Release notes for update package 1947-5242

This update package improves the detection capabilities of the Forcepoint NGFW system.

RELEASE DATE:    Wednesday October 29, 2025
MD5 CHECKSUM:    0aaf577bde5538c46c3c1b3c83687bd3
SHA1 CHECKSUM:    49c76f47fdf8f5bac6bf6a5ca3d32c2b76058a72
SHA256 CHECKSUM:    1946302588db415c54bcb18629cdc216e0338f9c8d859584aa99316096df06e0


UPDATE CRITICALITY:    HIGH

MINIMUM SOFTWARE VERSIONS
- Forcepoint NGFW Security Management Center:    6.10.1.11125
- Forcepoint NGFW:    6.8.1.24103

List of detected attacks in this update package:

Risk levelDescriptionReferenceVulnerability
High     A possible attempt to exploit a vulnerability in Windows Server Update Service     CVE-2025-59287     Windows-Server-Update-Service-Remote-Code-Execution-CVE-2025-59287
High     An attempt to exploit a vulnerability in Zabbix     CVE-2025-27240     Zabbix-Visible-Name-SQL-Injection-CVE-2025-27240

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

HTTP Client Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Zabbix-Visible-Name-SQL-Injection-CVE-2025-27240 CVE-2025-27240 HTTP_CS-Zabbix-Visible-Name-SQL-Injection-CVE-2025-27240 Suspected Compromise

Identified Text File Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Windows-Server-Update-Service-Remote-Code-Execution-CVE-2025-59287 CVE-2025-59287 File-TextId_WSUS-Remote-Code-Execution-CVE-2025-59287-Vulnerable-Component-Access Suspected Compromise

Updated detected attacks:

Identified Text File Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High Windows-Server-Update-Service-Remote-Code-Execution-CVE-2025-59287 CVE-2025-59287 File-TextId_Windows-Server-Update-Service-Remote-Code-Execution-CVE-2025-59287 Suspected Compromise
Detection mechanism updated

LIST OF OTHER CHANGES:

New objects:

TypeName
CategoryJuniper

Updated objects:

