Starting today November 21. 06am (local time in Germany) we could observe a lot of false positives with application control/url filter. Most of legitimate traffic will be detected as "ExpressVPN". This application has risk level critical and will be blocked.
Interesting detail, only traffic related to proxy connections will be detect as "expressVPN". We can see this for connections proxy => proxy and between client and proxy

This view shows timeline of the application "expressVPN" only:

Anyone seeing same problem?