> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.14/minor-releases.md).

# Minor Releases

| Cortex XSOAR Minor Release                                                                              | Release Date     |
| ------------------------------------------------------------------------------------------------------- | ---------------- |
| [Cortex XSOAR 6.14.0 (B6168561)](#UUID-ca677849-79e2-6520-1eaf-544a8313bb49_section-idm235075482954819) | December 7, 2025 |
| [Cortex XSOAR 6.14.0 (B3036535)](#UUID-ca677849-79e2-6520-1eaf-544a8313bb49_section-idm234455069170317) | April 6, 2024    |

For details on how to download and install the latest version, see [Upgrade Your Installation](/cortex-xsoar-6-installation-guides/6.14/cortex-xsoar-installation-guide/upgrade-your-installation/upgrade-the-cortex-xsoar-server.md).

#### Cortex XSOAR 6.14.0 (B6168561)

Cortex XSOAR 6.14.0 (B6168561) is a maintenance release that includes the following features and bug fixes:

**Enhancements**

| Enhancements                             | Description                                                                                                                                                                                                                                                                                                                                                                         |
| ---------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Unit 42 Threat Intelligence content pack | A new Unit 42 content pack provides high-value integrations that leverage Unit 42’s world-class threat intelligence, research, and analysis, replacing several deprecated packs (such as AutoFocus and Unit 42 ATOMs Feed). To complete this migration, configure the new Unit 42 Feed and Enrichment integrations, update all related playbooks, and disable the old integrations. |
| Supported versions                       | Cortex XSOAR now supports RHEL 10 for engine and server installation.                                                                                                                                                                                                                                                                                                               |
| Elasticsearch versions                   | Cortex XSOAR now supports Elasticsearch versions 8.18, 8.19, and 9.0.                                                                                                                                                                                                                                                                                                               |

**Fixed issues**

| Subject                              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| General                              | A Global Search would sometimes fail with a `too many nested clauses` error when there were many restricted investigations and Cortex XSOAR added them to every search query.                                                                                                                                                                                                                                                                                                                                                             |
| Mirroring                            | <ul><li>The <code>dbotDirtyFields</code> incident field did not automatically reset after each bidirectional mirroring cycle.</li><li>In some cases, mirroring outgoing changes would reset unchanged fields to their default values.</li></ul>                                                                                                                                                                                                                                                                                           |
| Incidents                            | <ul><li>When searching for incidents using the <strong>Relative time range</strong> option, if you chose 0 in the <code>to</code> field and clicked <strong>Apply</strong>, the value was reset to show incidents to <code>now</code> instead.</li><li>The Splunk integration created multiple duplicate incidents in Cortex XSOAR.</li><li>In rare cases, searching for incidents resulted in a client rendering error.</li></ul>                                                                                                        |
| Incidents (Multi-tenant)             | Users from the main account could see and select columns in incident search tables (not data) from all tenants, even from tenants that were not shared or made available. Filtering by these columns would break their incident search display.                                                                                                                                                                                                                                                                                           |
| Widgets                              | In some cases, when using Elasticsearch, time values such as months, hours, and days were displayed as numbers instead of text in widgets.                                                                                                                                                                                                                                                                                                                                                                                                |
| Engines                              | When installing or upgrading multiple engines on the same host, the installation or upgrade failed in some cases.                                                                                                                                                                                                                                                                                                                                                                                                                         |
| SAML Authentication                  | Case-sensitive LDAP group name matching in SAML authentication caused access issues.                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Permission issue with multiple roles | Users with multiple roles were not granted the highest level of permissions. The less privileged role restricted users' access.                                                                                                                                                                                                                                                                                                                                                                                                           |
| Permissions                          | Users with read-only permission could see the **Detach playbook** link and and when clicking it, a permission error was issued. The link now requires Read/Write permission to be visible, ensuring consistency with the **Detach automation** link.                                                                                                                                                                                                                                                                                      |
| Playbooks                            | In rare cases, when a playbook task was manually completed, the playbook task would be executed multiple times, utilizing a high number of workers.                                                                                                                                                                                                                                                                                                                                                                                       |
| Cortex XSOAR login                   | Cortex XSOAR login failed in Firefox due to a Cross-Site Request Forgery (CSRF) error.                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Dashboards/Reports                   | <ul><li>A filter was removed that generated an invalid search for a dashboard widget grouped by time.</li><li><p>In some cases, attempting to generate large-scale reports resulted in a report script execution timeout.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If this occurs, use the <code>reports.script.execution.timeout.seconds</code> server configuration to change the report execution timeout. The default is 300 seconds.</p></div></li></ul> |

**Changed features**

| Feature      | Description                                                                                                                                                                                                                                                                                                                         |
| ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Threat Intel | <p>The following pages and tabs have been removed:</p><ul><li>The Sample Analysis tab on the Threat Intel page</li><li>The Sessions and Submissions tab on the Threat Intel tab</li><li>The Unit 42 Intel tab on the indicator details page</li></ul><p>The Indicator search in the legacy Unit 42 library has been deprecated.</p> |

Installation file hash: `592f6688ecde5d6ab2080d507e384d60d54fad6`

#### Cortex XSOAR 6.14.0 (B3036535)

Cortex XSOAR 6.14.0 (B3036535) is a maintenance release that includes the following new features:

| Feature    | Description                                    |
| ---------- | ---------------------------------------------- |
| FIPS 140-3 | Cortex XSOAR is now compliant with FIPS 140-3. |

Installation file hash: `5496e6a7ff84f7cbd9e4c89b85ae61b8b66cfd8c`


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-release-notes/6.14/minor-releases.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