TypeNameChanges
SituationGenerative AI - Text and Code
Name: Generative AI - Text & Code->Generative AI - Text and Code
SituationHTTP_CSH-Shared-Variables
SituationHTTP_PSU-Shared-Variables
Fingerprint regexp changed
ApplicationFacebook
ApplicationTOR
ApplicationAmazon-WorkSpaces
Application detection context content changed
Application Port "tcp/443 tls: mandatory" -> "tcp/443 tls: free"
Application Port "tcp/4172 tls: no" -> "tcp/4172 tls: free"
Application Port "tcp/4195 tls: no" -> "tcp/4195 tls: free"
Application Port "udp/4172 tls: no" -> "udp/4172 tls: free"
Application Port "udp/4195 tls: no" -> "udp/4195 tls: free"
TLS Match identification changed from true to false
ApplicationDNS-Over-HTTPS
ApplicationNordVPN
CategoryJunos OS
CategoryJuniper ScreenOS
SituationURL_List-DNS-Over-HTTPS
Detection mechanism updated
IPListRwanda
IPListSomalia
IPListYemen
IPListIraq
IPListSaudi Arabia
IPListIran
IPListCyprus
IPListTanzania
IPListSyria
IPListArmenia
IPListKenya
IPListDR Congo
IPListDjibouti
IPListUganda
IPListCentral African Republic
IPListSeychelles
IPListJordan
IPListLebanon
IPListKuwait
IPListOman
IPListQatar
IPListBahrain
IPListUnited Arab Emirates
IPListIsrael
IPListTürkiye
IPListEthiopia
IPListEritrea
IPListEgypt
IPListSudan
IPListGreece
IPListBurundi
IPListEstonia
IPListLatvia
IPListAzerbaijan
IPListLithuania
IPListSvalbard and Jan Mayen
IPListGeorgia
IPListMoldova
IPListBelarus
IPListFinland
IPListÅland Islands
IPListUkraine
IPListNorth Macedonia
IPListHungary
IPListBulgaria
IPListAlbania
IPListPoland
IPListRomania
IPListZimbabwe
IPListZambia
IPListComoros
IPListMalawi
IPListLesotho
IPListBotswana
IPListMauritius
IPListEswatini
IPListRéunion
IPListSouth Africa
IPListMayotte
IPListMozambique
IPListMadagascar
IPListAfghanistan
IPListPakistan
IPListBangladesh
IPListTurkmenistan
IPListTajikistan
IPListSri Lanka
IPListBhutan
IPListIndia
IPListMaldives
IPListBritish Indian Ocean Territory
IPListNepal
IPListMyanmar
IPListUzbekistan
IPListKazakhstan
IPListKyrgyzstan
IPListFrench Southern Territories
IPListHeard and McDonald Islands
IPListCocos (Keeling) Islands
IPListPalau
IPListVietnam
IPListThailand
IPListIndonesia
IPListLaos
IPListTaiwan
IPListPhilippines
IPListMalaysia
IPListChina
IPListHong Kong
IPListBrunei
IPListMacao
IPListCambodia
IPListSouth Korea
IPListJapan
IPListNorth Korea
IPListSingapore
IPListCook Islands
IPListTimor-Leste
IPListRussia
IPListMongolia
IPListAustralia
IPListChristmas Island
IPListMarshall Islands
IPListFederated States of Micronesia
IPListPapua New Guinea
IPListSolomon Islands
IPListTuvalu
IPListNauru
IPListVanuatu
IPListNew Caledonia
IPListNorfolk Island
IPListNew Zealand
IPListFiji
IPListLibya
IPListCameroon
IPListSenegal
IPListCongo Republic
IPListPortugal
IPListLiberia
IPListIvory Coast
IPListGhana
IPListEquatorial Guinea
IPListNigeria
IPListBurkina Faso
IPListTogo
IPListGuinea-Bissau
IPListMauritania
IPListBenin
IPListGabon
IPListSierra Leone
IPListSão Tomé and Príncipe
IPListGibraltar
IPListGambia
IPListGuinea
IPListChad
IPListNiger
IPListMali
IPListWestern Sahara
IPListTunisia
IPListSpain
IPListMorocco
IPListMalta
IPListAlgeria
IPListFaroe Islands
IPListDenmark
IPListIceland
IPListUnited Kingdom
IPListSwitzerland
IPListSweden
IPListThe Netherlands
IPListAustria
IPListBelgium
IPListGermany
IPListLuxembourg
IPListIreland
IPListMonaco
IPListFrance
IPListAndorra
IPListLiechtenstein
IPListJersey
IPListIsle of Man
