Palo Alto Networks Release Notes
11 release notes curated from 18 sources by the Releasebot Team. Last updated: Aug 14, 2026
- Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
Addressed Issues in VM-Series Plugin 6.1.2-h1
Palo Alto Networks fixes a VM-Series plugin issue that defaulted MP cores to 1 when fetching the coremask.
The following issue is addressed in the VM-Series plugin 6.1.2-h1.
PLUG-22078
Resolved an issue where the VM-Series plugin defaulted the MP cores to 1 with an error while fetching the MP coremask.
Original source - Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
Panorama Plugin for Azure 3.2.0
Palo Alto Networks expands the Panorama plugin for Azure with support for up to 500 subscriptions and adds proxy support for monitoring and orchestration between Panorama and Azure resources.
This release introduces additional subscriptions support and introduces proxy support for the Panorama plugin for Azure.
Increased Subscription Support for the VM-Series on Azure
Beginning with Panorama plugin for Azure 3.2.0 adds support for additional subscriptions; up to 500 subscriptions and, therefore, 500 monitoring definitions. For information about processing time for different amounts of configured subscriptions, see Set Up the Azure Plugin for Monitoring on Panorama.
Proxy Support for the Panorama Plugin for Azure
If there is a proxy server deployed between your Panorama instance and your Azure resources, you can configure the proxy server settings on Panorama to allow monitoring and orchestration. To configure a proxy server, complete the following steps.
- Log in to the Panorama web interface.
- Select Panorama Setup Services and click the Edit icon.
- Enter the proxy IP address in the Server field.
- Enter the proxy server Port.
- Enter the User name.
- Enter and confirm the proxy Password.
- Click OK.
- Commit your changes to Panorama.
All of your release notes in one feed
Join Releasebot and get updates from Palo Alto Networks and hundreds of other software products.
- Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
Panorama Plugin for VMware NSX 2.0.3
Palo Alto Networks fixes Panorama Plugin for VMware NSX 2.0.3 with sync, validation, and stability improvements, including dynamic address object synchronization, service name handling, longer NSX Manager curl timeouts, and updated dynamic update timestamps.
The following list describes issues addressed in the Panorama Plugin for VMware NSX 2.0.3.
PLUG-1244
Fixed an issue that caused the Panorama plugin for VMware NSX Service Definition and Service Manager configuration windows to appear with no configuration fields on an M-600 appliance.
PLUG-1159
The Panorama plugin for VMware NSX now checks the length of a Service Definition Name while creating it rather than when attempting to save the configuration. If the name exceeds 31 characters, the plugin displays a length validation error.
PLUG-1021
Fixed an issue that caused the NSX Service Manager status to go Out of Sync because NSX Custom Service name contains an ampersand (&). The Panorama plugin for VMware NSX now correctly handle custom service names that contain an ampersand.
PLUG-987
Fixed an issue that prevented NSX dynamic address objects from synchronizing to Panorama.
PLUG-964
The default timer for Panorama curl calls to NSX Manager has been increased from 30 seconds to 120 seconds.
PLUG-555
The Last Dynamic Update timestamp is updated under Panorama VMware NSX Service Managers when NSX manager pushes dynamic address updates to Panorama and when a manual sync is triggered by clicking Synchronize Dynamic Objects.
Original source - Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
Panorama Plugin for VMware NSX 2.0.2
Palo Alto Networks fixes multiple Panorama Plugin for VMware NSX sync and deletion issues, improving service manager stability, security group consistency, non-ASCII handling, HA connection behavior, and adding TLSv1.2 communication with NSX Manager.
The following list describes issues addressed in the Panorama Plugin for VMware NSX 2.0.2.
PLUG-421
Fixed an issue where the service manager status continuously switched from registered to out of sync.
PLUG-385
Fixed an issue that did not delete service manager configuration from the NSX Manager when the service manager was successfully deleted from Panorama.
PLUG-378
Fixed an issue where the service manager status goes Out of Sync upon upgrading Panorama to 8.1.0.
PLUG-377
Fixed an issue where IP addresses for security groups in NSX Manager fell out of sync with those in Panorama.
PLUG-357
Fixed an issue that prevented the NSX plugin from correctly handling non-ASCII characters in updates received from NSX Manager. This caused the deletion of dynamic address group objects containing non-ASCII characters after performing a manual config sync.
PLUG-334
Fixed an issue where, after disabling the connection between the Secondary HA Panorama and the NSX Manager, the Primary HA Panorama disables the connection with NSX Manager as well.
PLUG-252
Panorama now uses TLSv1.2 when communicating with NSX Manager.
