Palo Alto Networks Release Notes

Follow

11 release notes curated from 18 sources by the Releasebot Team. Last updated: Aug 14, 2026

Get this feed:
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Addressed Issues in VM-Series Plugin 6.1.2-h1

    Palo Alto Networks fixes a VM-Series plugin issue that defaulted MP cores to 1 when fetching the coremask.

    The following issue is addressed in the VM-Series plugin 6.1.2-h1.

    PLUG-22078

    Resolved an issue where the VM-Series plugin defaulted the MP cores to 1 with an error while fetching the MP coremask.

    Original source
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Panorama Plugin for Azure 3.2.0

    Palo Alto Networks expands the Panorama plugin for Azure with support for up to 500 subscriptions and adds proxy support for monitoring and orchestration between Panorama and Azure resources.

    This release introduces additional subscriptions support and introduces proxy support for the Panorama plugin for Azure.

    Increased Subscription Support for the VM-Series on Azure

    Beginning with Panorama plugin for Azure 3.2.0 adds support for additional subscriptions; up to 500 subscriptions and, therefore, 500 monitoring definitions. For information about processing time for different amounts of configured subscriptions, see Set Up the Azure Plugin for Monitoring on Panorama.

    Proxy Support for the Panorama Plugin for Azure

    If there is a proxy server deployed between your Panorama instance and your Azure resources, you can configure the proxy server settings on Panorama to allow monitoring and orchestration. To configure a proxy server, complete the following steps.

    • Log in to the Panorama web interface.
    • Select Panorama Setup Services and click the Edit icon.
    • Enter the proxy IP address in the Server field.
    • Enter the proxy server Port.
    • Enter the User name.
    • Enter and confirm the proxy Password.
    • Click OK.
    • Commit your changes to Panorama.
    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Palo Alto Networks and hundreds of other software products.

    Create account
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Panorama Plugin for VMware NSX 2.0.3

    Palo Alto Networks fixes Panorama Plugin for VMware NSX 2.0.3 with sync, validation, and stability improvements, including dynamic address object synchronization, service name handling, longer NSX Manager curl timeouts, and updated dynamic update timestamps.

    The following list describes issues addressed in the Panorama Plugin for VMware NSX 2.0.3.

    PLUG-1244

    Fixed an issue that caused the Panorama plugin for VMware NSX Service Definition and Service Manager configuration windows to appear with no configuration fields on an M-600 appliance.

    PLUG-1159

    The Panorama plugin for VMware NSX now checks the length of a Service Definition Name while creating it rather than when attempting to save the configuration. If the name exceeds 31 characters, the plugin displays a length validation error.

    PLUG-1021

    Fixed an issue that caused the NSX Service Manager status to go Out of Sync because NSX Custom Service name contains an ampersand (&). The Panorama plugin for VMware NSX now correctly handle custom service names that contain an ampersand.

    PLUG-987

    Fixed an issue that prevented NSX dynamic address objects from synchronizing to Panorama.

    PLUG-964

    The default timer for Panorama curl calls to NSX Manager has been increased from 30 seconds to 120 seconds.

    PLUG-555

    The Last Dynamic Update timestamp is updated under Panorama VMware NSX Service Managers when NSX manager pushes dynamic address updates to Panorama and when a manual sync is triggered by clicking Synchronize Dynamic Objects.

    Original source
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Panorama Plugin for VMware NSX 2.0.2

    Palo Alto Networks fixes multiple Panorama Plugin for VMware NSX sync and deletion issues, improving service manager stability, security group consistency, non-ASCII handling, HA connection behavior, and adding TLSv1.2 communication with NSX Manager.

    The following list describes issues addressed in the Panorama Plugin for VMware NSX 2.0.2.

    PLUG-421

    Fixed an issue where the service manager status continuously switched from registered to out of sync.

    PLUG-385

    Fixed an issue that did not delete service manager configuration from the NSX Manager when the service manager was successfully deleted from Panorama.

    PLUG-378

    Fixed an issue where the service manager status goes Out of Sync upon upgrading Panorama to 8.1.0.

    PLUG-377

    Fixed an issue where IP addresses for security groups in NSX Manager fell out of sync with those in Panorama.

    PLUG-357

    Fixed an issue that prevented the NSX plugin from correctly handling non-ASCII characters in updates received from NSX Manager. This caused the deletion of dynamic address group objects containing non-ASCII characters after performing a manual config sync.

    PLUG-334

    Fixed an issue where, after disabling the connection between the Secondary HA Panorama and the NSX Manager, the Primary HA Panorama disables the connection with NSX Manager as well.

    PLUG-252

    Panorama now uses TLSv1.2 when communicating with NSX Manager.

