<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrading from 10.2.9-h1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-from-10-2-9-h1/m-p/1256403#M126599</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184904"&gt;@mmarie&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt; I would recommend reviewing the known and addressed issues for both &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-16-known-and-addressed-issues/pan-os-10-2-16-known-issues" target="_self"&gt;&lt;STRONG&gt;&lt;SPAN&gt;10.2.16-h6&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-16-known-and-addressed-issues/pan-os-10-2-16-h8-addressed-issues" target="_self"&gt;&lt;STRONG&gt;&lt;SPAN&gt;10.2.16-h8&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt;, then comparing those against the features you actually use in production and determine what is acceptable vs. unacceptable.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;As far as CVE-2026-0257 specifically, the advisory also lists mitigations if you need a temporary workaround while planning the upgrade:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Use a dedicated certificate for Authentication Override cookies. Do not reuse the portal/gateway certificate or share that certificate with other features.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Disable Authentication Override on the GlobalProtect portal and gateway by unchecking the options to generate and accept cookies.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For example, if Auth Override is enabled today, you could consider disabling it on both the GP portal and gateway as a temporary mitigation while you complete your upgrade review and change planning.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jun 2026 01:24:03 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2026-06-16T01:24:03Z</dc:date>
    <item>
      <title>Upgrading from 10.2.9-h1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-from-10-2-9-h1/m-p/1256305#M126594</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;We currently have two PA-3410 firewalls configured in HA, running PAN-OS 10.2.9-h1.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;We are planning to upgrade to the preferred release PAN-OS 10.2.16-h6. However, after reviewing the security advisories, it appears that this version does not fully mitigate some vulnerabilities, including CVE-2026-0257.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Would it be advisable to upgrade directly to PAN-OS 10.2.16-h8 instead of 10.2.16-h6 to ensure all known CVEs are addressed? Has anyone encountered any issues or concerns with 10.2.16-h8 in a production HA environment?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any recommendations would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2026 11:52:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-from-10-2-9-h1/m-p/1256305#M126594</guid>
      <dc:creator>mmarie</dc:creator>
      <dc:date>2026-06-14T11:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading from 10.2.9-h1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/upgrading-from-10-2-9-h1/m-p/1256403#M126599</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184904"&gt;@mmarie&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt; I would recommend reviewing the known and addressed issues for both &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-16-known-and-addressed-issues/pan-os-10-2-16-known-issues" target="_self"&gt;&lt;STRONG&gt;&lt;SPAN&gt;10.2.16-h6&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-16-known-and-addressed-issues/pan-os-10-2-16-h8-addressed-issues" target="_self"&gt;&lt;STRONG&gt;&lt;SPAN&gt;10.2.16-h8&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt;, then comparing those against the features you actually use in production and determine what is acceptable vs. unacceptable.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;As far as CVE-2026-0257 specifically, the advisory also lists mitigations if you need a temporary workaround while planning the upgrade:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;Use a dedicated certificate for Authentication Override cookies. Do not reuse the portal/gateway certificate or share that certificate with other features.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Disable Authentication Override on the GlobalProtect portal and gateway by unchecking the options to generate and accept cookies.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For example, if Auth Override is enabled today, you could consider disabling it on both the GP portal and gateway as a temporary mitigation while you complete your upgrade review and change planning.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 01:24:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/upgrading-from-10-2-9-h1/m-p/1256403#M126599</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-06-16T01:24:03Z</dc:date>
    </item>
  </channel>
</rss>