Original source - Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
Panorama IPS Signature Converter Plugin 1.0.0
Palo Alto Networks adds the IPS Signature Converter plugin for Panorama, letting users translate Snort and Suricata rules into custom threat signatures, push them to firewalls, and enforce policy with Vulnerability Protection, Anti-Spyware, and external dynamic lists.
Snort and Suricata are open-source intrusion prevention system (IPS) tools that use uniquely formatted rules to detect threats. The IPS Signature Converter plugin enables you to leverage these rules for immediate threat protection by translating them into custom Palo Alto Networks threat signatures. You can then register the custom signatures on Palo Alto Networks firewalls in specified device groups and enforce policy using Vulnerability Protection and Anti-Spyware Security Profiles.
Additionally, you can export rules that list IP address indicators of compromise (IOC) and use the resultant text file as an external dynamic list to enforce policy on the entries contained in the list.
You can download the IPS Signature Converter plugin for Panorama™ 10.0 or later releases from the Customer Support Portal or directly from Panorama Plugins. Panorama can push the signatures that it converts to firewalls running a PAN-OS® 10.0 or later release.
To install the plugin, you must meet the following system requirements:
SOFTWARE | VERSION
- Panorama | PAN-OS 10.0.0
- PAN-OS (Firewall) | PAN-OS 10.0.0
- Content Version (on both Panorama and firewalls) | 8293 or a later version Review and Install Content Updates to get the latest content version.
Before you begin, make sure you review the following information:
- Known Issues in the IPS Signature Converter Plugin 1.0.0
Similar to Palo Alto Networks with recent updates:
- Smokeball release notes138 release notes · Latest Aug 12, 2026
- Cosmolex release notes20 release notes · Latest Jul 30, 2025
- PracticePanther release notes36 release notes · Latest Aug 11, 2026
- Salesforce release notes58 release notes · Latest Jul 1, 2026
- Microsoft release notes782 release notes · Latest Aug 13, 2026
- Zoom release notes205 release notes · Latest Jul 27, 2026
- Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
Panorama Plugin for Azure 5.2.2
Palo Alto Networks Panorama plugin for Azure 5.2.2 fixes license consumption and deployment issues for Cloud NGFW, shifts Cloud NGFW timing to Azure-provided NTP, and tightens template stack behavior by greying out an option that should not be changed.
The following list describes issues addressed in the Panorama plugin for Azure 5.2.2:
PLUG-16299
Fixed an issue where Inactive Cloud NGFWs that were previously deployed continued to consume Panorama licenses.
PLUG-17405
Cloud NGFW resources now rely on Azure-provided NTP (Network Timing Protocol) rather than being synchronized via Panorama.
PLUG-18149
Fixed an issue where you could not select an individual Cloud NGFW instance when deploying AV content.
PLUG-18220
Fixed a situation where, by default, changes to a template stack were automatically pushed to the Cloud NGFW resource. Panorama erroneously allowed you to change this default setting by selecting the option to automatically push content changes to the device registered with Panorama in the Template Stack screen. This option is now greyed out.
Original source - Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
Panorama Plugin for AWS 5.0.0
Palo Alto Networks notes known issues in Panorama Plugin for AWS 5.0.0 and highlights a fix in 5.1.1 for CloudFormation template stack deployment with AWS::EC2::VPCEndpointServicePermissions, helping users troubleshoot cloud device group and tenant behavior.
The following list describes known issues in the Panorama Plugin for AWS 5.0.0.
FWAAS-6633
A firewall commit might not be triggered after the first cloud device group config push from Panorama.
Workaround: Retry the cloud device group config push from Panorama
FWAAS-6542
Selecting a different template stack for an existing Cloud Device Group is not supported. Despite allowing this operation, the template stack is not updated.
FWAAS-6540
The Panorama plugin for AWS incorrectly allows you to select template stacks from different tenants for existing cloud device groups.
Workaround: Do not associate template stacks for the same cloud device group across tenants.
FWAAS-6536
The cloud decive groups of all tenants might not be displayed when All is selected from the Tenant drop-down on the Cloud Device Group page in the Panorama plugin for AWS.
Workaround: To view the cloud device groups associated with a particular tenant, select that tenant from the Tenant drop-down.
PLUG-12882
Fixed in Panorama plugin for AWS 5.1.1.
