- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
- when does a proc go from ready to armed?
Ready means the process is not running, otherwise it'd go "armed". That's my take
- how do I set 'frozen' periods on when arming is allowed? We have frozen periods for autoupdater (although very limited)
CPLP works via autoupdatercli so if you have a frozen period there the same applies to CPLP (it wouldnt download an update)
- do we have an audit log browsable in smartlog?
Search "live patch" in audit logs
Hey,
I have clusters that definitely have the procs running. I am yet to see armed go to ready - anywhere.
I see that CPLP documentation is evolving as we speak. Maybe to go to armed mode would need a reboot, it looks like it.
On the arming frozen periods, I am not so sure.
live patch - gives zero hits in audit logs in an MDM managing 40 clusters.
We are still using R81,10 and will not update for the next 4-5 weeks. How can I apply the suggested mitigation without affecting my remote users?
same, I have a pair on R81.10 that are scheduled for replacement later this month. "disable implied rules for VPN" is far too vague, I'd like to know precisely what lines to comment out of implied_rules.def to achieve that. no JHF available, no CPLP. Mitigation is the only option for these (or anything older).
Val - please note the Quantum spark links need correcting, the image file for 2000 appliances is on the 2560 - 2590 link and the 2560 - 2590 image is on the 2000 link.
The 15x5/1575RIMG link is still the previous build as well.
I did a refresh of this page and the build was now correct.
One question I haven't seen answered: Do the live patch updates require any specific jumbo HFA to be installed first?
For example, I have an R82 host with JHF 107 that has the live patch installed and "armed". I have some other hosts with JHF 103 that haven't gotten the update yet. I have an R81.20 host with JHF 127 which does have the live patch armed. Many other R82 hosts with JHF 107 that don't yet have the live patch, nor do they have the latest "urgent_security_updates" components; I tried to update this component manually but nothing changed and no error was reported.
Seems like we don't have any way to influence these updates without manually installing packages, and that can be annoying to push out no matter how much Ansible tooling I have. 🙂 I haven't finished my draft version of the autoupdater Ansible modules yet. I started on it but got moved to another project. (maybe it's time... ?)
Thanks!
No. it can be installed on any Jumbo HF in versions R81.20, R82.00, R82.10
Yep, I see that now! Thanks!
My best guess is that Check Point was slow-walking these updates all day then around 2100 UTC they opened the gates to all. All of my customer gateways and management servers simultaneously started getting the updates around that time and over the next 1.5 hours.
Same thing @Machine_Head noted.
I am very ecstatic Check Point can close the gap so quickly with CPLP and thank you to all of those that worked on this feature. This is a big win! I think there is a marketing opportunity with some T-shirts that say, "I sure do love me... some CPLP!" Seriously though, it is a great feature.
The advisory has been updated to also patch the SMS as a matter of urgency, regarding CVE-2026-85103.
Just received an update this morning, that says the patch must be installed on *all* management servers:
Correct, I mentioned it above, the second CVE is about certificate handling, and considering all MGMT servers have CPCA, they have to be patched.
Hello
If I have disabled blade VPN and I/m installed the patch on the management station, can I postpone patching the gateways for a few days?
This is not recommended. Also, LivePatch does not require a reboot and does not cause any downtime or cluster failover.
It looks like we have a path via CPLP on both gateways:
# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 14/14 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 1/1 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 27/27 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-10 00:03:47 CVE-2026-85102 CVE-2026-85103
vpn1:iked* jumbofix livepatch 0/0 2026-07-09 09:20:01 sk185033
vpn1:vpnd* jumbofix livepatch 0/0 2026-07-09 09:20:01 sk185033
I have already patched my customer's Security Gateways that have IPSEC VPN and/or Mobile Access Blades enabled, and I have also patched the Management Server.
The customer also has several other Security Gateways that do not have IPSEC VPN or Mobile Access Blades enabled. Is it OK to leave these on R82 Jumbo HFA Take 122 for now?
As I mentioned, we recommend applying LivePatch to the whole estate, regardless of VPN is being used.
@_Val_, could you be a little more precise, please?
sk1000118 mentions "Affected Products: Security Management Server, Security Gateway, Check Point Spark Firewall" – not restricted to anything with VPN. And we see "wstlsd" and "cprid" live-patched – nothing to do with VPN. Are all security gateways affected?
No one at Check Point can or wants to tell me definitely. But that answer is crucial!
CPLP actions appear in the Audit Logs. Cool.
The gateways have been successfully auto-updated with the Live Patch; however, the Management Server has not been updated.
Could you please advise how we should proceed with applying the Live Patch on the Management Server?
Version R81.20 JHF TAKE 127
Do CheckPoint have any CPLP premier material available or videos to watch?
I literally did not know of its existence until yesterday and now I'm playing catch-up...
I'm looking at the autoupdatecli command and there are a lot of options.
If I want to be 100% certain that a Security Gateway will only download and install an urgently required Live Patch automatically (but never automatically install a full Jumbo HotFix Package or Reboot automatically), is there a simple command to show this clearly?
It looks like the correct command to enable this functionality is:
autoupdatercli enable urgent_security_updates
But is says security updates, not Live Patches, so I'm concerned that may not be correct.
I'm not finding the SK articles particularly informative or helpful...
Good video in regards to it.
https://youtu.be/6cNrNRAjvEw?si=JICZpcchV1Bz9i6D
Thanks for the link Magnus,
It's an extremely informative presentation by Aviv Abramovich. I would urge everybody to watch this and to give it your full attention... there are big changes coming:
https://youtu.be/6cNrNRAjvEw?si=JICZpcchV1Bz9i6D
I'm still unclear with regard to the proper enablement of Live Patching...
cplp list
Why is the same CVE shown more than once and how can it have the status of both Ready and Armed?
autoupdatercli show urgent_security_updates
I see:
What do I actually need to do to make the live patches take effect?
Do I just need to issue the command:
autoupdatercli update_component urgent_security_updates
And do I only need to issue this command just once for the whole LivePatching process to automatically up-to-date ???
I been through various SK articles and it's still not clear to me...
Please can the terminology be improved:
The word ARMED in this context is very ambiguous. ENFORCED would be far clearer, and not open to the wrong interpretation of the word.
According to the above, Ready means Installed and Waiting
Waiting for what target process? Can something be installed, but not active? Perhaps use the wording, Deployed, but not yet active or Deployed, but not yet enforced - it needs to be crystal clear.
I think we all just need some further clarity, as we're all playing catch up, and don't want to break anything...
LivePatch is clearly an impressive technology - thanks for the continued innovations.
Uploaded two Spark Pro, 1800 and 1900 clusters today from R82.10.10 2242 to 2325, centrally managed by Smart-1 Cloud.
No issues with both 1900. Doing one of the 1800, it worked but after rebooting, policy install fails and it reports management unreachable. Clustering works. After rebooting it, it reverted to 2242. Will try again later.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY