Security update for netcdf
Official SUSE security update.
Release notes and known issues →VERIFIED PUBLISHER INTELLIGENCE
Source-attributed product updates, affected versions, fixes and operational context. Update publication dates are kept separate from lifecycle boundaries.
Official SUSE security update.
Release notes and known issues →Official SUSE security update.
Release notes and known issues →Official SUSE security update.
Release notes and known issues →Official SUSE security update.
Release notes and known issues →Official SUSE security update.
Release notes and known issues →Official SUSE security update.
Release notes and known issues →Official SUSE security update.
Release notes and known issues →Official SUSE security update.
Release notes and known issues →Official SUSE security update.
Release notes and known issues →Official SUSE security update.
Release notes and known issues →2.1.1 September 16, 2026 SECURITY: core: Update github.com/apache/thrift to v0.24.0 to fix security vulnerability GHSA-8wv5-x4w7-5gww . core: Update golang.org/x/crypto to v0.56.0 to fix security vulnerabilities GO-2026-6354 and GO-2026-6355. core: Update google.golang.org/grpc to v1.83.2 to fix security vulnerability GHSA-2v4p-qf9q-27wj . CHANGES: auth/jwt: Added Okta provider with group fetching from Admin API when fetch_groups=true and truncation is detected. auth/jwt: Update plugin to v0.26.4 core/raft: Limited concurrent retry-join workers to 20. Any further retry-join attempts while 20 are in progress will result in an error ( too many concurrent raft retry joins in progress ). core: Bump Go version to 1.26.8 IMPROVEMENTS: secrets import: Add allowed_ipv4_cidrs to source_aws and source_azure Secrets Import blocks to allow private CIDR exemptions for SSRF-safe connectivity. secrets/pki: add an additional field to include an RFC 5280 revocation reason for (/pki/revoke) and (/pki/revoke-with-key). ui: Bump dompurify to 3.4.15 to address SECVULN advisories BUG FIXES: Secrets Recovery (enterprise): Fixing Vault panic in cli when running vault recover without a path. auth/jwt: Fixed incorrect HTTP status codes returned during agent ceiling policy evaluation. auth/token: Fixed a bug where auth/token/lookup and auth/token/lookup-self returned 403 for JWT tokens in a non-root namespace. consumption-billing: Fix OIDC identity token billing units being computed incorrectly across periodic flush cycles. The billing scalar now applies per-token duration adjustment, so the reported scalar and the per-mount attribution breakdown are always consistent. core/activitylog (enterprise): Fix a panic in CensusReport ACL policy metrics collection by safely handling transient missing policies and nil policy path/permission data while policies are changing. core/mounts: Fixed vault secrets move (and vault auth move ) incorrectly placing a mount in the root namespace when the destination path has a leading slash. oauth-resource-server (enterprise): Fix issue where RAR enforcement was skipped when the token's iss claim had cosmetic differences (e.g. different casing or trailing slash) compared to the issuer stored in the resource server profile. plugins: Fix issue with vault plugin reload -mounts command when run in the root namespace secrets-sync (enterprise): Fix LIST /v1/sys/sync/associations intermittently returning zero associations/secrets by forwarding the request to the active node instead of allowing it to be served locally by a performance standby or performance secondary. secrets/pki (enterprise): Fix panic in CMPv2 sentinel field parsing when cert request messages are empty. secrets/pki (enterprise): Fix unified CRL not being rebuilt after the background transfer copies locally-revoked certificates into unified storage. ui: Fix agent registry ceiling policies not displaying due to incorrect property name ui: Fix total secrets count binding on secrets sync overview page to match the API response key. ui: Resolve the flickering on the login page when a trailing slash is added to the namespace in the field.
Release notes and known issues →For stable releases, please refer to CHANGELOG.md for details. For pre-releases, please refer to CHANGELOG.md of the minor branch.
Release notes and known issues →This security and maintenance release features 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 11 security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 7.1.1 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update […]
Release notes and known issues →This security and maintenance release features 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 11 security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 7.1.1 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update […]
Release notes and known issues →compiler Commit Description wrap @for collection expression before appending non-null assertion core Commit Description return null when getDirectiveMetadata is called with null or undefined forms Commit Description mark control as dirty before setting its value in FVC interop
Release notes and known issues →compiler Commit Description wrap @for collection expression before appending non-null assertion compiler-cli Commit Description add strictUnclaimedEventNames option to catch misspelled output bindings core Commit Description return null when getDirectiveMetadata is called with null or undefined update FakeNavigation to match WHATWG HTML spec forms Commit Description mark control as dirty before setting its value in FVC interop router Commit Description maintain frozen state on rollback until resource loading completes mark router_resource module-level symbols as side-effect free
Release notes and known issues →A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare's machine learning models surface evasive client-side attacks for analyst investigation.
Release notes and known issues →Drupal 10.6.17
Release notes and known issues →Drupal 11.3.17
Release notes and known issues →Drupal 11.4.7
Release notes and known issues →Version v19.4.0
Release notes and known issues →Version v19.4.0-rc44
Release notes and known issues →The Stable channel has been updated to 154.0.8037.44/.45 for Windows. as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log . You can find more details about early Stable releases here . Interested in switching release channels? Find out how here . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common issues. Srinivas Sista Google Chrome
Release notes and known issues →Hello Everyone! We've just released Chrome 154 (154.0.8037.49) for Android to a small percentage of users. It'll become available on Google Play over the next few days. You can find more details about early Stable releases here . This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Krishna Govind Google Chrome
Release notes and known issues →Hi everyone! We've just released Chrome Beta 155 (155.0.8059.4) for Android. It's now available on Google Play . You can see a partial list of the changes in the Git log . For details on new features, check out the Chromium blog , and for details on web platform updates, check here . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome
Release notes and known issues →The Chrome team is excited to announce the promotion of Chrome 155 to the Beta channel for Windows, Mac and Linux. Chrome 155.0.8059.5 contains our usual under-the-hood performance and stability tweaks, but there are also some cool new features to explore - please head to the Chromium blog to learn more! A partial list of changes is available in the Git log . Interested in switching release channels? Find out how . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common issues. Chrome Release Team Google Chrome
Release notes and known issues →The Stable channel is being updated to OS version 16765.49.0 (Browser version 152.0.7977.129 ) for most ChromeOS devices. If you find new issues, please let us know one of the following ways: File a bug Visit our ChromeOS communities General: Chromebook Help Community Beta Specific: ChromeOS Beta Help Community Report an issue or send feedback on Chrome Interested in switching channels? Find out how. Luis Menezes Google ChromeOS
Release notes and known issues →Hello Everyone! We've just released Chrome 154 (154.0.8037.49) for Android to a small percentage of users. It'll become available on Google Play over the next few days. You can find more details about early Stable releases here . This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Krishna Govind Google Chrome
Release notes and known issues →The Stable channel has been updated to 154.0.8037.44/.45 for Windows. as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log . You can find more details about early Stable releases here . Interested in switching release channels? Find out how here . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common issues. Srinivas Sista Google Chrome
Release notes and known issues →The Chrome team is excited to announce the promotion of Chrome 155 to the Beta channel for Windows, Mac and Linux. Chrome 155.0.8059.5 contains our usual under-the-hood performance and stability tweaks, but there are also some cool new features to explore - please head to the Chromium blog to learn more! A partial list of changes is available in the Git log . Interested in switching release channels? Find out how . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common issues. Chrome Release Team Google Chrome
Release notes and known issues →Hi everyone! We've just released Chrome Beta 155 (155.0.8059.4) for Android. It's now available on Google Play . You can see a partial list of the changes in the Git log . For details on new features, check out the Chromium blog , and for details on web platform updates, check here . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome
Release notes and known issues →The Stable channel is being updated to OS version 16765.49.0 (Browser version 152.0.7977.129 ) for most ChromeOS devices. If you find new issues, please let us know one of the following ways: File a bug Visit our ChromeOS communities General: Chromebook Help Community Beta Specific: ChromeOS Beta Help Community Report an issue or send feedback on Chrome Interested in switching channels? Find out how. Luis Menezes Google ChromeOS
Release notes and known issues →Data regions are critical for helping organizations meet internal compliance, legal, regulatory, and data sovereignty obligations by controlling the geographic location of covered data at rest and through data processing. Expanding these controls to Apps Script allows organizations—including those in highly regulated industries and the public sector—to build, deploy, and automate enterprise workflows with confidence that their script data and executions remain within designated geographic boundaries. When a data regions policy is applied to an organizational unit or group, Apps Script data storage and runtime execution adhere to the specified region: Data at rest: Script project files, code definitions, manifest configurations, trigger metadata, and key-value storage (such as Property Service and Cache Service) are stored within the designated geographic region. Data processing: Script executions, container-bound automations, and associated runtime operations are processed within the selected region. Note on non-regionalized services: As Google Apps Script transitions to a regionalized data residency model, non-regionalized Apps Script services will be disabled starting in September 2026 for organizations that turn on the Drive and Docs disablement toggle in data regions advanced settings in the Admin console. Learn more about disabling non-regionalized services . Enabling Data regions support for Apps Script (Under Drive & Docs) Getting started Admins: Apps Script automatically adheres to your existing organizational data location policies configured in the Admin console under Menu > Data > Compliance > Data Regions. To manage advanced controls, such as allowing or disabling features that process data outside designated regions, navigate to Data > Compliance > Data Regions > Advanced settings. Visit the Help Center to learn more about choosing a geographic location for your data, what data is covered by a data region policy , and advanced settings for data regions . End users: There is no end user setting for this feature. Script project creation and executions will automatically follow the data region policy assigned to the user by their administrator. For custom cloud logging and external services, developers can review recommendations in the Apps Script Cloud Projects guide . Rollout pace Rapid Release and Scheduled Release domains: Available now Availability Enterprise: Enterprise Plus (provides in-region data storage and processing) Education: Education Standard and Education Plus (provides in-region data storage only) Other Editions: Frontline Plus (provides in-region data storage and processing) Resources Admin Help Center: Select geographic locations for data residency Admin Help Center: Data covered by region policies Admin Help Center: Configure advanced regional settings Admin Help Center: Overview of Assured Controls add-ons Developer Documentation: Apps Script overview and guides Developer Documentation: Managing Google Cloud Platform projects
