New features are available in Cortex XSOAR 8.12 On-prem, including release highlights and feature enhancements.
This section describes the new features and updates of the Cortex XSOAR 8.12 On-prem release.
Release build: master-8.12.0-8.12.0.3-52d2afe0
Release Highlights
The Cortex XSOAR 8.12 release includes the following highlights:
Feature | Description |
|---|---|
Conflict-free playbook editing | Prevent concurrent playbook editing with this enhancement, ensuring your team can build and modify automation workflows without conflicts. |
Unique task logos | Boost clarity, quickly distinguish between integration commands, custom scripts, and system actions with playbook tasks that display unique logos and content pack indicators. |
Forward logs to your syslog server | Enable centralized monitoring and satisfy log retention requirements by forwarding Management Audit, Integration, and Guard Rails logs to your preferred syslog server. |
Feature enhancements
The Cortex XSOAR 8.12 release includes the following enhancements:
Feature | Description |
|---|---|
Automated audit log cleanup | Ensure continuous system availability and prevent node shutdowns by automatically managing disk space for audit logs. This update introduces a background service that compresses rotated Debian audit logs and removes archived files older than six months. |
Changed features
The Cortex XSOAR 8.12 release includes the following changed features:
Feature | Description |
|---|---|
Threat Intel | The following pages and tabs have been removed:
The Indicator search in the legacy Unit 42 library has been deprecated. |
AWS Migration Hub deprecation | Improve the reliability of your AWS deployments by using the updated AMI conversion process. This update replaces the deprecated AWS Migration Hub Orchestrator method with a streamlined process for importing virtual machine images directly to AWS. For more information, see Install Cortex XSOAR on a VM deployed on AWS. |
System login and access | A security setting that could permanently lock out default Linux admin and viewer system users was fixed, ensuring these users can now change their passwords after expiration without being locked out. |
Marketplace Changes
This section describes the changes in content (integrations, playbooks, and indicators) from Cortex XSOAR 8.11 to 8.12.
Content | Description | Change type |
|---|---|---|
Rapid Response Playbook | Automate the detection and mitigation of CVE-2025-59287, a critical remote code execution vulnerability in Microsoft Windows Server Update Services (WSUS) caused by insecure deserialization. | New |