    Original source
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Panorama IPS Signature Converter Plugin 1.0.0

    Palo Alto Networks adds the IPS Signature Converter plugin for Panorama, letting users translate Snort and Suricata rules into custom threat signatures, push them to firewalls, and enforce policy with Vulnerability Protection, Anti-Spyware, and external dynamic lists.

    Snort and Suricata are open-source intrusion prevention system (IPS) tools that use uniquely formatted rules to detect threats. The IPS Signature Converter plugin enables you to leverage these rules for immediate threat protection by translating them into custom Palo Alto Networks threat signatures. You can then register the custom signatures on Palo Alto Networks firewalls in specified device groups and enforce policy using Vulnerability Protection and Anti-Spyware Security Profiles.

    Additionally, you can export rules that list IP address indicators of compromise (IOC) and use the resultant text file as an external dynamic list to enforce policy on the entries contained in the list.

    You can download the IPS Signature Converter plugin for Panorama™ 10.0 or later releases from the Customer Support Portal or directly from Panorama Plugins. Panorama can push the signatures that it converts to firewalls running a PAN-OS® 10.0 or later release.

    To install the plugin, you must meet the following system requirements:

    SOFTWARE | VERSION

    • Panorama | PAN-OS 10.0.0
    • PAN-OS (Firewall) | PAN-OS 10.0.0
    • Content Version (on both Panorama and firewalls) | 8293 or a later version Review and Install Content Updates to get the latest content version.

    Before you begin, make sure you review the following information:

    • Known Issues in the IPS Signature Converter Plugin 1.0.0
    Original source
  • Similar to Palo Alto Networks with recent updates:

  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Panorama Plugin for Azure 5.2.2

    Palo Alto Networks Panorama plugin for Azure 5.2.2 fixes license consumption and deployment issues for Cloud NGFW, shifts Cloud NGFW timing to Azure-provided NTP, and tightens template stack behavior by greying out an option that should not be changed.

    The following list describes issues addressed in the Panorama plugin for Azure 5.2.2:

    PLUG-16299

    Fixed an issue where Inactive Cloud NGFWs that were previously deployed continued to consume Panorama licenses.

    PLUG-17405

    Cloud NGFW resources now rely on Azure-provided NTP (Network Timing Protocol) rather than being synchronized via Panorama.

    PLUG-18149

    Fixed an issue where you could not select an individual Cloud NGFW instance when deploying AV content.

    PLUG-18220

    Fixed a situation where, by default, changes to a template stack were automatically pushed to the Cloud NGFW resource. Panorama erroneously allowed you to change this default setting by selecting the option to automatically push content changes to the device registered with Panorama in the Template Stack screen. This option is now greyed out.

    Original source
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Panorama Plugin for AWS 5.0.0

    Palo Alto Networks notes known issues in Panorama Plugin for AWS 5.0.0 and highlights a fix in 5.1.1 for CloudFormation template stack deployment with AWS::EC2::VPCEndpointServicePermissions, helping users troubleshoot cloud device group and tenant behavior.

    The following list describes known issues in the Panorama Plugin for AWS 5.0.0.

    FWAAS-6633

    A firewall commit might not be triggered after the first cloud device group config push from Panorama.

    Workaround: Retry the cloud device group config push from Panorama

    FWAAS-6542

    Selecting a different template stack for an existing Cloud Device Group is not supported. Despite allowing this operation, the template stack is not updated.

    FWAAS-6540

    The Panorama plugin for AWS incorrectly allows you to select template stacks from different tenants for existing cloud device groups.

    Workaround: Do not associate template stacks for the same cloud device group across tenants.

    FWAAS-6536

    The cloud decive groups of all tenants might not be displayed when All is selected from the Tenant drop-down on the Cloud Device Group page in the Panorama plugin for AWS.

    Workaround: To view the cloud device groups associated with a particular tenant, select that tenant from the Tenant drop-down.

    PLUG-12882

    Fixed in Panorama plugin for AWS 5.1.1.

    When using Panorama Plugin for AWS, the CloudFormation template stack deployment fails when creating AWS::EC2::VPCEndpointServicePermissions. To resolve this issue, include the parameter AllowedPrinciples in AWS::EC2::VPCEndpointServicePermissions. For example, the template should resemble:

    "VPCEndpointServicePermissions": {
      "Type" : "AWS::EC2::VPCEndpointServicePermissions",
      "Properties" : {
          "AllowedPrincipals" : ["*"],
          "ServiceId" : {"Ref": "VPCEndpointService"}
      },
      "DependsOn": ["VPCEndpointService"]
    }
    
    Original source
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Panorama Plugin for AWS 3.0.0

    Palo Alto Networks releases Panorama plugin for AWS updates with VM Monitoring enhancements, AWS deployment and resource configuration orchestration, plus general fixes. It also adds CIDR support for VPCID display and improves virtual machine attribute handling for supported firewalls.