IPListGuernsey
IPListSlovakia
IPListCzechia
IPListNorway
IPListVatican City
IPListSan Marino
IPListItaly
IPListSlovenia
IPListMontenegro
IPListCroatia
IPListBosnia and Herzegovina
IPListAngola
IPListNamibia
IPListSaint Helena
IPListBouvet Island
IPListBarbados
IPListCabo Verde
IPListGuyana
IPListFrench Guiana
IPListSuriname
IPListSaint Pierre and Miquelon
IPListGreenland
IPListParaguay
IPListUruguay
IPListBrazil
IPListFalkland Islands
IPListSouth Georgia and the South Sandwich Islands
IPListJamaica
IPListDominican Republic
IPListCuba
IPListMartinique
IPListBahamas
IPListBermuda
IPListAnguilla
IPListTrinidad and Tobago
IPListSt Kitts and Nevis
IPListDominica
IPListAntigua and Barbuda
IPListSaint Lucia
IPListTurks and Caicos Islands
IPListAruba
IPListBritish Virgin Islands
IPListSt Vincent and Grenadines
IPListMontserrat
IPListSaint Martin
IPListSaint Barthélemy
IPListGuadeloupe
IPListGrenada
IPListCayman Islands
IPListBelize
IPListEl Salvador
IPListGuatemala
IPListHonduras
IPListNicaragua
IPListCosta Rica
IPListVenezuela
IPListEcuador
IPListColombia
IPListPanama
IPListHaiti
IPListArgentina
IPListChile
IPListBolivia
IPListPeru
IPListMexico
IPListFrench Polynesia
IPListPitcairn Islands
IPListKiribati
IPListTokelau
IPListTonga
IPListWallis and Futuna
IPListSamoa
IPListNiue
IPListNorthern Mariana Islands
IPListGuam
IPListPuerto Rico
IPListU.S. Virgin Islands
IPListU.S. Outlying Islands
IPListAmerican Samoa
IPListCanada
IPListUnited States
IPListPalestine
IPListSerbia
IPListAntarctica
IPListSint Maarten
IPListCuraçao
IPListBonaire, Sint Eustatius, and Saba
IPListSouth Sudan
IPListTOR exit nodes IP Address List
IPListAmazon AMAZON
IPListAmazon S3
IPListAmazon EC2
IPListFacebook Servers
IPListGoogle Servers
IPListMicrosoft Azure datacenter for brazilsouth
IPListTOR relay nodes IP Address List
IPListMicrosoft Azure datacenter for centralindia
IPListMicrosoft Azure datacenter for centralus
IPListMicrosoft Azure datacenter for eastus2
IPListMicrosoft Azure datacenter for eastus
IPListMicrosoft Azure datacenter for centralfrance
IPListMicrosoft Azure datacenter for northcentralus
IPListMicrosoft Azure datacenter for northeurope
IPListMicrosoft Azure datacenter for southcentralus
IPListMicrosoft Azure datacenter for westeurope
IPListMicrosoft Azure datacenter for westus2
IPListMicrosoft Azure datacenter for westus
IPListMicrosoft Azure datacenter
IPListAmazon AMAZON af-south-1
IPListAmazon EC2 af-south-1
IPListAmazon AMAZON ap-east-1
IPListAmazon EC2 ap-east-1
IPListAmazon AMAZON ap-south-2
IPListAmazon EC2 ap-south-2
IPListAmazon AMAZON ap-northeast-1
IPListAmazon EC2 me-central-1
IPListAmazon AMAZON me-central-1
IPListAmazon EC2 ap-northeast-1
IPListAmazon AMAZON eu-south-2
IPListAmazon EC2 eu-south-2
IPListAmazon AMAZON eu-central-2
IPListAmazon EC2 eu-central-2
IPListAmazon AMAZON il-central-1
IPListAmazon AMAZON ap-northeast-2
IPListAmazon S3 ap-northeast-2
IPListAmazon EC2 ap-northeast-2
IPListAmazon EC2 il-central-1
IPListOkta IP Address List
IPListAmazon AMAZON ap-northeast-3
IPListAmazon EC2 ap-northeast-3
IPListBotnet IP Address List
IPListMalicious Site IP Address List
IPListAmazon AMAZON ap-southeast-6
IPListAmazon EC2 ap-southeast-6
IPListAmazon AMAZON ap-south-1
IPListAmazon EC2 ap-south-1
IPListMicrosoft Azure datacenter for indonesiacentral
IPListAmazon AMAZON ap-southeast-1
IPListAmazon EC2 ap-southeast-1
IPListNordVPN Servers IP Address List
