> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/5.0/traps-agent-release/known-issues-in-traps-agent-5.0.md).

# Known Issues in Traps Agent 5.0

The following table details known issues in Traps agent 5.0 releases.

| Issue ID                                                                                                                                                                                                                                 | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **CPATR-12877**                                                                                                                                                                                                                          | On Windows endpoints, unknown macros in Microsoft Office documents invoke notifications about these files when their verdict is received.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **CPATR-12865**                                                                                                                                                                                                                          | On Windows endpoints, post-detection alerts for Microsoft Office files that contain a macro are not retrievable from the management server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **CPATR-10614**                                                                                                                                                                                                                          | The Traps agent does not create a post-detection event when it receives from WildFire a malware verdict for a macro file that had a previous non-malware verdict.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **CPATR-9702**                                                                                                                                                                                                                           | <p>On endpoints running Windows Embedded POSReady 2009, the Traps agent 5.0.10 sometimes halts when:</p><ul><li>The Traps console is open on the endpoint before the agent applies the policy.</li><li>The Traps agent is running on the endpoint and attempting to update the Traps console (for example change the protection status or check-in info) while the console is closed, however it was previously open on the endpoint.</li></ul><p>The recommended workaround for this issue is:</p><p>1. Close the Traps console on the endpoint.</p><p>2. Delete the <code>TrapsAgent\_XXX.txt</code> file from <code>C:\Documents and Settings\All Users\Application Data\Cyvera\Everyone\Ipc</code>.</p><p>3. Restart <code>CyveraService.exe</code> using Cytool:</p><p>1. <code>Cytool runtime stop cyveraservice</code></p><p>2. <code>Cytool runtime start cyveraservice</code></p><p>4. <code>Cytool runtime stop cyveraservice</code></p><p>5. <code>Cytool runtime start cyveraservice</code></p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Before you install or upgrade the Traps 5.0.10 agent on an endpoint running Windows Embedded POSReady 2009, see <a href="/pages/owaXtKC21OGGuFBUK3rw#UUID-fb593bc8-4ba3-a763-4740-5726f1cef944_id8eb9d06f-af32-4609-8c5d-6535655a38bc">Changes to Default Behavior in Traps Agent 5.0.10</a></p></div> |
| <p><strong>CPA-3352</strong></p><p>This issue is now resolved. See <a href="/pages/ay4Rkt8cSSoHwI8b7arK#UUID-ebe87704-fbb5-d307-526e-a9cebcc02437_id71687a35-e152-4f19-98ea-7ad305efeb62">Addressed Issues in Traps Agent 5.0.6</a>.</p> | On endpoints running Windows 10 Insider Preview, the Windows Defender Security Center displays **Virus & threat protection** as `Unknown` and displays `Status unavailable` for Traps even though Traps successfully registers with the Security Center and is available.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CPA-2814</strong></p><p>This issue is now resolved. See <a href="/pages/ay4Rkt8cSSoHwI8b7arK#UUID-ebe87704-fbb5-d307-526e-a9cebcc02437_id6b92435b-babc-4a17-b077-ddd8060a2458">Addressed Issues in Traps Agent 5.0.3</a>.</p> | <p>When you install Traps on a Linux endpoint and multiple OpenSSL Red-hat Package Manager (RPM) packages are installed, installation fails.</p><p><strong>Workaround:</strong> Remove any extra OpenSSL packages from the Linux server.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CPA-2681</strong></p><p>This issue is now resolved. See <a href="/pages/ay4Rkt8cSSoHwI8b7arK#UUID-ebe87704-fbb5-d307-526e-a9cebcc02437_id185BF06506Y">Traps Agent 5.0.1 Addressed Issues</a>.</p>                             | Clicking **Check In Now** in the Traps agent console disconnects the agent from the Traps management service after you configure a malware profile with a **Parent Process Name** that exceeds 250 characters (Profiles → Windows → **`<malware_profile>`**).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>CPA-1942</strong></p><p>This issue is now resolved. See <a href="/pages/ay4Rkt8cSSoHwI8b7arK#UUID-ebe87704-fbb5-d307-526e-a9cebcc02437_id185BF06506Y">Traps Agent 5.0.1 Addressed Issues</a>.</p>                             | When you first install the Traps agent, the Traps management service can take up to one hour to display the associated content and agent version. As a result, the Dashboard can misreport the content version as outdated.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>CPA-1861</strong></p><p>This issue is now resolved. See <a href="/pages/ay4Rkt8cSSoHwI8b7arK#UUID-ebe87704-fbb5-d307-526e-a9cebcc02437_idda826acd-9859-490c-9fe0-6f219e202465">Addressed Issues in Traps Agent 5.0.4</a>.</p> | When device details such as username, user domain, and hostname change on an endpoint, the Traps management service can take up to five minutes to display the updated details after the endpoint restarts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>CPA-1768</strong></p><p>This issue is now resolved. See <a href="/pages/ay4Rkt8cSSoHwI8b7arK#UUID-ebe87704-fbb5-d307-526e-a9cebcc02437_idda826acd-9859-490c-9fe0-6f219e202465">Addressed Issues in Traps Agent 5.0.4</a>.</p> | When a remote user logs into a Remote Desktop Server, the Traps does not capture the name of the remote user. As a result, when a security event occurs, the user is identified in logs as undefined.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **CPA-1278**                                                                                                                                                                                                                             | When you configure a hash exception for a file that local analysis reported as malware, the Traps agent overrides the WildFire verdict of Unknown with Benign in the local cache instead of waiting for the official WildFire verdict.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/5.0/traps-agent-release/known-issues-in-traps-agent-5.0.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