    The Panorama plugin for AWS version 3.0.0 includes VM Monitoring enhancements, AWS deployment, and resource configuration orchestration on Panorama (new in this release), and general changes and fixes.

    You can download the AWS plugin for Panorama from the Customer Support Portal or directly from Panorama Plugins. Panorama can push the virtual machine attributes that it retrieves to firewalls running the versions detailed in the plugin Compatibility Matrix for public clouds.

    Refer to the VM-Series Deployment Guide for details on the Panorama plugin for AWS.

    When you upgrade the AWS plugin to version 3.0.3, the previously configured custom tags get removed and select all 32 tags option is selected by default on the Notify Group dialogue box in Panorama.

    After upgrading to AWS plugin version 3.0.0, public IP addresses are not retrieved when you use the tag combination with your VPC.

    AWS plugin 3.0.X now supports CIDR format of VPCID that displays the subnet range instead of the list of IP addresses.

    Original source
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS Plugin for ADEM 1.1.0-h3

    Palo Alto Networks releases the PAN-OS plugin for ADEM, expanding application experience monitoring to next-generation firewalls for a broader view of user digital experience. The 1.1.0-h3 update also includes addressed issues and known issue guidance.

    Here are the updates released in 1.1.0-h3.

    Known Issues in 1.1.0-h3

    Known issues for the ADEM plugin 1.1.0-h3 release.

    ISSUE ID | DESCRIPTION
    DEM-9284 | When creating tests for NGFW Remote Sites, the Application Entities field is marked Optional. This field is mandatory and will cause tests to fail if left empty.
    DEM-9966 | In the event of mismatched GlobalProtect Gateway names, the firewall will not appear in the Gateway location map (Application Experience >Map).
    DEM-11607 | In Insights > Application Experience > Remote Site Experience >Global Distribution of Application Experience Scores for Remote Sites, the map displays incorrect number of sites in wrong locations and fails to show their proper site names.

    Addressed Issues in 1.1.0-h3

    Addressed issues for the ADEM plugin 1.1.0-h3 release.

    ISSUE ID
    NETVIS-5371

    PAN-OS Plugin for ADEM 1.0.1

    The PAN-OS plugin for ADEM Version 1.0.1 was released on 4.24.2025, review the following information below:

    Known Issues in 1.0.1

    Known issues for the ADEM plugin 1.0.1 release.

    ISSUE ID | DESCRIPTION
    DEM-9284 | When creating tests for NGFW Remote Sites, the Application Entities field is marked Optional. This field is mandatory and will cause tests to fail if left empty.
    DEM-9966 | In the event of mismatched GlobalProtect Gateway names, the firewall will not appear in the Gateway location map (Application Experience >Map).
    NETVIS-5371 | In Activity Insights > Users the NGFW Gateway Location does not match users connected through a GlobalProtect Gateway.

    Addressed Issues in 1.0.1

    Addressed issues for the ADEM plugin 1.0.1 release.

    ISSUE ID
    DEM-10036
    DEM-10197

    PAN-OS Plugin for ADEM 1.0.0

    The PAN-OS plugin for ADEM Version 1.0.0 was released on 4.17.2025, review the following information below:

    Features Introduced in 1.0.0

    Key feature(s) introduced with the ADEM plugin 1.0.0 release.

    NEW FEATURE | DESCRIPTION
    Initial Release | Introducing the PAN-OS plugin for ADEM. Autonomous Digital Experience Management (ADEM) now extends its end-to-end application experience and performance monitoring capabilities beyond the SASE platform to next-generation firewalls (NGFWs) for a more comprehensive view into your users’ digital experience.

    Changes to Default Behavior in 1.0.0

    Changes to default behavior introduced with the ADEM plugin 1.0.0 release.

    CHANGE | DESCRIPTION
    Initial Release | Users can now use ADEM to monitor NGFWs.

    Known Issues in 1.0.0

    Known issues for ADEM plugin 1.0.0 the release.

    ISSUE ID | DESCRIPTION
    DEM-9284 | When creating tests for NGFW Remote Sites, the Application Entities field is marked Optional. This field is mandatory and will cause tests to fail if left empty.
    DEM-9966 | In the event of mismatched GlobalProtect Gateway names, the firewall will not appear in the Gateway location map (Application Experience >Map).
    DEM-10036 | License status will incorrectly display as Failed when checking CLI status for NGFWs with a GlobalProtect license only.
    NETVIS-5371 | In Activity Insights > Users the NGFW Gateway Location does not match users connected through a GlobalProtect Gateway.

