USG FLEX H Series - V1.38 Patch 0 Firmware Release

Options
Zyxel_Melen
Zyxel_Melen Posts: 4,705 image  Zyxel Employee
Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

Zywall USG FLEX H Series Release Note 

April 2026

Firmware Version on all models

  • Please use the cloud firmware upgrade function to upgrade USG FLEX H Series
USG FLEX H SeriesFirmware Version
FLEX50HV1.38(ACLO.0)C0
FLEX50HPV1.38(ACLP.0)C0
FLEX100HV1.38(ABXF.0)C0
FLEX100HPV1.38(ACII.0)C0
FLEX200HV1.38(ABWV.0)C0
FLEX200HPV1.38(ABXE.0)C0
FLEX500HV1.38(ABZH.0)C0
FLEX700HV1.38(ABZI.0)C0

New Feature and Enhancements

1. [Enhancement] Collaborative Detection & Response (CDR) integration is now supported- Nebula Configuration only.

2. [Enhancement] Multiple SSL VPN profiles are now supported. [eITS#250701199, 250801736]

3. [Enhancement] SSL VPN and IPsec VPN now generate log events for both successful and failed login attempts. [eITS#250501921, 260301137]

4. [Enhancement] Enhanced system logs to include detailed certificate information when SSL Inspection blocks traffic, improving visibility and troubleshooting. [eITS#251200360]

5. [Enhancement] Security Policy auditing now includes change logs to track and review configuration modifications. [eITS#251000667]

6. [Enhancement] Heartbot AnyInsight AI-powered Data Leak Prevention (DLP) is now supported for enhanced data protection.

7. [Enhancement] Content Filtering filter GenAI apps across 111+ URL categories effortlessly.

8. [Enhancement] Captive Portal enhancements: • Nebula Cloud Authentication support. [eITS#250900257] • Nebula walled garden list support • Customizable Captive Portal pages and template download. • Cloud-based updates for OIDC provider walled garden lists.

9. [Enhancement] Enhanced password complexity requirements: • Password history – Prevent users from reusing their current or recent passwords • Username restriction – Passwords cannot match the user account name

10. [Enhancement] External group users now support captive portal integration with the OIDC authentication server for enforcing user-aware policies.

11. [Enhancement] Static DHCP reservations now use IP address as the key, eliminating hostname conflicts. [eITS#251100742]

12. [Enhancement] The traffic statistics and daily email report now supports up to 8 interfaces and the device’s maximum supported port count, reflecting user selections from the monitoring pages (both previously limited to 4). [eITS# 251101344]

13. [Enhancement] H series diagnostic information download now available in Nebula OPtool. [eITS#250800257]

14. [Enhancement] Web GUI enhancements: a. Security Best Practice check b. Session monitor page now displays bandwidth management (BWM) matching information. c. Updated wording for Google Authentication revocation. [eITS#251101018] d. Updated wording for configuration validation. [eITS#251200030] e. Updated wording for Device HA failover. f. Enhanced dark mode UI for better readability and consistency. g. Security policy list position retained after editing. [eITS#240701655] h. GUI performance enhancement: The firewall (from web GUI) taking around 15 seconds to save a one secure policy while there are lots of address- objects since you click to "save". [eITS#251101738] i. Change the tag “Beta” to “Preview” j. IPv4 Interface table, the IP/Netmask field add assignment information. k. Correct the name of SecuManager to SecuManager v3 to distinguish with CloudCNM SeucManager (v1). l. Updated the DNS server layout on the Remote Access IPsec VPN and SSL VPN pages.

15. [Enhancement] Support clean arp command. [eITS#250701330]

16. [Enhancement] Added the ability to disable the default admin account in UAM.

17. [Feature Change] [SNMP] SNMP Configuration Validation Enhancement, • Remove SNMP v1 • When SNMP v2c is enabled, SNMP Community 1 are now mandatory fields. • Real-time validation has been added to ensure required SNMP Community fields are properly configured. • When SNMP v2c are disabled, SNMP Community and Trap settings are grayed out and cannot be edited.

18. [Feature Change] Captive Portal: Removed General interface from Incoming selection. [eITS#260200639]

19. [Feature Change] Changed the default DNS query type in NSlookup (Network Tool) to Type A for FQDN object resolution. [eITS#260100219] 

[AP Controller] *Local only

1. [Enhancement] Support WiFi Aid

2. [Enhancement] Support Rogue AP Detection

3. [Enhancement] Support Zero wait DFS

4. [Enhancement] The AP Controller (APC) now officially supports management of the WBE665S.

Bug Fix

1. [eITS#250901513, 251002228] Improved system stability to prevent temporary firewall interruptions and ensure continuous operation.

2. [eITS#251001053] Network connections not work properly at times.

3. [eITS#251200198] The sorting order by duration from large to small is not working.

4. [eITS#251200731] Security policy is not being applied correctly when using Tailscale settings.

5. [eITS#251201224] Policy route packet marking issues cause traffic to go to the wrong interface.

6. [eITS#251201436] Resolved an issue that could cause the device to reboot unexpectedly during certain events.

7. [eITS#260100498] Device may intermittently stop updating the IPv4 cache for certain FQDN objects. A reboot or toggling the object temporarily restores updates.

8. [eITS#260101036] Web GUI unavailable when configuring 8088 as HTTP or HTTPS port

9. [eITS#260101249] Resolved an issue that could cause the firewall to become unresponsive and inaccessible from both WAN and LAN interfaces.

10. [eITS#260101313] Resolved an issue where SNMP queries could lead to increased memory usage and cause unexpected system reboots.

11. [eITS#260101390] Resolved an issue where Interface Connectivity Check and Policy Route Connectivity Check did not function correctly together.

12. [eITS#260101826] Remote IPSec VPN script with Split Tunnel cannot be imported to Window native VPN client

13. [eITS#260200067] The device may occasionally become unresponsive and recover after a few minutes.

14. [eITS#260200480] Corrected a typo in the SecuExtender provisioning configuration file name.

15. [eITS#260200514] DDNS update failure.

16. [eITS#260200945] Resolved an issue where application statistics might be missing on the Nebula Dashboard.

17. [eITS#260201047] Resolved an issue where USG FLEX H could experience intermittent service interruptions.

18. [eITS#260201252] Tailscale VPN loses connectivity after reboot.

19. [eITS#260201457] Resolved an issue where Nebula VPN connectivity could be disrupted after a certificate update.

20. [eITS#260201458, 260301049] Resolved an issue where Android devices could lose Internet connectivity when DNS SafeSearch was enabled in Content Filtering.

21. [eITS#260201468, 260300475, 260300880] If "any" is selected on SSL VPN > Authentication > User, ad-user belonging to ext-group-user cannot establish SSL VPN. Besides, if an AD user belongs to many groups, the firewall cannot recognize the user.

22. [eITS#260201558] Resolved an issue that could cause intermittent connectivity problems and temporary device unresponsiveness.

23. [eITS#260300082] Resolved an issue that could cause intermittent connectivity problems and temporary device unresponsiveness.

24. [eITS#260300819] Fixed an issue where admin 2FA backup codes could disappear after canceling changes and could not be regenerated.

25. [eITS#260300822] The Internet connection could disconnect unexpectedly.

26. [eITS#260300871] AD groups were not correctly recognized during VPN authentication

27. [eITS#260301047] The system logs saved to USB storage could not be downloaded. 

[AP Controller]

1. [eITS#260200398] AP does not broadcast configured SSID.

Please refer to the Download Link for more details.

Zyxel Melen