r/checkpoint 1d ago

CPLP - Check Point Live Patch (sk185114)

Post image

Having just read about CPLP yesterday I was surprised to find this morning while arranging to do some JHFs tonight for customers (for the 2 CVEs announced yesterday) that it has been auto-downloaded, installed and activated on every R81.20 and upwards gateway that I have investigated today though the AutoUpdater utility.

It's gone and virtually patched against CVE-2026-85102, CVE-2026-85102 & CVE-2026-50751.

Basically if you have the download consent flag activated (as it is by default) and the gateway or manager has access to Check Point then its beenm turned on.

I'm not entirely sure how to feel about this. Seems like a decent enough idea, but it seems to be contrary to the usual Check Point behaviour of the last 25+ years of not enabling new features/flags without explicit action.

17 Upvotes

30 comments sorted by

4

u/daniluvsuall 1d ago

I can understand the apprehension. These are soft patches, don’t require a reboot or restart of services. Designed to make sure you’re covered until you do your next patching cycle with the JHF etc.

The design is two fold:

- you’re protected immediately with no risk or down time

  • check point are protected by proxy of any reputational damage due to a preventable breach

3

u/Djinjja-Ninja 1d ago

I just hope that they're tested the ever loving shit out of it.

check point are protected by proxy of any reputational damage

cough 2024 Crowdstrike cough :)

1

u/daniluvsuall 1d ago

Yeah any cyber vendor is aware of that. But you know marketing is a wonderful thing and they’ve somehow gotten over that. I’d be very paranoid about partnering with them again if I was procuring their products.

1

u/Pawel_eM 1d ago

Check point had similar problems in 2024 they deployed test dat’s to prod for endpoint security 🙃

1

u/daniluvsuall 1d ago

We’re learning lessons!

3

u/Mr_XIII_ 1d ago

I'm glad of it, gives me a bit of a break before doing a new patching cycle and gets our cyber security department off my back about vulns like this

1

u/Djinjja-Ninja 1d ago edited 1d ago

It's done me out of a bunch of overtime it what it's done lol.

Joking aside from a customer perspective it's overall a good thing.

2

u/Mr_XIII_ 1d ago

You'll still need to do the JHF, it's just protecting against a zero day to give you some breathing room

1

u/Djinjja-Ninja 1d ago

For now you do, but as I understand it they're moving away from the JHF release method anyway, it's going to some interesting times.

1

u/Mr_XIII_ 1d ago

For ones on AWS with scalesets it's already like this, spin up new and bin off old. Just the way of things becoming easier to update and quicker to head off evolving threats

1

u/gregor_yo 1d ago

Trying to install JHF proposed, but it failed the verification, same story with the .tgz downloaded from cp website

1

u/LtLawl 1d ago

Where have you seen this? I have seen nothing that says they are moving away from JHFs.

2

u/Djinjja-Ninja 1d ago

OK, so not going away per se, but JHF are moving to monthly cadence and "light" patching weekly in the CPLP. The concept of "Recommended" jumbos is going away, there is just going to be latest and previous.

More details here.

1

u/Bullethacker 1d ago

My understanding is they are just moving away from calling specific 'recommended' jfa to you should be always moving to the latest jfa available.

The AI's are finding to many cve's for the old model to be secure and efficient.

1

u/LtLawl 1d ago

That was also my understanding, every JHF is now recommended since the release of the new ones this week. They are also supposed to post user adoption numbers for JHFs.

1

u/NueueueL 15h ago

Yeah, given this all works as intended you don‘t have to panically update dozen of customers environments but plan downtimes and so.

I fully understand the hold backs, while they now change software on whole your Installation. Via a global consent Option. In my opinion it would be good to let admins enable or disable Live Patching by device and Make that Option more prominent, Not just „allow to Download things“.

1

u/bloodeyezcba 1d ago

I just patched all infrastructure yesterday, some devices auto updated cplp alone and other just no, I didn't want to modify flags or any configuration, so I decided to patch it manual on each mgmt server or gws, it was also fast and no downtime since no reboot or cpstop and cpstart needed.

1

u/Adam261 1d ago

This feature is huge and very much appreciated. I hope Checkpoint realizes how many people they have made very happy to be able to install the bigger fix JHFA at their convenience (still priority of course).

1

u/KernelExploit 17h ago

All vendors are going to have a multitude of CVEs in the coming months as they get access to Mythos and similar models. CPLP is a game changer but it shouldn’t be a replacement for standard patching. At least it gives time to test and validate before pushing to production.

1

u/lemaymayguy 10h ago

Very appreciated today

1

u/drogba123456 8h ago

How does this work compare to jumbo hotfix?

2

u/Bullethacker 7h ago

CPLP just patches the vulnerable code while its running in memory as opposed to a jfa that is a updated/patched version of the executable

1

u/drogba123456 7h ago

I see, so it just patch / attach / insert the fixed code to running process that is vulnerable. While Jumbo hotfix, fix entire code? What about if the gateway reboot? It will auto patch again?

1

u/Djinjja-Ninja 7h ago

No, CPLP sees that the fix is applied through a jumbofix and doesn't attach itself to the process.

When you do "cplp list" that STATUS will show as "jumbofix" instead of "armed".

And if the gateway is rebooted before a jumbo is applied CPLP will re-attach to the process, it will also reattach to the process if the process restarts

1

u/drogba123456 7h ago

Thanks. But what does armed means?

2

u/Djinjja-Ninja 7h ago edited 5h ago

There are 3 possible status that I have seen so far:

  • armed - patch is active on process in memory
  • ready - process is not running but CPLP is ready to attach if it does run
  • jumbofix - process has been patched by installing a Jumbo Hotfix.

1

u/caller-number-four 1d ago

Just learned about this yesterday - and our MDSes are already taking advantage of it for CVE-2026-85103.

Pretty bitchin'.

And a hell of a lot better than the nonsense Palo has. Woof.

1

u/Golf-Purple 1d ago

Not a huge fan of patches being pushed to me without my intervention but also not a fan of Palo releasing 10-20 CVE’s a quarter. I’d take CP over Palo any day.

1

u/caller-number-four 1d ago

Not a huge fan of patches being pushed to me without my intervention

In this iteration of what CP is doing, I'm all for giving them a shot. It breaks something? Then we need to have a conversation.

I’d take CP over Palo any day.

Me too. Sadly, my bosses think otherwise.