0]# cplp list
bash: cplp: command not found
Regards,
Magnus
hello magnus you can find it inside here:
Just run the command like this copy and paste : /usr/local/bin/cplp list
Ye that works 🙂
[Expert@se-sec-vsx030_n1:0]# /usr/local/bin/cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
vpn1:iked ready livepatch 0/0 2026-09-02 11:57:45
vpn1:vpnd ready livepatch 0/0 2026-09-02 11:57:45
I have an offline Management Server with R81.20 / T161 and there is no cplp`bash: /usr/local/bin/cplp: No such file or directory`
I do have /opt/AutoUpdater/latest/bin/autoupdatercli though. Can it be applied via autoupdatercli?
You can, but you must use the manual packages to update. You may need to update the AutoUpdater package and its components first. This is described in the SK article and with the links to other AutoUpdater articles (also listed within the article for this advisory).
And Mobile Access ??
Since the vulnerability was found internally, are there any indicators in logs which would allow to identify attempts?
We did not see any evidence of those vulnerabilities being exploited externally. IOCs are only relevant for existing exploits.
I can see that the patch is downloaded and implementet for all processes except cpca and vpnrad.
Do we need to reboot the whole VSX-box to make it arm these processes aswell or will it happen automagically ?
Output:
[Expert@fw-vsxcluster-node1:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 5/5 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 7/7 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 6/6 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-09 15:25:33 CVE-2026-85102 CVE-2026-85103
vpn1:ike* armed livepatch 5/5 2026-07-09 09:25:04 sk185033
vpn1:vpn* armed livepatch 7/7 2026-07-09 09:25:04 sk185033
Ready means the live patch is present, but no relevant processes are running. Armed is the same state, but relevant processes have been found and patched in RAM.
We discovered the existence of CPLP this morning with these announcements. We are a little confused on the functionality of this feature. When we ran the commands 'cplp list" on our gateways this morning it showed only the older iked and vpnd fixes in the list, and showed "ready" status for both of them. However when we ran the command again about 30 minutes later, it now shows several additional entries including the ones released today, and showing some as "armed" status, some as 'ready" status, and some as "jumbofix" status.
It is almost like CPLP was not actually fully functional until we entered the "cplp list" command?
It is possible you might have received the auto-update within that time frame. You can check the log on your gateway to verify.
T24 would be the new one.
Timestamps from our gateway.
more /opt/CPInstLog/AutoUpdater.log | grep urgent_security_updates_R81.20
*N* %2026-07-13 12:33:11% : Importing package urgent_security_updates_R81_20_Bundle_T10_AutoUpdate.tar for component urgent_security_updates version 10 branch urgent_security_update_R81_20_AutoUpdate
*N* %2026-07-13 12:33:17% : <action = install, component = urgent_security_updates, build = 10, package_name = urgent_security_updates_R81_20_Bundle_T10_FULL.tgz, source = INTERNAL>
*N* %2026-09-01 09:01:15% : Importing package urgent_security_updates_R81_20_Bundle_T18_AutoUpdate.tar for component urgent_security_updates version 18 branch urgent_security_update_R81_20_AutoUpdate
*N* %2026-09-01 09:01:20% : <action = install, component = urgent_security_updates, build = 18, package_name = urgent_security_updates_R81_20_Bundle_T18_FULL.tgz, source = INTERNAL>
unable to understand why take 24 not pushed....
I can see that the patch is downloaded and implementet for all processes except cpca and vpnrad.
Do we need to reboot the whole VSX-box to make it arm these processes aswell or will it happen automagically ?
[Expert@fw-vsxcluster-node1:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 5/5 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 7/7 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 6/6 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-09 15:25:33 CVE-2026-85102 CVE-2026-85103
vpn1:ike* armed livepatch 5/5 2026-07-09 09:25:04 sk185033
vpn1:vpn* armed livepatch 7/7 2026-07-09 09:25:04 sk185033
I believe "ready" state is because the process is actually not running on the box
Would be great if thats the case, Check Point should definately clarify some more in their sk`s :).
According to sk185114, "ready" means "The patch is installed and waiting. It will be applied automatically as soon as the target process starts."
On the box i cant find "cpca" process (and would not expect to since its a VSX gateway and not Management so you are probably correct 🙂
As soon as the process executes it will switch status to armed.
For example, the cpca process is Check Point Internal CA which only runs on a management appliance.
The vpnrad process is a new one to me, also does not seem documented in sk97638.
few Commands for autoudpatercli
autoupdatercli show urgent_security_updates
autoupdatercli update_component urgent_security_updates
Note:
autoupdatercli update_component command only downloads the package if the new one is "rolled out" to your device.
You just get ahead of the scheduled job
What controls "rolled out to your device?" I've manually installed the critical ones, but nothing has automatically advanced beyond version 17.
CheckPoint does a progressive rollout i guess, i've checked this morning and all the firewalls i manage are now patched, for some it was overnight (europe)
Yes, something triggered and over the ~3 hour check in timer, most everything updated / patched. That will need to be a discussion if there is a active attack. Where does 'my' account specifically fall in the staged roll out and is there a button to "go now".
I know.. it didn't exist yesterday and I want it to be faster today... But that is the roll of a customer right?
As mentioned in the original statement, we do not have any indication that either vulnerability was actively exploited. Both CVEs were discovered internally.
CPLP has a lot of potential, the need for patch will only increase - But I think this thread clearly highlights that cplp is early days.
The documentation is almost zero.
- cplp only works with full path
- why are new cplp versions needed for new live patches? When are these pushed?
- when does a proc go from ready to armed?
- how do I set 'frozen' periods on when arming is allowed? We have frozen periods for autoupdater (although very limited)
- do we have an audit log browsable in smartlog?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY