- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-11-2026 07:29 AM
Anyone else seeing this? Its slowing all our servers down and VM's
08-11-2026 08:05 AM
Hello @Joe-Oberfoell ,
Greetings for the day.
Regarding the high CPU usage observed after the Cortex XDR 2380 content update, this is a known phenomenon that can occur when a content update triggers intensive security scans or encounters resource contention, particularly on high-load servers like ADFS WAP or database servers .
For a thorough investigation, I recommend raising a TAC support ticket with the Cortex XDR Palo Alto Networks team. They can perform an in-depth analysis to identify the root cause (RCA) and provide the necessary resolution.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
08-11-2026 08:19 AM
Thx, I did open a ticket. This is the 1st time in 4 years a content update has ever slowed us down.
08-11-2026 11:39 AM
Hi.
We have same issue.
cortex-xdr-payload.exe is scanning our disks at 200-250 MB per second.
What the hell was this?
Also we have in logs 1 minute after this update so it definitely correlates :
EVENT LOG CONTENT: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
. This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {7e47b561-971a-46e6-96b9-696eeaa53b2a}
Writer Name: MSMQ Writer (MSMQ)
Writer Instance Name: MSMQ Writer (MSMQ)
Writer Instance ID: {785f9b7b-08b0-4426-8ee9-d1be09549405} - (WindowsAppLog)
Please @Joe-Oberfoell post here what support says.
@susekar forward this to support, this is NOT normal and it is first time that happened to us.
Regards,Gregor
08-11-2026 07:23 PM
We had this same issue, to verify it was indeed the content update I powered back on some recently deprecated servers that didn't have the 2380 update. Let them sit and become idle, allowed the cortex connection in the firewall and it immediately spiked the CPU to about 10-15GHZ usage. We have large clusters and they are balanced on the weekends via DRS and unfortunately this did cause a disruption as some of our individual nodes got overwhelmed as they all seemed to update around the same time.
Same story - we've never experienced this in the ~3 years we've used cortex. Not sure how expanding resources is going to help when they are overwhelming the physical servers already with the availability they have and we can't control when they get the update.
08-12-2026 05:37 AM
Hello @Joe-Oberfoell , @Jeff_Carlisle , @GregorMustar ,
Thank you for the response.
Understood. Once the Support team investigates the issue with @Joe-Oberfoell in more detail and identifies the root cause, they can share the findings here.
Also, could you please share the support ticket number here for reference? This will allow us to review the details as needed.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
08-12-2026 05:47 AM
CASE #04164785
This was originally opened questioning the cortex VSS snapshots; this was because this is what we were seeing in the logs at the time of the CPU spike, I didn't find this post nor verify the 2380 update until after case was created.
Thanks,
Jeff
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

