Release notes for update package 2008-5242

This update package improves the detection capabilities of the Forcepoint NGFW system.

RELEASE DATE:    Monday April 13, 2026
MD5 CHECKSUM:    33c7b0ec07689a7d514337e359fb1bc7
SHA1 CHECKSUM:    0c2aa3bf0f0f6933e1f15dddd0570506fff89864
SHA256 CHECKSUM:    32d2a5661e58cd81004a887cf8c531ad912717bcbae5876c6937f96d728a20ac


UPDATE CRITICALITY:    HIGH

MINIMUM SOFTWARE VERSIONS
- Forcepoint NGFW Security Management Center:    6.10.1.11125
- Forcepoint NGFW:    6.10.1.26058

List of detected attacks in this update package:

Risk levelDescriptionReferenceVulnerability
High     An attempt to exploit a vulnerability in Open WebUI     CVE-2025-64496     Open-Webui-Code-Injection-CVE-2025-64496
High     An attempt to exploit a vulnerability in mcp-package-docs     CVE-2025-54073     MCP-Package-Docs-Command-Injection-CVE-2025-54073
High     An attempt to exploit a vulnerability in Sangoma FreePBX     CVE-2019-19006     Sangoma-FreePBX-Authentication-Bypass-CVE-2019-19006
High     Masjesu botnet exploiting traffic     No CVE/CAN Masjesu-Botnet-C2-Activity
High     Masjesu botnet command-and-control traffic     No CVE/CAN Masjesu-Botnet-C2-Activity

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

HTTP Request URI

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Sangoma-FreePBX-Authentication-Bypass-CVE-2019-19006 CVE-2019-19006 HTTP_CSU-Sangoma-FreePBX-Authentication-Bypass-CVE-2019-19006 Potential Compromise
High Masjesu-Botnet-C2-Activity No CVE/CAN HTTP_CSU-Masjesu-Botnet-C2-Activity Suspected Botnet

HTTP Request Header Line

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Masjesu-Botnet-C2-Activity No CVE/CAN HTTP_CSH-Masjesu-Botnet-Exploiting-Activity Suspected Botnet

Text File Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Open-Webui-Code-Injection-CVE-2025-64496 CVE-2025-64496 File-Text_Open-Webui-Code-Injection-CVE-2025-64496 Potential Compromise
High MCP-Package-Docs-Command-Injection-CVE-2025-54073 CVE-2025-54073 File-Text_MCP-Package-Docs-Command-Injection-CVE-2025-54073 Suspected Compromise

LIST OF OTHER CHANGES:

New objects:

TypeName
CategoryMasjesu
Categorymcp-package-docs

Updated objects:

TypeNameChanges
IPListTOR exit nodes IP Address List
IPListAmazon AMAZON
IPListAmazon S3
IPListAmazon EC2
IPListTOR relay nodes IP Address List
IPListAmazon AMAZON ap-northeast-1
IPListAmazon S3 ap-northeast-1
IPListAmazon EC2 ap-northeast-1
IPListAmazon AMAZON eu-south-2
IPListOkta IP Address List
IPListMalicious Site IP Address List
IPListNordVPN Servers IP Address List
IPListAmazon AMAZON eu-central-1
IPListAmazon EC2 eu-central-1
IPListAmazon AMAZON us-east-2
IPListAmazon EC2 us-east-2
IPListForcepoint Drop IP Address List
IPListAmazon IVS_REALTIME
IPListAmazon IVS_REALTIME us-east-2
SituationHTTP_CSU-Shared-Variables
ApplicationTOR
ApplicationNordVPN

HOW TO IMPORT AND ACTIVATE THE DYNAMIC UPDATE PACKAGE

  1. Download the dynamic update package, then make sure that the checksums for the original files and the files that you have downloaded match.
  2. In the Management Client, select Menu > File > Import > Import Update Packages.
  3. Browse to the file, select it, then click Import.
  4. Select  Configuration, then browse to Administration > Other Elements > Updates.
  5. Right-click the imported dynamic update package, then select Activate.
  6. When the activation is finished, refresh the policy on all NGFW Engines. If your policy uses a custom template, you might need to edit the policy.

DISCLAIMER AND COPYRIGHT

Copyright © 2026 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.