Release notes and known issues →Earlier this year, we introduced the refreshed Google Meet homepage on the web to help you stay organized and prepared throughout your entire meeting workflow. Starting today, we’re enhancing the Meet homepage experience by displaying conference room and physical meeting locations directly on upcoming meeting cards. For in-office users this update allows them to see where they need to go directly on their Meet landing page, streamlining their workflow before and between meetings. Key capabilities of this update include: Intelligent Room Prioritization: For meetings with multiple rooms across different buildings or campuses (such as all-hands or cross-functional team syncs), Google Meet automatically compares room metadata against the user's Working Location set in Google Calendar. The conference room located in the user's building is moved to the top and highlighted, saving users from having to search through remote room lists. Wayfinding: Clicking or tapping on a conference room opens building wayfinding or campus map links (where configured by administrators), helping users navigate to unfamiliar rooms with ease. Google Maps Integration for Physical Locations: For offsite meetings, client visits, or events that specify a street address rather than a conference room, clicking the location opens Google Maps directly for turn-by-turn directions. Contextual Visibility: Room and location details are prominently visible on cards for meetings that are "Happening Now" and "Starting Soon" (< 10 minutes). For later meetings, location details appear on hover. If an event has multiple rooms or both a room and an address, hovering reveals an overflow button listing all locations. Getting started Admins: There is no admin control for this feature. Conference room details are automatically populated from the building and room resources configured in the Google Workspace Admin console (under Directory > Buildings and resources ). End users: There is no end user setting for this feature. Go to the Google Meet homepage on the web to use the enhanced experience. To take full advantage of local room prioritization, users should ensure their working location is set in Google Calendar. Visit the Help Center to learn more about setting your working location . Rollout pace Rapid Release domains: Gradual rollout (up to 15 days for feature visibility) started on September 14, 2026 Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on September 28, 2026 Availability Available to all Google Workspace customers and Workspace Individual subscribers. Resources Google Meet: Google Meet Homepage Google Meet Help: Use the Google Meet homepage Google Calendar Help: Set your working location Google Workspace Admin Help: Manage buildings, features, and resources Google Workspace Updates Blog: A centralized hub for meeting resources on the new Google Meet homepage
Release notes and known issues →Avoiding Unplanned Reboots and Service Restarts When Upgrading Veeam Analytics Service KB ID: 4927 Product: Veeam ONE | 13 | 13.1 Published: 2026-09-16 Last Modified: 2026-09-16 Purpose The Veeam Analytics Service runs on every Veeam Backup & Replication server connected to Veeam ONE. When Veeam ONE is upgraded, it automatically upgrades the Veeam Analytics Service on each connected server. On Windows-based Veeam Backup & Replication deployments, this upgrade can install a missing or outdated prerequisite runtime (Microsoft .NET Runtime or Microsoft ASP.NET Core Runtime), which can trigger an unplanned reboot of the server. A restart only occurs when a prerequisite actually has to be installed; a server that already has the required versions is upgraded without any restart. Veeam ONE cannot control or postpone this restart, because the prerequisites are installed by the platform's own installers rather than by Veeam ONE itself. Note: The Veeam Software Appliance (VSA) is not affected. Its prerequisites are supplied differently and do not require a restart to install. This article describes how to install the prerequisites on connected Windows-based Veeam Backup & Replication servers in advance, at a time chosen by the administrator, so that the Veeam ONE upgrade does not restart them. Affected upgrade paths The Veeam Analytics Service was introduced in Veeam ONE 13, so this behavior applies to upgrades between Veeam ONE 13 releases. It has been identified, on Windows-based Veeam Backup & Replication deployments, for upgrades from any Veeam ONE 13.0 build to Veeam ONE 13.1. For a full list of builds, see KB4357 . Solution To mitigate the possibility of an unplanned reboot of the Veeam Backup & Replication server, manually install the .NET components on each connected Windows-based Veeam Backup & Replication server before the Veeam ONE server is upgraded. The current list of Veeam Backup & Replication servers connected to Veeam ONE is available in the Veeam ONE Web Client, under Configuration → Data Collection Overview . Copy the following redistributables from the the \Redistr\x64\ folder on the Veeam ONE installation ISO to the connected Veeam Backup & Replication server: aspnetcore-runtime-10.0.10-win-x64.exe dotnet-runtime-10.0.10-win-x64.exe Run both installers on the Veeam Backup & Replication server, in any order. Open Apps & features (or Programs and Features ) on the Veeam Backup & Replication server and confirm both of the following are listed before proceeding to upgrade Veeam ONE: Microsoft .NET Runtime - 10.0.10 (x64) Microsoft ASP.NET Core Runtime - 10.0.10 (x64) If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
Release notes and known issues →Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #52834 [CVE-2026-90997] Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts #52835 [ CVE-2026-79651 ] Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching #52836 [ CVE-2026-74909 ] Incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher #52837 [ CVE-2026-19607 ] Username Takeover Leading to Account Lockout #52838 [ CVE-2026-17526 ] Privilege escalation: the "impersonation" role can impersonate a realm administrator #52839 [ CVE-2026-18212 ] SAML Redirect DEFLATE helpers leak native zlib state Enhancements #52354 Upgrade to Quarkus 3.33.3.2 dist/quarkus Bugs #49635 Performance issue with 26.6.2 dist/quarkus #51102 Flaky test: org.keycloak.testsuite.oauth.AccessTokenTest#accessTokenRequest ci #52015 New links errors for https://quarkus.io/guides docs #52172 Cached `RealmAdapter.isUserManagedAccessAllowed()` returns `isEnabled()` infinispan #52173 `realm_client` is computed into a client's attributes and then persisted on save admin/api #52233 Oracle 19 full client OCI driver crashes on startup since 26.6.0 — SQLFeatureNotSupportedException on setNetworkTimeout dist/quarkus #52241 Clicking on a sub group in the admin console throws an exception admin/ui #52283 Flaky test SessionRestServiceTest.testGetDevicesSessions testsuite #52430 Flaky test: userprofile.spec.ts fails with timeout on "no-users-found-empty-action" in serial suite testsuite
Release notes and known issues →Tagging release 0fcf7d2 as: deploy@1…
Release notes and known issues →The PostgreSQL skills and MCP plugin turns supported AI coding assistants into context-aware PostgreSQL experts that can both provide guidance and act on a connected database. The bundled plugin combines expert-curated skills for PostgreSQL and Azure Data
Release notes and known issues →In mid-September 2026, the following updates and enhancements were made to Azure SQL:Configure soft delete for the Azure SQL logical server. When the logical server is deleted, it goes into a soft deleted state and is self-restorable during the configured
Release notes and known issues →The containerized SAP data connector retired on September 14, 2026 and is unsupported and unmaintained. Existing TLS-compliant agents may continue sending logs through the retired HTTP Data Collector API. Container images will be removed on October 14, 20
Release notes and known issues →Azure Red Hat OpenShift with hosted control planes is now in public preview. It is a new deployment option for Azure Red Hat OpenShift that runs the OpenShift control plane as a fully managed service, separate from the worker nodes that run customer appli
Release notes and known issues →MOODLE_503_BETA
Release notes and known issues →Notable Changes [ d414624dce ] - (SEMVER-MINOR) crypto : add a generic MAC API (Filip Skokan) #65553 [ 7ac458f802 ] - (SEMVER-MINOR) crypto : discover ciphers from OpenSSL providers (Filip Skokan) #65484 [ 7c7e95a3bd ] - (SEMVER-MINOR) crypto : discover hashes from OpenSSL providers (Filip Skokan) #65484 [ 2d2f4f6d1a ] - (SEMVER-MINOR) ffi : enable module by default (Matteo Collina) #65475 [ 657415c6df ] - (SEMVER-MINOR) lib : implement node:bench (James M Snell) #65606 [ ebcfec2f0c ] - (SEMVER-MINOR) perf_hooks : implement Histogram meanCI API (James M Snell) #65606 [ e1913630c3 ] - (SEMVER-MINOR) perf_hooks : add CBOR export/import for histogram exchange (James M Snell) #65434 [ 8e9151c9f2 ] - (SEMVER-MINOR) src : let embedders supply a builtin code cache without a snapshot (Shelley Vohr) #65352 [ 889854f18b ] - (SEMVER-MINOR) src,lib : implement experimental DTLS API (James M Snell) #63182 [ 5198142c59 ] - (SEMVER-MINOR) vfs : integrate with CJS and ESM module loaders (Matteo Collina) #63653 [ 5af9d72e7f ] - (SEMVER-MINOR) worker : add support for Web Workers (Aviv Keller) #64894 Commits [ 59dcad3f44 ] - (SEMVER-MINOR) benchmark : implement node:bench version of bench tools (James M Snell) #65606 [ 6bdb6dd8fa ] - benchmark : fix max-regressions detection in compare.js (James M Snell) #65587 [ 49d40091ba ] - benchmark : add --analyze option to benchmark/scatter.js (James M Snell) #65594 [ bd40a9a19a ] - benchmark : add crypto class benchmarks (Filip Skokan) #65518 [ 6bff2238f5 ] - buffer : pad aligned allocations by a multiple of 8 (Lazizbek Ergashev) #65605 [ 37d12946dd ] - buffer : prevent abort on indexOf with lone surrogate needle (Rafael Gonzaga) #65430 [ 02f8eb3b2d ] - build : add --shared-perfetto flag (Antoine du Hamel) #65614 [ fe7032ec41 ] - build : enable V8 gdb/lldb plugin support (Chengzhong Wu) #65786 [ 109f2caf80 ] - build : allow linking shared dependencies in the GN build (Shelley Vohr) #65797 [ 55213fd8a8 ] - build : enable the V8 sandbox in shared-cage builds (Shelley Vohr) #62237 [ 120929a1b3 ] - build : add --shared-highway configure flag (Antoine du Hamel) #65686 [ c99af0942b ] - build : add --shared-abseil configure flag (Antoine du Hamel) #65682 [ 431c2bf0eb ] - build : define V8_CONTIGUOUS_COMPRESSED_RO_SPACE for shared cage (Shelley Vohr) #65464 [ b6b5764c6e ] - build : remove obsolete configure flags (Chengzhong Wu) #65456 [ a623ee29d9 ] - build,src : make --use-largepages a no-op (Joyee Cheung) #65389 [ 2f494cb7aa ] - crypto : fix multi-prime RSA JWKs (Filip Skokan) #65649 [ 501d8ac815 ] - crypto : cache valid ECDH key pairs (Filip Skokan) #65615 [ 3fd905ea8f ] - crypto : add strict mode to --force-fips (Filip Skokan) #65645 [ 54b3cdb805 ] - crypto : add FIPS indicator diagnostics channel (Filip Skokan) #65645 [ 3e6e931fc9 ] - crypto : fix public PKCS8 export error (한국) #65609 [ d414624dce ] - (SEMVER-MINOR) crypto : add a generic MAC API (Filip Skokan) #65553 [ eef579047c ] - crypto : validate JWK usages before key_ops (Filip Skokan) #65550 [ 9a9b137a24 ] - crypto : fix private SPKI export error (Filip Skokan) #65550 [ 9941fb5dab ] - crypto : fix RSA-PSS oversized salt handling (Filip Skokan) #65550 [ 09b431596a ] - crypto : correct CCM decryption FIPS error message (kyungrae) #65450 [ e6b34e6f7a ] - crypto : harden X509Certificate state (Filip Skokan) #65518 [ a884b6ccbc ] - crypto : optimize key slot caching (Filip Skokan) #65518 [ fb512086d3 ] - crypto : add null checks for OPENSSL_INIT_new() (Nora Dossche) #63457 [ 656504ffc0 ] - crypto : prevent Hmac.digest() from returning uninitialized memory (Matteo Collina) #65112 [ 15e7884732 ] - crypto : avoid throwing CryptoKey brand checks (Filip Skokan) #65503 [ 3302bec74a ] - crypto : avoid throwing KeyObject brand checks (Filip Skokan) #65503 [ 7ac458f802 ] - (SEMVER-MINOR) crypto : discover ciphers from OpenSSL providers (Filip Skokan) #65484 [ 7c7e95a3bd ] - (SEMVER-MINOR) crypto : discover hashes from OpenSSL providers (Filip Skokan) #65484 [ 0
Release notes and known issues →1.16.3 (September 16, 2026) BUG FIXES: Fix handling of destroy=false around create_before_destroy instances ( #39169 ) Fix function result comparison when there are multiple marks ( #39170 ) Filter logic for marks could cause values with multiple marks to erroneously fail validations ( #39171 ) Fix issue with import provider resolution ( #39185 )
Release notes and known issues →Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats#beats-9.4.7-release-notes
Release notes and known issues →Downloads: https://elastic.co/downloads/beats Release notes: https://www.elastic.co/docs/release-notes/beats#beats-9.5.4-release-notes
Release notes and known issues →Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Google, and Microsoft.
Release notes and known issues →You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely.
Release notes and known issues →Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/docs/release-notes/elasticsearch#elasticsearch-9.4.7-release-notes
Release notes and known issues →Downloads: https://elastic.co/downloads/elasticsearch Release notes: https://www.elastic.co/docs/release-notes/elasticsearch#elasticsearch-9.5.4-release-notes
Release notes and known issues →Version v19.4.0-rc42
Release notes and known issues →Version v19.4.0-rc43
Release notes and known issues →Google Meet users can now connect to nearby conference room hardware by entering a 5-character room code on their personal device. Building on the recent Connect Room launch that uses proximity-based detection to identify nearby hardware, this update provides a reliable manual fallback when ultrasound is unavailable or disabled. Users will see a "Connect with room code" button on their device’s pre-call screen, which allows them to enter the alphanumeric code displayed directly on the hardware’s screen. See our Early Preview announcement for full details . Getting started Admins: This feature will be ON by default and can be disabled/enabled at the device level. We have updated our admin settings for Connect room and related features, visit the Help Center to learn more . End users: This feature will be ON by default. Your admin can turn this feature off for devices in your organization. Rollout pace Rapid Release and Scheduled Release domains: Gradual rollout (up to 15 days for feature visibility) starting on September 15, 2026 Availability Available to all Google Workspace customers with Google Meet hardware devices Resources Google Meet Help: Use Connect room feature in Google Meet Workspace Updates Blog: Seamlessly join meetings on Google Meet hardware with “Connect room”
Release notes and known issues →We recently announced the launch of AI Overviews in Gmail search which allows users to ask natural language questions in Gmail’s search bar and get concise summaries and answers without digging through emails. Starting today, we are expanding access to AI Overviews in Gmail search to global users (with paid plans) who have their Gmail language set as English. Previously, this was only available to users in the US with their language set as English. Getting started Admins: This feature will be ON by default if Gemini for Workspace in Gmail is enabled and Workspace Intelligence access to Gmail is enabled . End users: This feature is available by default when smart features are enabled. Users must have both “Smart features in Gmail, Chat, and Meet” and “Google Workspace smart features” turned on to access AI Overviews in Gmail search. Rollout pace Rapid Release domains: Gradual rollout (up to 15 days for feature visibility) started on September 3, 2026 Scheduled Release domains: Full rollout (1–3 days for feature visibility) starting on September 21, 2026 Personal Google Accounts (Consumer): Gradual rollout started on September 3, 2026 Availability Business: Business Starter, Standard, and Plus Enterprise: Enterprise Starter, Standard, and Plus Consumers: Google AI Plus, Pro, and Ultra (excluding personal accounts in the EEA, UK, Switzerland, and Japan) Other Editions: Frontline Plus Education Add-ons: Google AI Pro for Education Other Add-ons: AI Expanded Access Resources Google Workspace Admin Help: Manage access to Gemini features in Workspace services Google Help: Get an AI Overview in Gmail search Google Workspace Updates Blog: Search faster and smarter with AI Overviews in Gmail search Consumer Launch Blog: Gmail is entering the Gemini era
Release notes and known issues →Download page What's new highlights Security Security: Fix CVE-2026-12704 Security: Fix CVE-2026-15815 Security: Fix CVE-2026-76154 Security: Fix CVE-2026-79656
Release notes and known issues →Download page What's new highlights Security Security: Fix CVE-2026-15815 Security: Fix CVE-2026-76154 Security: Fix CVE-2026-79656 Bug fixes Dashboards: Preserve query variable refresh setting on v2 dashboard import #132088 , @grafana-writer[bot]
Release notes and known issues →Download page What's new highlights Security Security: Fix CVE-2026-15815 Security: Fix CVE-2026-76154 Security: Fix CVE-2026-79656 Bug fixes Dashboards: Preserve query variable refresh setting on v2 dashboard import #132090 , @grafana-writer[bot] Provisioning: Fix folder rename UID collision during full sync #132164 , @grafana-writer[bot]
Release notes and known issues →Download page What's new highlights Security Security: Fix CVE-2026-15815 Security: Fix CVE-2026-76154 Security: Fix CVE-2026-79656 Bug fixes Dashboards: Preserve query variable refresh setting on v2 dashboard import #132089 , @grafana-writer[bot] Provisioning: Fix folder rename UID collision during full sync #132157 , @grafana-writer[bot]
Release notes and known issues →Veeam Backup & Replication Upgrade Paths KB ID: 2053 Product: Veeam Backup & Replication | 10 | 11 | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 | 13 | 13.1 Published: 2015-07-10 Last Modified: 2026-09-15 Languages: JP Tenants of Veeam Cloud Service Providers If your Veeam Backup & Replication installation is connected to a Veeam Cloud Service Provider, contact your Service Provider before upgrading to ensure that the intended upgrade will not break compatibility. A tenant cannot be on a newer version of Veeam Backup & Replication than the Service Provider. Purpose This article documents upgrade paths available to Windows-based Veeam Backup & Replication deployments to reach the latest version. Solution End of Support Upgrade Path If you are using a version of Veeam Backup & Replication (VBR) that has reached its End of Support (EOS) and cannot be directly upgraded to a supported version, you will need to install a new instance of VBR using the latest VBR version . Clarification: If the Upgrade Instructions in the User Guide for a currently supported version of VBR include an upgrade path from an older, unsupported version, this upgrade pathway is still considered supported. This article provides details on upgrade processes for such situations, provided that a currently supported version of VBR supports a direct upgrade from these older versions. For example: When VBR version 11a was supported, it provided an upgrade path from VBR version 9.5 Update 4b. However, VBR version 12 does not support upgrading directly from 9.5 Update 4b. As a result, after VBR 11a reached EOS, the upgrade path for 9.5 Update 4b was removed from this document. VBR version 12.0, which is currently supported, allows upgrading directly from VBR version 10a. Thus, although VBR 10a is no longer supported itself, the upgrade details for 10a are included in this document because an upgrade to VBR 12.0 from that version is officially supported. VSA Migration Version Limitation Please note that deployment migration from Windows-based Veeam Backup & Replication to the new Linux-based Veeam Software Appliance is supported only for version 13.0.x builds. Customers who plan to migrate deployments should remain on 13.0.3 until after the migration is completed. More Information: KB4800: Veeam Backup & Replication Platform Migration Guide (Windows to Linux) Veeam Backup & Replication 13.0.3.63 remains available from the Previous Versions download page . The upgrade paths shown below for 13.1 are the same for 13.0. 10a to 13.1.1 Path: 10a (10.0.1.x) → 12.0 → 12.3.2 → 13.1.1 Upgrade to Veeam Backup & Replication 12.0 Note: It is necessary to first upgrade to Veeam Backup & Replication 12.0 to allow components such as Veeam Backup for Nutanix AHV Proxy to be upgraded to a version that is compatible with being upgraded to the version included with Veeam Backup & Replication 12.3.2. Upgrade to Veeam Backup & Replication 12.3.2 Upgrade to Veeam Backup & Replication 13.1.1 11 to 13.1.1 Path: 11 (11.0.0.x) → 12.0 → 12.3.2 → 13.1.1 Upgrade to Veeam Backup & Replication 12.0 Note: It is necessary to first upgrade to Veeam Backup & Replication 12.0 to allow components such as Veeam Backup for Nutanix AHV Proxy to be upgraded to a version that is compatible with being upgraded to the version included with Veeam Backup & Replication 12.3.2. Upgrade to Veeam Backup & Replication 12.3.2 Upgrade to Veeam Backup & Replication 13.1.1 11a to 13.1.1 Veeam Backup & Replication 11a Upgrade Path Notes If the Veeam Backup & Replication 11a deployment does not interact with Nutanix AHV , it can be upgraded directly to the latest version 12.3 release, skipping version 12.0. If Veeam Backup & Replication 11a P20240304 is installed, it is only compatible with upgrading to version 12.1.2 or higher (such as 12.3). Upgrading to version 12.0 is not supported. Path: 11a (11.0.1.x) → 12.0 → 12.3.2 → 13.1.1 Upgrade to Veeam Backup & Replication 12.0 Note: It is necessary to first upgrade to Veeam Back
Release notes and known issues →Kanister Pods Fail Image Pulls on Kubernetes 1.35 KB ID: 4929 Product: Veeam Kasten for Kubernetes Published: 2026-09-15 Last Modified: 2026-09-15 Challenge On Kubernetes 1.35 or later, Veeam Kasten for Kubernetes worker pods fail with ImagePullBackOff errors when the cluster uses a private container registry. These pods run in the application namespace and have no image pull credentials. The following operations are affected: Backup and restore of applications protected by a Kanister blueprint Backup of volumes not attached to a running workload Execution hooks whose blueprint creates a pod Generic Storage Backup operations Kanister times out after approximately 15 minutes per attempt. Cause This issue occurs because Kubernetes 1.35 enables the KubeletEnsureSecretPulledImages feature gate by default. Every pod must now present valid registry credentials to pull an image, and cached images no longer bypass authentication. Veeam Kasten for Kubernetes runs certain worker pods in the application namespace. The image pull secret (by default, k10-ecr ) exists only in the kasten-io namespace. Those worker pods have no imagePullSecrets and reference no service account credentials, so they cannot authenticate against a private registry. On Kubernetes 1.34 and earlier, cached images did not require re-authentication. This masked the missing credentials. Solution Copy the image pull secret into each protected namespace, then attach it to the default service account of that namespace. Both steps are required. A secret that exists in the namespace but is not referenced by the service account has no effect. Prerequisites kubectl access to the cluster Permission to create secrets and patch service accounts in the