Upgrading from 10.2.9-h1

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Upgrading from 10.2.9-h1

L1 Bithead

Hello,

We currently have two PA-3410 firewalls configured in HA, running PAN-OS 10.2.9-h1.

We are planning to upgrade to the preferred release PAN-OS 10.2.16-h6. However, after reviewing the security advisories, it appears that this version does not fully mitigate some vulnerabilities, including CVE-2026-0257.

Would it be advisable to upgrade directly to PAN-OS 10.2.16-h8 instead of 10.2.16-h6 to ensure all known CVEs are addressed? Has anyone encountered any issues or concerns with 10.2.16-h8 in a production HA environment?

Any recommendations would be appreciated.

 

Thanks

1 REPLY 1

Community Team Member

Hi @mmarie ,

 

I would recommend reviewing the known and addressed issues for both 10.2.16-h6 and 10.2.16-h8, then comparing those against the features you actually use in production and determine what is acceptable vs. unacceptable. 

 

As far as CVE-2026-0257 specifically, the advisory also lists mitigations if you need a temporary workaround while planning the upgrade:

 

  • Use a dedicated certificate for Authentication Override cookies. Do not reuse the portal/gateway certificate or share that certificate with other features.
  • Disable Authentication Override on the GlobalProtect portal and gateway by unchecking the options to generate and accept cookies.

 

For example, if Auth Override is enabled today, you could consider disabling it on both the GP portal and gateway as a temporary mitigation while you complete your upgrade review and change planning.

 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 95 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!