- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
AI Security Masters
LGTM: Bypassing an LLM Build Gate
When Prompt Injection Fails
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
CheckMates Go:
Half is Not Enough
This is exactly what I have been talking about.
I had issues with R82 JH Take 122. I had issues with R82 JH Take 126. And now, after installing the recently released R82 JH Take 127, I am experiencing issues again.
In all three cases, I had to uninstall the Jumbo Hotfix because of problems identified on the cluster during our maintenance and testing window. This environment belongs to an extremely important customer here in Brazil.
This is precisely my point: there is little benefit in releasing Jumbo Hotfixes quickly if it appears that they are not being tested thoroughly enough before release.
In our case, keeping critical customer environments compliant requires a significant operational effort. Obtaining a maintenance window can take weeks or even months of planning, including management approval and coordination across multiple teams. Having to roll back the update at the end of that process creates significant operational challenges, especially when management is also demanding compliance, CVE remediation, and an up-to-date environment.
For this reason, I strongly believe Jumbo Hotfixes need more extensive testing, and that Check Point needs to ensure the quality and stability of these packages, not only for customers but also for the engineers and teams responsible for maintaining these environments.
With JH Take 127, I am now seeing a serious issue during policy installation. At approximately 75% of the Install Policy process, the firewall starts experiencing severe packet loss affecting Internet-bound traffic, VPN traffic, and internal traffic. Once the policy installation finishes, traffic returns to normal. This behavior was not occurring before installing Take 127.
For now, I am remaining on JH Take 91.
At least I have enabled Check Point Live Patch (CPLP), which helps reduce some of the exposure. However, the latest CVE is not covered by CPLP. I have implemented all applicable mitigation measures to reduce the exposure to these CVEs and keep my customers' environments as protected as possible while maintaining the stability of their production systems.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY