Thank you for the post @BigPalo If you are looking only into fixing vulnerability issue, then today, Palo Alto released version with fix: 9.0.15, 9.1.12-h3 and 10.0.8-h8, so you do not have to go all the way up to: 10.1.3-h1. Regarding backward compatibility between Panorama and managed Firewalls, as long as Panorama is running higher version than managed Firewall all should work, however based on my experience, by pushing configurations to Firewalls running 8.1 I occasionally get minor issues that config was not applied. Lastly, PAN-OS 8.1 and 9.0 will be end of life on 1st March 2022, so you should look into upgrade soon. Kind Regards Pavel
... View more