> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2025/november-2025.md).

# November 2025

This section describes the new features and updates introduced in the Cortex XSOAR SaaS 8.12 release.

## Release highlights

The Cortex XSOAR 8.12 release includes the following highlights:

| Feature                                  | Description                                                                                                                                                                                                                                                                                                                                                                      |
| ---------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Conflict-free playbook editing           | Prevent concurrent playbook editing with this enhancement, ensuring your team can build and modify automation workflows without conflicts.                                                                                                                                                                                                                                       |
| Unique task logos                        | Boost clarity, quickly distinguish between integration commands, custom scripts, and system actions with playbook tasks that display unique logos and content pack indicators.                                                                                                                                                                                                   |
| Unit 42 Threat Intelligence content pack | A new Unit 42 content pack provides high-value integrations that leverage Unit 42’s world-class threat intelligence, research, and analysis, replacing several deprecated packs (like AutoFocus and Unit 42 ATOMs Feed). To complete this migration, configure the new Unit 42 Feed and Enrichment integrations, update all related playbooks, and disable the old integrations. |

## Changed features

The Cortex XSOAR 8.12 release includes the following changed features:

| Feature      | Description                                                                                                                                                                                                                                                                                                                         |
| ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Threat Intel | <p>The following pages and tabs have been removed:</p><ul><li>The Sample Analysis tab on the Threat Intel page</li><li>The Sessions and Submissions tab on the Threat Intel tab</li><li>The Unit 42 Intel tab on the indicator details page</li></ul><p>The Indicator search in the legacy Unit 42 library has been deprecated.</p> |

## Marketplace content changes

This section describes the changes in content (integrations, playbooks, and indicators) from July to November.

| Content                                                                                                                               | Description                                                                                                                                                                                                                                                                                                           | Change Type |
| ------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------- |
| CVE-2025-49704 and CVE-2025-49706 and CVE-2025-53770 and CVE-2025-53771 - Microsoft SharePoint ToolShell vulnerability chain playbook | Automates the investigation and response to potential exploitation of four chained vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771) in Microsoft SharePoint. This chain can allow unauthenticated threat actors to run arbitrary commands and gain remote execution capabilities. | New         |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2025/november-2025.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