IPListAmazon AMAZON ap-southeast-2
IPListAmazon EC2 ap-southeast-2
IPListAmazon AMAZON ca-central-1
IPListAmazon S3 ca-central-1
IPListAmazon EC2 ca-central-1
IPListAmazon AMAZON cn-north-1
IPListAmazon EC2 cn-north-1
IPListAmazon EC2 sa-west-1
IPListAmazon AMAZON sa-west-1
IPListAmazon AMAZON cn-northwest-1
IPListAmazon EC2 cn-northwest-1
IPListAmazon AMAZON eu-central-1
IPListAmazon S3 eu-central-1
IPListAmazon EC2 eu-central-1
IPListAmazon AMAZON eu-north-1
IPListAmazon EC2 eu-north-1
IPListAmazon AMAZON ap-southeast-5
IPListAmazon AMAZON eu-west-1
IPListAmazon EC2 ap-southeast-5
IPListAmazon EC2 eu-west-1
IPListAmazon AMAZON eu-west-2
IPListAmazon EC2 eu-west-2
IPListAmazon AMAZON eu-west-3
IPListAmazon EC2 eu-west-3
IPListAmazon AMAZON me-south-1
IPListAmazon EC2 me-south-1
IPListAmazon AMAZON sa-east-1
IPListAmazon EC2 sa-east-1
IPListAmazon AMAZON us-east-1
IPListAmazon EC2 us-east-1
IPListAmazon AMAZON us-east-2
IPListAmazon EC2 us-east-2
IPListForcepoint Drop IP Address List
IPListMicrosoft Azure service for Scuba
IPListAmazon AMAZON us-gov-east-1
IPListAmazon EC2 us-gov-east-1
IPListAmazon AMAZON us-gov-west-1
IPListAmazon EC2 us-gov-west-1
IPListAmazon AMAZON us-west-1
IPListAmazon EC2 us-west-1
IPListAmazon AMAZON us-west-2
IPListAmazon EC2 us-west-2
IPListAmazon AMAZON eu-south-1
IPListAmazon EC2 eu-south-1
IPListAmazon AMAZON ap-southeast-3
IPListAmazon EC2 ap-southeast-3
IPListMicrosoft Azure datacenter for germanyn
IPListGitHub Actions IP Address List
IPListMicrosoft Azure service for AzureCloud
IPListAmazon AMAZON ap-east-2
IPListAmazon AMAZON mx-central-1
IPListMicrosoft Azure service for AzureMonitor
IPListAmazon AMAZON ap-southeast-7
IPListAmazon EC2 ap-southeast-7
IPListAmazon EC2 mx-central-1
IPListAmazon EC2 ap-east-2
IPListMicrosoft Azure datacenter for westus3
IPListAmazon EC2 ap-southeast-4
IPListAmazon AMAZON ap-southeast-4
IPListMicrosoft Azure datacenter for austriaeast
IPListMicrosoft Azure datacenter for israelcentral
IPListMicrosoft Azure datacenter for italynorth
IPListMicrosoft Azure datacenter for spaincentral
IPListAmazon CLOUDFRONT_ORIGIN_FACING
IPListAmazon AMAZON ca-west-1
IPListAmazon EC2 ca-west-1
IPListOracle Services Network us-ashburn-1
IPListGoogle Cloud IP Address List for europe-central2
IPListGoogle Cloud IP Address List for europe-west6
IPListGoogle Cloud IP Address List for us-central1
IPListAmazon EC2 me-west-1
IPListMicrosoft Azure datacenter for southcentralus2
IPListAmazon AMAZON me-west-1
IPListWeChat IP Address List
IPListOpenAI ChatGPT User Servers
IPListGoogle User Triggered Fetcher Servers
IPListMicrosoft Azure datacenter for southeastus3

HOW TO IMPORT AND ACTIVATE THE DYNAMIC UPDATE PACKAGE

  1. Download the dynamic update package, then make sure that the checksums for the original files and the files that you have downloaded match.
  2. In the Management Client, select Menu > File > Import > Import Update Packages.
  3. Browse to the file, select it, then click Import.
  4. Select  Configuration, then browse to Administration > Other Elements > Updates.
  5. Right-click the imported dynamic update package, then select Activate.
  6. When the activation is finished, refresh the policy on all NGFW Engines. If your policy uses a custom template, you might need to edit the policy.

DISCLAIMER AND COPYRIGHT

Copyright © 2025 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.