Minor Releases
Cortex XSOAR 6.14 minor release, maintenance release.
December 7, 2025
April 6, 2024
For details on how to download and install the latest version, see Upgrade Your Installation.
Cortex XSOAR 6.14.0 (B6168561)
Cortex XSOAR 6.14.0 (B6168561) is a maintenance release that includes the following features and bug fixes:
Enhancements
Unit 42 Threat Intelligence content pack
A new Unit 42 content pack provides high-value integrations that leverage Unit 42’s world-class threat intelligence, research, and analysis, replacing several deprecated packs (such as AutoFocus and Unit 42 ATOMs Feed). To complete this migration, configure the new Unit 42 Feed and Enrichment integrations, update all related playbooks, and disable the old integrations.
Supported versions
Cortex XSOAR now supports RHEL 10 for engine and server installation.
Elasticsearch versions
Cortex XSOAR now supports Elasticsearch versions 8.18, 8.19, and 9.0.
Fixed issues
General
A Global Search would sometimes fail with a too many nested clauses error when there were many restricted investigations and Cortex XSOAR added them to every search query.
Mirroring
The
dbotDirtyFieldsincident field did not automatically reset after each bidirectional mirroring cycle.In some cases, mirroring outgoing changes would reset unchanged fields to their default values.
Incidents
When searching for incidents using the Relative time range option, if you chose 0 in the
tofield and clicked Apply, the value was reset to show incidents tonowinstead.The Splunk integration created multiple duplicate incidents in Cortex XSOAR.
In rare cases, searching for incidents resulted in a client rendering error.
Incidents (Multi-tenant)
Users from the main account could see and select columns in incident search tables (not data) from all tenants, even from tenants that were not shared or made available. Filtering by these columns would break their incident search display.
Widgets
In some cases, when using Elasticsearch, time values such as months, hours, and days were displayed as numbers instead of text in widgets.
Engines
When installing or upgrading multiple engines on the same host, the installation or upgrade failed in some cases.
SAML Authentication
Case-sensitive LDAP group name matching in SAML authentication caused access issues.
Permission issue with multiple roles
Users with multiple roles were not granted the highest level of permissions. The less privileged role restricted users' access.
Permissions
Users with read-only permission could see the Detach playbook link and and when clicking it, a permission error was issued. The link now requires Read/Write permission to be visible, ensuring consistency with the Detach automation link.
Playbooks
In rare cases, when a playbook task was manually completed, the playbook task would be executed multiple times, utilizing a high number of workers.
Cortex XSOAR login
Cortex XSOAR login failed in Firefox due to a Cross-Site Request Forgery (CSRF) error.
Dashboards/Reports
A filter was removed that generated an invalid search for a dashboard widget grouped by time.
In some cases, attempting to generate large-scale reports resulted in a report script execution timeout.
Changed features
Threat Intel
The following pages and tabs have been removed:
The Sample Analysis tab on the Threat Intel page
The Sessions and Submissions tab on the Threat Intel tab
The Unit 42 Intel tab on the indicator details page
The Indicator search in the legacy Unit 42 library has been deprecated.
Installation file hash: 592f6688ecde5d6ab2080d507e384d60d54fad6
Cortex XSOAR 6.14.0 (B3036535)
Cortex XSOAR 6.14.0 (B3036535) is a maintenance release that includes the following new features:
FIPS 140-3
Cortex XSOAR is now compliant with FIPS 140-3.
Installation file hash: 5496e6a7ff84f7cbd9e4c89b85ae61b8b66cfd8c
Last updated
Was this helpful?
