- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello folks,
Maybe a weird question, but I am looking for the recommended HFA to take for all supported versions, starting from R81.20 to R82.10, but only the latest HFA is present. Am I missing something, and will the latest branch be the new recommended?
Thanks
I have several customers in the same position where they prefer the "recommended" versus "latest" release.
sk95746 has more information regarding recommended versus latest takes.
The "recommended" take can still be found under "Previously released takes". Keep in mind that this release will not cover the recently released CVEs.
For example:
R81.20 JHF 127 can be found at the following link.
Each JHF has information regarding the release date as well as the recommended date.
Hi,
Check this article:
sk174185 - Download Archive of Recommended Jumbo Hotfix Accumulator Takes
Regards,
Martijn
The previous recommended takes are not highlighted as recommended as they don't include the recent roundup of CVEs patched in the latest takes. Once we have seen the latest takes have significant install sizes without issues they will become recommended.
This is really confusing.... Check Point shouldn't make poor decisions like this without thoroughly thinking about the consequences (intended or otherwise).
People who work in a highly compliance / regulated environment frequently have a policy where they will only install "Recommended" versions. You risk organisations uninstalling their current Take and going back to the GA release which I'm sure is not your intention.
Whatever was the Recommended Take, should stay the Recommended Take until the replacement is ready and available (and fully tested!).
I have several customers in the same position where they prefer the "recommended" versus "latest" release.
sk95746 has more information regarding recommended versus latest takes.
The "recommended" take can still be found under "Previously released takes". Keep in mind that this release will not cover the recently released CVEs.
For example:
R81.20 JHF 127 can be found at the following link.
Each JHF has information regarding the release date as well as the recommended date.
Normally, the most recent Recommended is listed, but this is a case of a Recommended JHF being "revoked" for one reason or another. I've seen it happen before. In this case, it looks like the reason is what @emmap said; looks like the recent pile of CVEs are more important. You'll see Recommended come back again soon. Then at some point in the future, you'll see a repeat of this same scenario when some other extenuating circumstance occurs.
Imagine from Check Point's perspective, tho: "I installed the most recent Recommended but now my vulnerability scanning service says I'm vulnerable to all these CVEs! I thought I had all the updates!" ...well, you did... until things changed. Now you're not.
They didn't completely rescind the last recommended JHF either, as you found. If you install that, tho, now that time has passed since that JHF, you need to be aware of the forward risk. There are CVEs now published which have been patched in the new JHF candidate. You have a decision to make: Install the new candidate, or ask TAC to get you portfixes for those CRs for your current JHF. It's up to you; you have options. Pick the one that's best for you.
I've noticed the same for R82 the recommended release a few days back was JHFA91, now JHFA is the only thing listed, but its not listed as recommended release.
Yeah, they did it for all of them. Looks like the CVEs are the reason this time. Phoneboy had another post about the recent Frontier AI model work (I'm guessing they got Mythos) finding issues in their code, so they proactively release CVEs and hotfixes for those issues. I'm sure they have individual hotfixes and portfixes available if one were to open a TAC case and ask.
These CVEs were found using our own internally-developed AI-driven tools.
More here: https://blog.checkpoint.com/security/check-point-frontier-ai-models-readiness-program-security-updat...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 5 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY