> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/7.x/cortex-xdr-agent-7.9-ce-release-information/addressed-issues-in-cortex-xdr-agent-7.9-ce.md).

# Addressed Issues in Cortex XDR Agent 7.9-CE

#### Addressed Issue in Cortex XDR agent 7.9.103-CE HF (7.9.103.53632)

The following issue has been resolved in Cortex XDR agent 7.9.103-CE HF (7.9.103.53632)

| Issue   | Description                               |
| ------- | ----------------------------------------- |
| Windows | Updated the Windows security certificate. |

#### Addressed Issues in Cortex XDR Agent 7.9.103-CE

The following issues have been resolved in this release.

| Issue                            | Description                                                                                                                                                                                                  |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| <p>CPATR-24407</p><p>(Linux)</p> | Fixed an issue where on rare occasions, the Cortex XDR agent may not load the Kernel module on SUSE Linux Enterprise Server 15.3.                                                                            |
| <p>CPATR-24120</p><p>(Linux)</p> | Increased the log level of a message that is issued when event collection fails to start.                                                                                                                    |
| <p>CPATR-23499</p><p>Windows</p> | Fixed an issue where a short time lapse may have been encountered, in certain VPN solutions, before endpoint management recognized the protection status of the Cortex XDR agent after the machine boots up. |

**Addressed Issues in Cortex XDR Agent 7.9.102-CE**

The following issues have been resolved in this release.

| Issue                              | Description                                                                                                                                                                                   |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>CPATR‑23360</p><p>(Linux)</p>   | Fixed an issue that may be encountered when running a clean installation with a package manager on a specific system configuration, where the clean installation may be deemed as an upgrade. |
| CPATR-23265                        | Fixed an issue so that files with special characters in the filename may be deleted with the destroy command.                                                                                 |
| <p>CPATR-22755</p><p>(Windows)</p> | Fixed an issue that may cause user applications to get sharing violation errors when opening Office documents that have macros or portable executable files.                                  |
| <p>CPATR-22636</p><p>(Windows)</p> | Fixed an issue where consuming clipboard events may cause agent stability issues.                                                                                                             |
| <p>CPATR-22565</p><p>(Windows)</p> | Improvement made to the Cortex XDR agent security and stability posture.                                                                                                                      |
| <p>CPATR-22407</p><p>(Linux)</p>   | Fixed an issue where the upgrade flag is provided for clean install.                                                                                                                          |
| CPATR-22247                        | Fixed an issue that may impact endpoints that do not support the BMI2 instruction set.                                                                                                        |
| CPATR-22202                        | Fixed an issue where for some alerts, the username field was not populated.                                                                                                                   |
| <p>CPATR-21933</p><p>(Linux)</p>   | Cortex XDR agents can be deployed in Linux environments where Pod Security Admission controller enforces Pod Security Standards.                                                              |
| <p>CPATR-21870</p><p>(Windows)</p> | Fixed an issue that may lead to agent upgrade failure on non-US locale OS editions.                                                                                                           |
| <p>CPATR-21825</p><p>(Windows)</p> | Fixed an issue where persistent hash caching may cause system deadlocks during volume dismounting.                                                                                            |
| <p>CPATR-21465</p><p>(Linux)</p>   | Fixed an issue on RHEL 8 and RHEL 9-based endpoints that may prevent the Cortex XDR agent from starting correctly.                                                                            |
| <p>CPATR-21445</p><p>(Linux)</p>   | Fixed an issue that may lead to agent processes timeout.                                                                                                                                      |
| <p>CPATR-21331</p><p>(Windows)</p> | Fixed an issue that may lead to high CPU resources on Windows Server endpoints.                                                                                                               |
| <p>CPATR-21125</p><p>(Linux)</p>   | Fixed a rare issue that may cause Cortex XDR agent installation to fail.                                                                                                                      |
| CPATR-20816                        | Fixed an agent stability issue that may occur after multiple cases of endpoint hardboot or by file system failures.                                                                           |
| CPATR-20233                        | Fixed an issue to ensure that an interrupted scheduled scan will resume scanning as close to the scheduled timeframe as possible.                                                             |

#### Addressed Issue In Cortex XDR Agent 7.9.101-CE-HF2

The following issue has been addressed in release 7.9.101-CE-HF2 (7.9.101.118742)

| Issue                            | Description                                                                                                                  |
| -------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| <p>CPATR‑22124</p><p>(Linux)</p> | Fixed an issue to prevent a potential vulnerability in the GNU C library's dynamic loader within the Cortex XDR agent image. |

#### Addressed Issue In Cortex XDR Agent 7.9.101-CE-HF1

The following issue has been addressed in release 7.9.101-CE-HF1.

| Issue                              | Description                                                                                                                                                             |
| ---------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>CPATR‑20983</p><p>(Windows)</p> | Fixed an issue related to a Microsoft Windows Server 2022 update, that may lead to an interoperability issue or browser instability when Exploit Prevention is enabled. |

**Addressed Issues In Cortex XDR Agent 7.9.101-CE**

The following issues have been addressed in release 7.9.101-CE.

| **Issue**                          | **Description**                                                                                                                                                                               |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>CPATR-20548</p><p>(Windows)</p> | Fixed an issue where local hash caching may impact application file access.                                                                                                                   |
| <p>CPATR‑20300</p><p>(Windows)</p> | Fixed an issue that may cause instability when enabling injections with Driver Verifier enabled.                                                                                              |
| <p>CPATR‑20269</p><p>(Windows)</p> | Fixed an issue that may cause the disk manager to handle detached virtual volumes incorrectly.                                                                                                |
| <p>CPATR‑20215</p><p>(MacOS)</p>   | Fixed an issue where the Cortex XDR agent console falsely reported a Cortex XDR endpoint as unprotected.                                                                                      |
| CPATR-20174                        | Added support for Amazon Linux 2023.                                                                                                                                                          |
| <p>CPATR-19959</p><p>(Windows)</p> | Fixed an issue in the Java anti-deserialization protection module that may cause reporting of false positive alerts.                                                                          |
| <p>CPATR-19823</p><p>(Windows)</p> | Fixed an issue that may impact boot time of Windows 11-based endpoints where virtualization-based security (VBS) was enabled.                                                                 |
| CPATR-19721                        | Fixed an issue where in some cases, file scans were incomplete and could lead to incorrect detection.                                                                                         |
| CPATR-19716                        | Fixed an issue that affected system extension memory in rare system cases.                                                                                                                    |
| CPATR-19535                        | Fixed an issue that falsely reported Cortex XDR agent operational status when some modules were disabled in the policy profile.                                                               |
| CPATR-19245                        | Fixed an issue where the Cortex XDR agent may face connection issues to the Cortex XDR server due to missing files.                                                                           |
| CPATR-18588                        | Fixed an issue where applications may fail due to virtual memory reservations.                                                                                                                |
| CPATR-18293                        | Fixed an issue where various file system volumes, such as CSV, VSS, and VHD, could not be excluded from monitoring.                                                                           |
| CPATR-17891                        | Fixed an issue with Java module protection module that could lead to Java virtual machine incompatibilities.                                                                                  |
| CPATR-15156                        | Fixed an issue where performing a File Search action without removing the file, results in a no file\_results report being sent to the server, leaving the action in the 'In Progress' state. |

#### Addressed Issue In Cortex XDR Agent 7.9.100-CE

The following issue has been addressed in release 7.9.100-CE.

| Issue       | Description                                                                                |
| ----------- | ------------------------------------------------------------------------------------------ |
| CPATR-19933 | Fixed an issue that caused upgrade failure on Windows 7 and Windows Server 2008 endpoints. |

#### Addressed issues in Cortex XDR agent 7.9-CE

| Issue                                  | Description                                                                                                                                                                                        |
| -------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CPATR-19305                            | Fixed an issue where corruption of internal files may lead to agent instability.                                                                                                                   |
| CPATR-19140                            | Fixed an issue where the causality termination did not detect the source process correctly.                                                                                                        |
| <p>CPATR-19009</p><p>(Windows)</p>     | Fixed an issue where a Windows function registry key was created falsely, which led to the creation of empty user profiles, resulting in a compatibility issue with SCCM deployment.               |
| <p>CPATR-18979</p><p>(Windows)</p>     | Fixed an issue with driver unload on Windows 11 22H2 where the endpoint may come to a halt.                                                                                                        |
| <p>CPATR-18967</p><p>(Mac)</p>         | Fixed an issue where running the uninstaller.sh may lead to slowness on external apps.                                                                                                             |
| CPATR-18856                            | In Citrix App Layering, Cortex XDR from version 7.9.1 supports content update regardless of the agent installation type.                                                                           |
| <p>CPATR-18853</p><p>(Windows)</p>     | Fixed an issue of incorrect domain name extraction in Windows endpoints.                                                                                                                           |
| <p>CPATR-18847</p><p>(Linux)</p>       | Fixed an issue that when running with aarch64 architecture, the agent shows as partially protected.                                                                                                |
| <p>CPATR-18797</p><p>(Mac)</p>         | Fixed an issue where the cytool startup command didn't work as expected and required the user to first stop the agent's services.                                                                  |
| <p>CPATR-18757</p><p>(iOS)</p>         | Fixed an issue where the Cortex XDR icon was cropped during registration.                                                                                                                          |
| <p>CPATR-18754</p><p>(Windows)</p>     | Fixed an issue where the agent console may have become unavailable due to a file load conflict.                                                                                                    |
| <p>CPATR-18628</p><p>(Linux)</p>       | Fixed an issue of a potential deadlock occurring during MMAP hook.                                                                                                                                 |
| <p>CPATR-18625</p><p>(VDI Windows)</p> | Fixed an issue where the Microsoft Signature check in VDIs may impact boot time.                                                                                                                   |
| <p>CPATR-18608</p><p>(Linux)</p>       | Fixed an issue where a scheduled scan runs incorrectly if a manual scan is triggered.                                                                                                              |
| <p>CPATR-18580</p><p>(Windows)</p>     | Fixed an issue that occurred when virtual USB Devices were removed.                                                                                                                                |
| <p>CPATR-18342</p><p>(Windows)</p>     | Fixed an issue on Windows-based Cortex XDR agents where the Java Deserialization Protection (JDP) module was activated on incompatible Java processes that were executed early during system boot. |

|                                    |                                                                                                                                                                  |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| CPATR‑18374                        | Fixed an issue where multiple agents begin uploading at once which may lead to overload and too many request errors.                                             |
| CPATR‑18332                        | Fixed an issue of redundant Check-In operation during VDI session registration.                                                                                  |
| CPATR‑18314                        | Fixed an issue where the virtual memory count is the same in every collection.                                                                                   |
| CPATR‑18185                        | Fixed an issue of data corruption caused by accumulation of large amounts of data.                                                                               |
| CPATR‑18172                        | Fixed an issue which caused the audit log of a successful upgrade to be reported twice.                                                                          |
| CPATR‑18144                        | Fixed an issue where XDR Agent makes continuous attempts to write to the EDR directory, even when failing to read the directory's size.                          |
| CPATR‑18115                        | Fixed an issue where periodic network scans did not obtain operating system details due to incorrect reporting of the XDR Agent's network interface subnet mask. |
| CPATR‑18108                        | Fixed an issue which caused some services to start automatically in safe mode.                                                                                   |
| CPATR‑18100                        | Fixed an issue with the 'cytool import content' command which caused the command to fail.                                                                        |
| CPATR‑17994                        | Fixed an issue where Cortex XDR agent mishandled preventions when the allowlist exceeded a certain size                                                          |
| CPATR‑17886                        | Fixed an issue where Cortex XDR agent sometimes caused a deadlock in the java application during native library load.                                            |
| CPATR‑17814                        | Fixed an issue which caused threat intel log errors when the IOC feature is disabled.                                                                            |
| <p>CPATR‑17807</p><p>(Windows)</p> | Fixed an issue where missing or invalid timezone keys strings prevents XDR Agent from running scripts.                                                           |
| CPATR-17458                        | Fixed an issue which prevented the resolution of DNS requests in queries.                                                                                        |
| CPATR‑16542                        | Fixed an issue where XDR Agent may not parse the proxies list successfully, and continues to use incorrect proxies.                                              |
| CPATR‑16452                        | Fixed an issue which caused the wrong location to be returned by DNS queries.                                                                                    |
| <p>CPATR‑15809</p><p>(Windows)</p> | Fixed an issue which made XDR Agent use the endpoint's DNS suffix instead of the actual domain name.                                                             |
| CPATR‑10830                        | Fixed an issue where the alert of a post detection termination event of multiple processes or applications does not list the process/application name.           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/7.x/cortex-xdr-agent-7.9-ce-release-information/addressed-issues-in-cortex-xdr-agent-7.9-ce.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
