*** 12.4.3 Aug 2026 Platform Hotfix *** Name: pform-hotfix-12.4.3-03526 Type: Hotfix Date: Fri Aug 28 14:49:33 UTC 2026 Build: 12.4.3-03526 Issues fixed in pform-hotfix-12.4.3-03526: SMA1000-9428 [Vulnerability] Pre-authentication SSRF via unintended forward-proxy SMA1000-9226 [Vulnerability] Post-authentication Remote Code Execution (RCE) Vulnerability Issues fixed in previous pform-hotfix-12.4.3 releases: SMA1000-9054 [Vulnerability] RCE in SMA1000 SMA1000-9057 [Vulnerability] Pre auth SSRF SMA1000-8896 FIPS: RSA verification is buggy SMA1000-8612 Azure instance Change in interface speed observed post applying dec hotfix for 12.4.3 causing resource access failure. SMA1000-8719 GTO DNS alert is active on CMS even though external delegations are correct SMA1000-8783 Appliance drops user frequently causing production issues SMA1000-8824 Remove usage of NGINX Unit -- it has been abandoned by its maintainers SMA1000-8843 CouchDB logs about source/destination addresses are using the wrong address when accessed through the port 6984 NGINX proxy SMA1000-8951 AMC allows invalid IPv4 address in subnet resources, causes PS to fail parsing policy_file.xml SMA1000-8921 CVE-2026-43038: Update kernel for ICMP error SMA1000-8949 AD ADV authentication failure for forest child users & cross-forest trust users. SMA1000-8985 Apache HTTP/2 memory vulnerabilities (CVE-2026-49975) SMA1000-8700 [Vulnerability] TOTP bypass when using AD/LDAP authentication in AMC SMA1000-8714 [Vulnerability] SQL injection on AMC User Sessions page SMA1000-8739 CVE-2026-24486: python-multipart arbitrary file-write SMA1000-7410 Issue with website shortcut for application that uses web socket connections SMA1000-8045 License on CMS count never matches individual appliance count summed up. SMA1000-8387 Unable to access CMS Admin console SMA1000-8544 Ensure root filesystem can be safely checked / repaired during boot process SMA1000-8557 Better filesystem error handling SMA1000-8576 Appliance drops 1360 users generates Vmcore takes a while to restore SMA1000-8580 Inotify leads to spurious GTO reconfig SMA1000-8484 Incorrect display size for RDP shortcut SMA1000-8492 Need better 'secure erase' functionality for new hardware with NVME drive SMA1000-8514 Error observed when accessing custom URL resource from Workplace SMA1000-8596 Physical Appliances show deprecated user option 'image' when logging in recovery partition using GRUB. SMA1000-8602 Avpsd and logserver cores dumped post-install Pform-hotfix-03245 SMA1000-8616 Appliance generating unit cores not during hotfix installation but post few hours SMA1000-8654 Logs failing to push to multiple syslog servers SMA1000-8666 irqaffinity script shows errors on single-homed virtual appliances SMA1000-8399 SAML authentication using web-auth mode fails on Mac CT SMA1000-8307 Entropy falls back to RDSEED on AMD Processors SMA1000-8392 Need to increase the 'processing cost' of our local auth and admin passwords SMA1000-8430 Hostnames processed through infoblox for processing DDNS does have issues. SMA1000-8474 Citrix workspace over ODP is not working in hostname mapped access SMA1000-8226 Getting Submitted by: Unknown in Capture ATP report SMA1000-8247 Path-relative style sheet import used in Virtual Key Board SMA1000-8264 AMC showing all signature algorithms while generating RSA LE certificate SMA1000-8270 Unable to see full details of connected user from CMS User Sessions SMA1000-8285 Support TS Farms with load balance info for standalone RDP shortcuts with native RDP client SMA1000-8359 Saving a WorkPlace Style with an empty title or greeting results in corrupted config when pending changes are applied SMA1000-8362 Unable to Disable "Enable Access to URLs" in WorkPlace Settings SMA1000-8374 Update OpenSSL for various CVEs SMA1000-8385 Need an option to disable change password option with Local Authentication server SMA1000-8410 ActiveSync - New account adding is broken SMA1000-8415 Upgrade OpenJDK to 11.0.29 for multiple CVEs SMA1000-8424 UTF-8, OTP sent to users seen with garbled message (Korean Characters) SMA1000-8016 User Drop / Service restart and resumed automatically after few mins. SMA1000-8023 Installed client list Could not be obtained due to database error SMA1000-8066 Appliance flooded with message "An attempt to match was made by a service that does not provide scheme information" SMA1000-8126 Apache request-splitting CVEs (CVE-2024-42516, CVE-2024-43204, CVE-2023-38709) SMA1000-8137 Intune Graph API query for Windows devices by defaults use "azureADDeviceId" attribute as a key. SMA1000-8172 Policyserver & unitd throw core dumps and dump 300 users SMA1000-8178 AD ADV non ssl configuration fail to authenticate against Microsoft Windows 2025. SMA1000-8206 Appliance drops users in node2 with unitd core found SMA1000-8225 Radius authentication not working when primary Radius server is down or unreachable. SMA1000-7189 Allow users to select platform while downloading CT clients in Workplace Lite mode SMA1000-7993 Accessing appliance-local service (like AMC) over the tunnel fails on AWS appliance (eth0 at 9001 MTU) SMA1000-8004 API to export backup fails to download aea file SMA1000-8005 Unable to track deleted address pool in AMC Management audit log SMA1000-8011 AMC UI and API help for split tunnel option is confusing and wrong SMA1000-8043 After upgrading to version 12.4.3, the warning message 'System DeferredSQL: SQL was queued for xxxx ms' started appearing regularly. SMA1000-8152 Update nodejs for CVE-2025-27209 (12.4.3) SMA1000-8169 Update OpenJDK for 12.4.3 Sept HF to clear some new vulnerabilities SMA1000-8177 AD ADV non ssl configuration "Test connection" failed against Microsoft Windows 2025. SMA1000-8209 Restrict Web Proxy base-uri's through Content Security Policy SMA1000-8260 TTL on Lets Encrypt domain challenge TXT record must be 0 SMA1000-7796 PKI Authentication with Attribute PrinciPal Name failing to match group membership SMA1000-7823 Update OpenJDK to most recent 11.0.X release SMA1000-7970 Apache Commons BeanUtils zero-click RCE vulnerability SMA1000-7784 Network capture from AMC when launched throw permission error SMA1000-7814 AD test connection validates domain controller certificate even when unselected SMA1000-7827 CMS UI has a few issues when conncurrent user count is 0 SMA1000-7841 Policy_audit log of CMS does not show the logout information correctly SMA1000-7870 ACL Advanced client network restriction option is unclear SMA1000-7936 CMS policy sync can result in more than one NAT pool on a managed appliance SMA1000-7859 Support route to internet for tunnel traffic on single-homed cloud appliances SMA1000-7897 Need Content-Security-Policy: frame-ancestors option SMA1000-7822 Multiple critical and high severity vulnerabilities in 3PL and OS packages SMA1000-7962 Multiple kernel CVEs -- need to update to 5.10.237 SMA1000-7963 POLICY_PUBLIC_ACCESS_URLS not working after Hotfix 12.4.3-02963 SMA1000-7818 getinfo have few entries which need to be reviewed. SMA1000-7819 Remove incorrect information from asm-cli tool (RAID array tool) SMA1000-7837 Unit service restart and segfault when device has multiple users logging in during morning hours SMA1000-7898 CVE-2025-43859: Need to update h11 package SMA1000-7965 Logserver Cores were generated and the appliance got auto restarted SMA6210 SMA1000-7831 [Vulnerability] SMA1000 12.4.3 Server-side request forgery (SSRF) Vulnerability SMA1000-7599 Apache Struts vulnerability (CVE-2024-53677) 9.8 Critical SMA1000-7403 SMA VA licenses are removed automatically when we sync from CMS to SMA, users are affected SMA1000-7519 Encoding error reported when accessing a resource over Web Proxy SMA1000-7584 All appliance certs are replaced during Let's Encrypt auto-renewal. SMA1000-7602 Radius Accounting data used for user data byte count does not match with extranet logs. This is used for bandwidth monitoring SMA1000-7605 China Managed appliance is unable to communicate with cms and other managed appliances. SMA1000-7616 RADIUS accounting inbound/outbound byte counts are doubled SMA1000-7683 Spike license days remaining displayed on Dashboard does not match with licensing for Spike under General settings SMA1000-7687 Unable to access RDweb published broker applications via Web/Client server or Custom FQDN method, ODT/CT works SMA1000-7691 AWS instance is with default MTU with 9001 SMA1000-7705 Citrix fails to launch in GTO based access. SMA1000-7489 Translation issue with customer portal - go-alias access method SMA1000-7578 HTTP sharepoint resource stops working as soon as we upgrade to 12.4.3 firmware and also on latest HF. SMA1000-7595 CMS and Managed Appliance license leasing is set for 7days or 168 hours need this to be longer SMA1000-7596 Unable to access WorkPlace with IPv6 using Chrome/Edge browser SMA1000-7603 Add AMC UI option to delete uploaded Citrix/VMware agents SMA1000-7607 Monitoring-Troubleshooting-Network Traffic does not work as expected its caching the previous values SMA1000-7693 AMC web proxy audit log does not display byte counts SMA1000-7706 VMCore dump post-install the JAN hotfix on FIPS Enabled device SMA1000-7721 Realms are not displayed when we try to manually add AD user using manual entry. SMA1000-7730 Only allow 2 hotfix rollbacks SMA1000-7743 Realm filtering based on host profile is broken when 'Host' header contains port number SMA1000-7778 SAML Authentication fails intermittently on some browsers SMA1000-7789 Option to set Web Proxy cookies with SameSite=Lax attribute SMA1000-7804 CVE-2025-29775 / CVE-2025-29774: Vulnerabilities in nodejs xml-crypto package SMA1000-7809 MobileConnect connection via au's cellular network sometimes disconnects immediately after authentication. SMA1000-7679 Unauthenticated requests containing struts actions in URL should always return the login page or 404 not found SMA1000-7567 Intense user authentication loads can affect new-user service levels SMA1000-7474 Too many open files causing hd full and failing new users to connect. SMA1000-7498 Consistant Memory growth post Sep 21st reboot and raising again. SMA1000-7501 default community members should always be read-only in AMC UI SMA1000-7510 ExtraWeb authentication UI allows manual selection of invalid realms for a host profile SMA1000-7549 Updating Resource Group on CMS and Synchronization disrupted user connections SMA1000-7418 Memory usage becomes high gradually and finally SSLVPN connection fails. SMA1000-7440 Memory usage gradually increasing though there were few/no users, and reduce the logging SMA1000-7451 Appliance reports restarting of services for any change made to the device. SMA1000-7409 Potential remove of 'savelog' program that has unfavorable licensing terms SMA1000-7442 File descriptor leak in policyserver, signs point to RADIUS code SMA1000-7432 Appliance drops users due to OOM reported VMCore SMA1000-7415 Adding or Removing appliance to existing CMS GTO setup disrupts existing connected users to the functional appliances. SMA1000-7400 DeviceVPN & UserVPN doesn't resume correctly when Local Network gets disrupted SMA1000-7391 Database password mismatch causes backpressure and user rejection SMA1000-7386 [Vulnerability] SMA1000 Unauthenticated SSRF vulnerability SMA1000-7376 CMS Upgrade failing with exit code 244 'timeoutMinutes' is not valid. SMA1000-7373 Let's Encrypt failing with missing TXT SMA1000-7369 Blast RADIUS vulnerability mitigation SMA1000-7350 Mismatch between scaling parameters of Apache (extraweb) and Unitd (authentication API) SMA1000-7347 OpenSSL CVEs SMA1000-7346 Multiple CVEs relating to Apache 2.4.59 SMA1000-7327 CSR limits Alternate names while generating through UI SMA1000-7323 New errors TOTP fails to display users when clicked on USERS WITH amc encountered an unrecoverable error SMA1000-7271 HTML5 RDP fails to launch when remote user uses port forwarding to reach Workplace SMA1000-7285 Common Criteria: Need year in timestamp of syslog and local files SMA1000-7263 Workplace shortcut for RDP fails to work post upgrade to 12.4.3 + hotfix SMA1000-7269 While creating workplace -> shortcuts, received System Error but this did not abort setting the shortcuts SMA1000-7274 user sessions are missing in AMC UI on appliance when DISABLE_CENTRAL_REPORTING=true SMA1000-7307 users unable to connect to appliance using CT with appliance 12.4.3 March hotfix post upgrade from 12.4.2 SMA1000-7308 Lets Encrypt update breaks our recognition of LE certs SMA1000-7317 [Vulnerability] Workplace reflected Cross-site Scripting vulnerability SMA1000-7319 TOTP fails to display users when clicked on USERS WITH amc encountered an unrecoverable error SMA1000-7140 Time Difference alert how is this calculated, the alert is seen on devices sitting on the same network with Common NTP SMA1000-7185 Post upgrade from 12.4.2 to 12.4.3 workplace shortcuts editing or creating are failing SMA1000-7213 Apache CVEs: CVE-2024-27316, CVE-2024-24795, CVE-2023-38709 SMA1000-7245 COMMON-CRITERIA: Security updates SMA1000-7267 After login to workplace (SMA) through the FW by opening TCP port, not able to logout from workplace SMA1000-7278 Disable browser caching of Web Proxy files SMA1000-7280 External users are receiving error messages when trying to access workplace randomly SMA1000-7293 Unable to add group user as admin in 12.4.3 firmware + Mar24 hotfix SMA1000-7314 High CPU utilization during scanning, found Web Proxy cores, users were dropped SMA1000-7176 Exclusions configured under redirect-all internal proxy (RIP) are not saved to config SMA1000-7175 Spike License Activation/deactivation restarts avfm and forces users session resumption SMA1000-7165 HTML5 SSH fails when expected pasword based authentication is of keyboard-interactive type. SMA1000-7164 SMTP Failing to validate Certificate which is part of SAN SMA1000-7157 Appliance drop users with policyserver crash SMA1000-7155 AMC should validate struts form inputs before calling ObjectInputStream.readObject() SMA1000-7147 policy audit log does not record spike license deactivation SMA1000-7142 CVE-2023-44487: HTTP/2 Rapid Reset Vulnerability SMA1000-7137 Mark Cluster Interface (used in HA pair) related SNMP MIBs as Obsolete SMA1000-7129 While Adding Exclusion from realm Tunnel Access tab is landing on Item not find page SMA1000-7128 Adding resource from Access control will redirecting to System Error Page SMA1000-7116 Error message should be updated for adding subnet resource SMA1000-7114 'Next' Button on realm selection page is not working when using browser cache SMA1000-7112 InterfaceThroughput SNMP MIBs do not show correct values SMA1000-7109 Multiple warnings are displayed instead of only one warning SMA1000-7084 Content-Security-Policy header is missing object-src SMA1000-7081 Unable to generate a new Let's Encrypt certificate with IPV6 enabled. SMA1000-7034 Only 9 GTO services are allowed to add in CMS UI SMA1000-7033 Mouse pointer is set to location even when Add GTO prompt is opened SMA1000-7027 Mismatch between AMC and Mgmt API for Max allowed characters in SMS config page SMA1000-7017 While Directory Browsing group details are loading very slowly SMA1000-7015 Management API allows System admins to delete their own API Keys whereas AMC UI doesn't. SMA1000-7010 CMS Management API shows empty response for spike license on spike license API SMA1000-7009 CMS Management API does not show proper spike license details on licensing API SMA1000-6984 Good to display a warning message if NTP is not enabled for DUO auth SMA1000-6983 Reserved IP are allowed on SMTP configuration using API on CMS SMA1000-6961 Misleading documentation when configuring SAML service providers SMA1000-6951 Cross-Site Request Forgery protection in Web Proxy SMA1000-6943 'Reset Defaults' under Managed Appliances logging page doesn't resets the logging level to defaults if log levels set from "All appliances" SMA1000-6901 The activation of the spike license never completes when pending configuration changes are scheduled Installation instructions: 1. Login to the AMC as Admin 2. Go to Maintenance -> Update 3. Upload 'pform-hotfix-12.4.3-03526.bin' file and click 'Install Update' The 'pform-hotfix-12.4.3-03526' script will perform the following actions: a. Backs up existing files. b. Replaces files with updated ones containing the fix. c. Adds new files if needed. d. Reboots the appliance. Restore instructions: If you wish to restore the appliance to the state it was in before applying the hotfix, run the following steps: 1. Login to the AMC as Admin 2. Go to Maintenance -> Rollback. 3. Under hotfixes select 'pform-hotfix-12.4.3-03526' and click 'Remove'