target namespace The name of the image pull secret used during Veeam Kasten for Kubernetes installation (default: k10-ecr ) Procedure 1. Set variables for the target namespace and secret name. If a name other than k10-ecr was provided to global.imagePullSecret during installation, replace the value accordingly: export APP_NAMESPACE = < application-namespace > export SECRET_NAME = k10-ecr Copy 2. Copy the image pull secret from the kasten-io namespace into the application namespace: kubectl get secret ${SECRET_NAME} --namespace = kasten-io --output = json \ | jq '{apiVersion, kind, metadata: {name: .metadata.name}, type, data}' \ | kubectl apply --namespace = ${APP_NAMESPACE} --filename = - Copy 3. Patch the default service account to reference the secret: kubectl patch serviceaccount default \ --namespace = ${APP_NAMESPACE} \ --patch = "{ \" imagePullSecrets \" :[{ \" name \" : \" ${SECRET_NAME} \" }]}" Copy 4. Repeat steps 1–3 for each protected application namespace. 5. Delete any Kanister pods stuck in ImagePullBackOff . Veeam Kasten for Kubernetes recreates them with the updated credentials. Important The kubectl patch command replaces the imagePullSecrets field rather than merging into it. If the default service account already lists other image pull secrets, include them in the patch value. To restore an application into a namespace that does not yet exist, create and configure that namespace before you run the restore. More Information This is a documented workaround. A product-side fix is tracked internally. Clusters that use a public registry are not affected. For more information on private registry configuration, see the Air-Gapped Installation section of the Veeam Kasten documentation. For details on the upstream Kubernetes change, see KEP-2535 ( KubeletEnsureSecretPulledImages ). If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
Release notes and known issues →Downloads: https://elastic.co/downloads/kibana Release notes: https://www.elastic.co/docs/release-notes/kibana#kibana-9.4.7-release-notes
Release notes and known issues →Downloads: https://elastic.co/downloads/kibana Release notes: https://www.elastic.co/docs/release-notes/kibana#kibana-9.5.4-release-notes
Release notes and known issues →Downloads: https://elastic.co/downloads/logstash Release notes: https://www.elastic.co/docs/release-notes/logstash#logstash-9.4.7-release-notes
Release notes and known issues →Downloads: https://elastic.co/downloads/logstash Release notes: https://www.elastic.co/docs/release-notes/logstash#logstash-9.5.4-release-notes
Release notes and known issues →Details on this release can be found in the Release Notes
Release notes and known issues →Details on this release can be found in the Release Notes
Release notes and known issues →nginx-1.30.5 stable version has been released, with fixes for buffer overflow vulnerability when using ngx_http_v3_module ( CVE-2026-90439 ). See official CHANGES-1.30 on nginx.org. Below is a release summary generated by GitHub. What's Changed nginx-1.30.5-RELEASE by @pluknet in #1772 Full Changelog : release-1.30.4...release-1.30.5
Release notes and known issues →nginx-1.31.6 mainline version has been released, with fixes for buffer overflow vulnerability when using ngx_http_v3_module ( CVE-2026-90439 ). See official CHANGES on nginx.org. Below is a release summary generated by GitHub. What's Changed man page updates by @pluknet in #1727 Handle predicate location variable error by @arut in #1750 Handle nested location lookup error by @arut in #1751 Control API: fixed socket inheritance on binary upgrade by @pluknet in #1760 Geo: check binary base CRC32 before relocation by @pluknet in #1739 QUIC compatibility layer fix by @pluknet in #1769 nginx-1.31.6-RELEASE by @pluknet in #1770 Full Changelog : release-1.31.5...release-1.31.6
Release notes and known issues →Expose a best-effort AOF replay-time estimate in INFO persistence so operators can gauge reload RTO. Count time only for writes that enter the AOF, credit leftover call() time to synthetic rewrites, and skip the bookkeeping when AOF is off.
Release notes and known issues →.......... [ZBXNEXT-826] release of 7.0.31rc1
Release notes and known issues →.......... [ZBXNEXT-826] release of 7.4.15rc1
Release notes and known issues →Build Numbers and Versions of Veeam Backup for Microsoft 365 KB ID: 4106 Product: Veeam Backup for Microsoft 365 | 6.0 | 7.0 | 7a | 8 | 8.1 | 8.2 | 8.3 | 8.4 | 8.5 | 8.6 Veeam Backup for Microsoft Office 365 | 1.0 | 1.5 | 2.0 | 3.0 | 4.0 | 5.0 Published: 2021-02-17 Last Modified: 2026-09-14 This KB article lists all versions of Veeam Backup for Microsoft 365 and their respective build numbers. For more information on downloading the latest version of Veeam Backup for Microsoft 365 , visit: Veeam Backup for Microsoft 365 — Current Version Download Page Veeam Backup for Microsoft 365 — What's New PDF Version Console Build Build in Logs Release Date Release Notes Veeam Backup for Microsoft 365 8 Releases Veeam Backup for Microsoft 365 8.6 8.6.0.1102 13.6.0.1102 2026-09-14 KB4913 HTML Veeam Backup for Microsoft 365 8.5 8.5.0.1014 13.5.0.1014 2026-06-29 KB4873 HTML Veeam Backup for Microsoft 365 8.4 8.4.0.1457 13.4.0.1457 2026-04-16 KB4843 HTML Veeam Backup for Microsoft 365 8.3 8.3.0.2201 13.3.0.2201 2025-12-18 KB4809 HTML Veeam Backup for Microsoft 