When using Panorama Plugin for AWS, the CloudFormation template stack deployment fails when creating AWS::EC2::VPCEndpointServicePermissions. To resolve this issue, include the parameter AllowedPrinciples in AWS::EC2::VPCEndpointServicePermissions. For example, the template should resemble:
Original source"VPCEndpointServicePermissions": { "Type" : "AWS::EC2::VPCEndpointServicePermissions", "Properties" : { "AllowedPrincipals" : ["*"], "ServiceId" : {"Ref": "VPCEndpointService"} }, "DependsOn": ["VPCEndpointService"] } - Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
Panorama Plugin for AWS 3.0.0
Palo Alto Networks releases Panorama plugin for AWS updates with VM Monitoring enhancements, AWS deployment and resource configuration orchestration, plus general fixes. It also adds CIDR support for VPCID display and improves virtual machine attribute handling for supported firewalls.
The Panorama plugin for AWS version 3.0.0 includes VM Monitoring enhancements, AWS deployment, and resource configuration orchestration on Panorama (new in this release), and general changes and fixes.
You can download the AWS plugin for Panorama from the Customer Support Portal or directly from Panorama Plugins. Panorama can push the virtual machine attributes that it retrieves to firewalls running the versions detailed in the plugin Compatibility Matrix for public clouds.
Refer to the VM-Series Deployment Guide for details on the Panorama plugin for AWS.
When you upgrade the AWS plugin to version 3.0.3, the previously configured custom tags get removed and select all 32 tags option is selected by default on the Notify Group dialogue box in Panorama.
After upgrading to AWS plugin version 3.0.0, public IP addresses are not retrieved when you use the tag combination with your VPC.
AWS plugin 3.0.X now supports CIDR format of VPCID that displays the subnet range instead of the list of IP addresses.
Original source - Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
PAN-OS Plugin for ADEM 1.1.0-h3
Palo Alto Networks releases the PAN-OS plugin for ADEM, expanding application experience monitoring to next-generation firewalls for a broader view of user digital experience. The 1.1.0-h3 update also includes addressed issues and known issue guidance.
Here are the updates released in 1.1.0-h3.
Known Issues in 1.1.0-h3
Known issues for the ADEM plugin 1.1.0-h3 release.
ISSUE ID | DESCRIPTION
DEM-9284 | When creating tests for NGFW Remote Sites, the Application Entities field is marked Optional. This field is mandatory and will cause tests to fail if left empty.
DEM-9966 | In the event of mismatched GlobalProtect Gateway names, the firewall will not appear in the Gateway location map (Application Experience >Map).
DEM-11607 | In Insights > Application Experience > Remote Site Experience >Global Distribution of Application Experience Scores for Remote Sites, the map displays incorrect number of sites in wrong locations and fails to show their proper site names.Addressed Issues in 1.1.0-h3
Addressed issues for the ADEM plugin 1.1.0-h3 release.
ISSUE ID
NETVIS-5371PAN-OS Plugin for ADEM 1.0.1
The PAN-OS plugin for ADEM Version 1.0.1 was released on 4.24.2025, review the following information below:
Known Issues in 1.0.1
Known issues for the ADEM plugin 1.0.1 release.
ISSUE ID | DESCRIPTION
DEM-9284 | When creating tests for NGFW Remote Sites, the Application Entities field is marked Optional. This field is mandatory and will cause tests to fail if left empty.
DEM-9966 | In the event of mismatched GlobalProtect Gateway names, the firewall will not appear in the Gateway location map (Application Experience >Map).
NETVIS-5371 | In Activity Insights > Users the NGFW Gateway Location does not match users connected through a GlobalProtect Gateway.Addressed Issues in 1.0.1
Addressed issues for the ADEM plugin 1.0.1 release.
ISSUE ID
DEM-10036
DEM-10197PAN-OS Plugin for ADEM 1.0.0
The PAN-OS plugin for ADEM Version 1.0.0 was released on 4.17.2025, review the following information below:
Features Introduced in 1.0.0
Key feature(s) introduced with the ADEM plugin 1.0.0 release.
NEW FEATURE | DESCRIPTION
Initial Release | Introducing the PAN-OS plugin for ADEM. Autonomous Digital Experience Management (ADEM) now extends its end-to-end application experience and performance monitoring capabilities beyond the SASE platform to next-generation firewalls (NGFWs) for a more comprehensive view into your users’ digital experience.Changes to Default Behavior in 1.0.0
Changes to default behavior introduced with the ADEM plugin 1.0.0 release.
CHANGE | DESCRIPTION
Initial Release | Users can now use ADEM to monitor NGFWs.Known Issues in 1.0.0
Known issues for ADEM plugin 1.0.0 the release.
ISSUE ID | DESCRIPTION
Original source
DEM-9284 | When creating tests for NGFW Remote Sites, the Application Entities field is marked Optional. This field is mandatory and will cause tests to fail if left empty.
DEM-9966 | In the event of mismatched GlobalProtect Gateway names, the firewall will not appear in the Gateway location map (Application Experience >Map).
