Manage software upgrades

Use the Software Upgrade Planner to review suggested software versions for your Firewall Threat Defense devices and evaluate the security and operational benefits of upgrading. In addition to suggested upgrade versions, the planner provides insights into active threat campaigns and guided remediation for vulnerabilities and bugs affecting your devices.

Before you begin

Ensure that the Software Upgrade Planner toggle is enabled under Insights & Reports > Settings > Operations.

Procedure


Step 1

In the left pane, click Insights & Reports > Software Upgrade Planner.

The Software Upgrade Planner page displays a summary of upgrade opportunities across your deployment. The Summary section provides an overview of:

  • Devices with upgrades available

  • Total available fixes

  • Details on threat campaigns

  • Security vulnerability fixes

  • Bug fixes

You can click View all in the CVE Fixes or Bug Fixes tiles to review the corresponding issues across your deployment.

Step 2

Review the suggested upgrade versions for your devices.

  • Multiple upgrade options are available based on vulnerabilities, bugs, and new features. The Cisco-suggested version is indicated by a gold star. Choose the version that suits your requirements.

  • For each device, the planner displays the current software version and suggested upgrade versions. If a device is affected by one or more active threat campaigns, the current software version displays the number of threat campaigns affecting the device.

  • Hover over the Current version to view additional details, including the current software version, vulnerabilities found, bugs found, and the active threat campaigns affecting the device.

  • Select a threat campaign to open the corresponding Cisco Talos Intelligence blog and learn more about the campaign.

Step 3

To perform an upgrade, click More actions (⋮) for the device, and click Go to product upgrade

The Product Upgrades page opens in Cloud-Delivered Firewall Management Center, where you can perform the upgrade.

Step 4

In the Software Upgrade Planner page, select a device to view more details.

The device details page displays Suggested and Golden versions. For each suggested version, you can review:

  • Active threat campaigns resolved

  • Security vulnerability fixes and bug fixes

  • Estimated downtime

  • New features included in the release

  • Link to detailed release notes

Use this information to compare the available upgrade versions and determine the most appropriate upgrade version for your deployment.

Step 5

Review the Security vulnerability fixes or Bug fixes tabs.

  • These tabs list the vulnerabilities and bugs affecting the selected device. You can search and filter the results or export the list as a CSV file.

  • Select a CVE ID or bug ID to open the details pane. The details pane provides AI-generated insights to help you understand the issue, including:

    • Root cause analysis that summarizes the issue and its potential impact.

    • Workaround information, when available, to help mitigate the issue before upgrading.

    • Remediation guidance that identifies how many devices in your deployment are affected and explains whether upgrading resolves the issue.

You can use the Software Upgrade Planner to evaluate suggested software versions, review threat campaign exposure, analyze security vulnerabilities and bug fixes, and use AI-generated remediation insights to make informed upgrade decisions.