    Original source
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    VM-Series Plugin 5.1.0

    Palo Alto Networks releases VM-Series plugin 5.1.0 with fixes for VM-Series firewall users and updated compatibility for PAN-OS 11.2. It also reduces maximum session counts on supported memory profiles to help ensure enough memory for security features.

    The VM-Series plugin 5.1.0 includes new fixes to improve your experience with the VM-Series firewall.

    VM-Series plugin 5.1.0 is the minimum required plugin version for VM-Series firewall running PAN-OS 11.2.

    Refer to the Compatibility Matrix to correlate this VM-Series plugin version with a PAN-OS version.

    Reduce Maximum Session Count on VM-Series Firewalls

    Beginning with PAN-11.2.0 and VM-Series plugin 5.1.0 (required for 11.2), the maximum session count has been reduced for each memory profile. This change helps ensure that the VM-Series firewall has enough memory to support the various features that secure your virtual network. Additionally, when GTP, session resiliency, or virtual system is enabled, the new maximum session counts are reduced by 30%. For example, if you deploy a VM-Series firewall with 14GB of memory, that firewall has a maximum session count of 1,100,000 sessions. However, if you enable session resiliency on that firewall, the maximum session count is reduced to 770,000 sessions.

    Memory Old Maximum Session Count New Maximum Session Count 4.5GB 20,000 — 5GB 40,000 — 5.5GB 50,000 — 6GB 100,000 — 6.5GB 200,000 — 7GB 300,000 250,000 8GB 500,000 300,000 9GB 600,000 400,000 10GB 800,000 500,000 12GB 1,000,000 800,000 14GB 1,100,000 1,100,000 16GB 1,100,000 1,100,000 18GB 1,200,000 1,200,000 20GB 1,800,000 1,800,000 24GB 3,600,000 2,500,000 28GB 4,400,000 2,800,000 32GB 5,200,000 3,500,000 36GB 6,000,000 4,500,000 40GB 6,800,000 5,500,000 44GB 7,600,000 6,750,000 48GB 8,400,000 7,000,000 52GB 9,200,000 8,150,000 56GB 10,000,000 8,500,000 64GB 10,000,000 8,250,000 128GB 14,000,000 10,000,000 Original source
  • Jul 30, 2026
    • Date parsed from source:
      Jul 30, 2026
    • First seen by Releasebot:
      Aug 14, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    VM-Series Plugin 3.0.0

    Palo Alto Networks publishes VM-Series Plugin 3.0.0 known issues, covering licensing updates, HA upgrade ordering, cloud bootstrap and logging quirks, and performance impacts, with one OCI login issue fixed in plugin 2.1.8.

    Known Issues in VM-Series Plugin 3.0.0

    The following list describes known issues in the VM-Series Plugin 3.0.0.

    • PLUG-10392
      License information is not updated when cores are changed using CLI.

    • PLUG-10069
      When upgrading the VM-Series firewall running PAN-OS 10.1.0, 10.1.1, 10.1.2, 10.1.3, or 10.1.4 in an HA deployment, you must first upgrade the VM-Series plugin to version 2.1.5 before upgrading to PAN-OS 10.2. Additionally, the upgrade must be performed in the following order:

      1. Upgrade VM-Series plugin to 2.1.5 on the Active peer.
      2. Upgrade VM-Series plugin to 2.1.5 on the Passive peer.
      3. Upgrade PAN-OS to 10.2 on the Passive peer.
      4. Upgrade PAN-OS to 10.2 on the Active peer.
    • PLUG-10082
      Virtual Machines with actual memory greater than 120GB will be recognized as Tier-4(T4-128GB model) firewall.

    • PLUG-9987
      On a VM deployed in Azure environment, the validate button at
      Device
      VM-Series
      Azure HA Configuration
      Edit
      displays the error
      resource-mgr-endpoint is invalid
      if the resource manager endpoint is not configured.

    • PLUG-9983
      AWS PA-VM does not associate with a collector group on Panorama, if the collector group name is given as userdata on AWS, during bootstrap.

    • PLUG-9933
      In OCI cloud, logging in to PA-VM fails if user data is missing a new line.
      Fixed in VM-Series plugin 2.1.8.

    • PLUG-9868
      In AWS FIPS-CC enabled PA-VMs, the HA failover is impaired on interface-move mode.

    • PLUG-9771
      Performance impact(high utilization of the CPU) is observed on vmxnet3(Esxi) and ena(AWS) driver based VM-Series Firewalls due to
      dpdk-rx-queue-num
      set to 1 for PAYG images.

    Original source

This is the end. You've seen all the release notes in this feed!

Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.