DEM-10036 | License status will incorrectly display as Failed when checking CLI status for NGFWs with a GlobalProtect license only.
NETVIS-5371 | In Activity Insights > Users the NGFW Gateway Location does not match users connected through a GlobalProtect Gateway. - Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
VM-Series Plugin 5.1.0
Palo Alto Networks releases VM-Series plugin 5.1.0 with fixes for VM-Series firewall users and updated compatibility for PAN-OS 11.2. It also reduces maximum session counts on supported memory profiles to help ensure enough memory for security features.
The VM-Series plugin 5.1.0 includes new fixes to improve your experience with the VM-Series firewall.
VM-Series plugin 5.1.0 is the minimum required plugin version for VM-Series firewall running PAN-OS 11.2.
Refer to the Compatibility Matrix to correlate this VM-Series plugin version with a PAN-OS version.
Reduce Maximum Session Count on VM-Series Firewalls
Beginning with PAN-11.2.0 and VM-Series plugin 5.1.0 (required for 11.2), the maximum session count has been reduced for each memory profile. This change helps ensure that the VM-Series firewall has enough memory to support the various features that secure your virtual network. Additionally, when GTP, session resiliency, or virtual system is enabled, the new maximum session counts are reduced by 30%. For example, if you deploy a VM-Series firewall with 14GB of memory, that firewall has a maximum session count of 1,100,000 sessions. However, if you enable session resiliency on that firewall, the maximum session count is reduced to 770,000 sessions.
Memory Old Maximum Session Count New Maximum Session Count 4.5GB 20,000 — 5GB 40,000 — 5.5GB 50,000 — 6GB 100,000 — 6.5GB 200,000 — 7GB 300,000 250,000 8GB 500,000 300,000 9GB 600,000 400,000 10GB 800,000 500,000 12GB 1,000,000 800,000 14GB 1,100,000 1,100,000 16GB 1,100,000 1,100,000 18GB 1,200,000 1,200,000 20GB 1,800,000 1,800,000 24GB 3,600,000 2,500,000 28GB 4,400,000 2,800,000 32GB 5,200,000 3,500,000 36GB 6,000,000 4,500,000 40GB 6,800,000 5,500,000 44GB 7,600,000 6,750,000 48GB 8,400,000 7,000,000 52GB 9,200,000 8,150,000 56GB 10,000,000 8,500,000 64GB 10,000,000 8,250,000 128GB 14,000,000 10,000,000 Original source - Jul 30, 2026
- Date parsed from source:Jul 30, 2026
- First seen by Releasebot:Aug 14, 2026
VM-Series Plugin 3.0.0
Palo Alto Networks publishes VM-Series Plugin 3.0.0 known issues, covering licensing updates, HA upgrade ordering, cloud bootstrap and logging quirks, and performance impacts, with one OCI login issue fixed in plugin 2.1.8.
Known Issues in VM-Series Plugin 3.0.0
The following list describes known issues in the VM-Series Plugin 3.0.0.
PLUG-10392
License information is not updated when cores are changed using CLI.PLUG-10069
When upgrading the VM-Series firewall running PAN-OS 10.1.0, 10.1.1, 10.1.2, 10.1.3, or 10.1.4 in an HA deployment, you must first upgrade the VM-Series plugin to version 2.1.5 before upgrading to PAN-OS 10.2. Additionally, the upgrade must be performed in the following order:- Upgrade VM-Series plugin to 2.1.5 on the Active peer.
- Upgrade VM-Series plugin to 2.1.5 on the Passive peer.
- Upgrade PAN-OS to 10.2 on the Passive peer.
- Upgrade PAN-OS to 10.2 on the Active peer.
PLUG-10082
Virtual Machines with actual memory greater than 120GB will be recognized as Tier-4(T4-128GB model) firewall.PLUG-9987
On a VM deployed in Azure environment, the validate button at
Device
VM-Series
Azure HA Configuration
Edit
displays the error
resource-mgr-endpoint is invalid
if the resource manager endpoint is not configured.PLUG-9983
AWS PA-VM does not associate with a collector group on Panorama, if the collector group name is given as userdata on AWS, during bootstrap.PLUG-9933
In OCI cloud, logging in to PA-VM fails if user data is missing a new line.
Fixed in VM-Series plugin 2.1.8.PLUG-9868
In AWS FIPS-CC enabled PA-VMs, the HA failover is impaired on interface-move mode.PLUG-9771
Performance impact(high utilization of the CPU) is observed on vmxnet3(Esxi) and ena(AWS) driver based VM-Series Firewalls due to
dpdk-rx-queue-num
set to 1 for PAYG images.
This is the end. You've seen all the release notes in this feed!
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.