365 8.2 P20251031 8.2.0.2202 13.2.0.2202 2025-11-06 KB4751 Veeam Backup for Microsoft 365 8.2 8.2.0.2008 13.2.0.2008 2025-10-23 KB4751 HTML Veeam Backup for Microsoft 365 8.1.2.3301 8.1.2.3301 13.1.2.3301 2025-10-24 KB4711 HTML Veeam Backup for Microsoft 365 8.1.2.180 8.1.2.180 13.1.2.180 2025-07-01 Veeam Backup for Microsoft 365 8.1.1.159 8.1.1.159 13.1.1.159 2025-04-02 Veeam Backup for Microsoft 365 8.1.0.3503 8.1.0.3503 13.1.0.3503 2025-02-27 Veeam Backup for Microsoft 365 8.1.0.331 8.1.0.331 13.1.0.331 2025-02-11 Veeam Backup for Microsoft 365 8.1 8.1.0.305 13.1.0.305 2025-01-23 Veeam Backup for Microsoft 365 8.0.5 8.0.5.20 13.0.5.20 2024-11-14 KB4656 HTML Veeam Backup for Microsoft 365 8.0.4 8.0.4.29 13.0.4.29 2024-10-30 Veeam Backup for Microsoft 365 8.0.3.1073 8.0.3.1073 13.0.3.1073 2024-10-16 Veeam Backup for Microsoft 365 8 P20241004 8.0.3.1044 13.0.3.1044 2024-10-08 Veeam Backup for Microsoft 365 8 P20240910 8.0.2.200 13.0.2.200 2024-09-11 Veeam Backup for Microsoft 365 8 8.0.2.159 13.0.2.159 2024-09-03 Veeam Backup for Microsoft 365 7 Releases Veeam Backup for Microsoft 365 7a P20240418 7.1.0.2031 12.1.0.2031 2024-04-24 KB4533 Veeam Backup for Microsoft 365 7a P20240411 7.1.0.1502 12.1.0.1502 2024-04-15 Veeam Backup for Microsoft 365 7a P20240123 7.1.0.1501 12.1.0.1501 2024-01-25 Veeam Backup for Microsoft 365 7a P20231218 7.1.0.1401 12.1.0.1401 2023-12-26 Veeam Backup for Microsoft 365 7a 7.1.0.1301 12.1.0.1301 2023-12-05 PDF Veeam Backup for Microsoft 365 7 P20240123 7.0.0.4901 12.0.0.4901 2024-01-25 KB4425 Veeam Backup for Microsoft 365 7 P20231218 7.0.0.4551 12.0.0.4551 2023-12-25 Veeam Backup for Microsoft 365 7 P20231015 7.0.0.4388 12.0.0.4388 2023-10-15 Veeam Backup for Microsoft 365 7 P20231005 7.0.0.4385 12.0.0.4385 2023-10-12 Veeam Backup for Microsoft 365 7 P20230704 7.0.0.3968 12.0.0.3968 2023-07-13 Veeam Backup for Microsoft 365 7 P20230512 7.0.0.3604 12.0.0.3604 2023-05-24 Veeam Backup for Microsoft 365 7 P20230421 7.0.0.3007 12.0.0.3007 2023-04-25 Veeam Backup for Microsoft 365 7 P20230302 7.0.0.2914 12.0.0.2914 2023-03-09 Veeam Backup for Microsoft 365 7 7.0.0.2911 12.0.0.2911 2023-02-28 PDF Veeam Backup for Microsoft 365 6 Releases Veeam Backup for Microsoft 365 6a P20230322 6.1.0.1015 11.2.0.1015 2023-03-28 KB4347 Veeam Backup for Microsoft 365 6a P20221215 6.1.0.438 11.2.0.438 2022-12-20 Veeam Backup for Microsoft 365 6a P20220926 6.1.0.423 11.2.0.423 2022-10-06 Veeam Backup for Microsoft 365 6a P20220825 6.1.0.254 11.2.0.254 2022-08-25 Veeam Backup for Microsoft 365 6a 6.1.0.222 11.2.0.222 2022-08-10 PDF KB4344 Veeam Backup for Microsoft 365 6 P20220718 6.0.0.400 11.1.0.400 2022-07-27 KB4285 Veeam Backup for Microsoft 365 6 P20220524 6.0.0.385 11.1.0.385 2022-05-31 Veeam Backup for Microsoft 365 6 P20220413 6.0.0.379 11.1.0.379 2022-05-05 Veeam Backup for Microsoft 365 6 GA 6.0.0.367 11.1.0.367 2022-03-09 PDF KB4286 Veeam Backup for Microsoft Office 365 5
Release notes and known issues →Shared Server Compatibility of Veeam Backup for Microsoft 365 and Veeam Backup & Replication KB ID: 4325 Product: Veeam Backup & Replication | 12 | 12.1 | 12.2 | 12.3 | 13 | 13.1 Veeam Backup for Microsoft 365 | 8 | 8.1 | 8.2 | 8.3 | 8.4 | 8.5 | 8.6 Published: 2022-08-10 Last Modified: 2026-09-14 Purpose It is important to remember that Veeam Backup for Microsoft 365 and Veeam Backup & Replication are separate backup products designed to operate separately from each other. However, both Veeam Backup for Microsoft 365 and Veeam Backup & Replication utilize Veeam Explorers as secondary applications to perform application item restores. The Veeam Explorers are installed alongside either backup application. Due to this shared use of the Veeam Explorer applications, it is imperative that when both Veeam Backup for Microsoft 365 and Veeam Backup & Replication are installed on the same server, that only specific compatible versions be installed (see table below) . Failure to ensure compatibility could lead to a situation where one backup product may not be able to utilize the Veeam Explorer application installed by the other backup product, thus causing application item restores to fail. Solution When installing Veeam Backup & Replication (VBR) and Veeam Backup for Microsoft 365 (VB365) on the same server, be mindful of the following compatibility when upgrading. Note: As new versions of either product are released, they will be added to the table, and as versions reach End of Support , they will be removed. The release schedule of these products is not synchronized. If a version of either product is released before the compatible version of the other, it is critical to wait until inter-compatible versions are available. For example, if a new version of Veeam Backup & Replication is released and a compatible version of Veeam Backup for Microsoft 365 is not available yet, upgrading Veeam Backup & Replication would lead to the issue documented in KB3028 . Build Numbers and Versions of Veeam Backup & Replication Build Numbers and Versions of Veeam Backup for Microsoft 365 VBR13.1 VBR 13 VBR 12.1, 12.2, 12.3 VBR 12.0 VB365 8.6 [1] , [2] [1] , [2] [1] , [2] [1] VB365 8.5 [1] , [2] [1] , [2] [1] , [2] [1] VB365 8.4 [1] , [2] [1] , [2] [1] , [2] [1] VB365 8.3 [1] , [2] [1] , [2] [1] , [2] [1] VB365 8.2 [1] , [2] [1] , [2] [1] , [2] [1] VB365 8.1 [1] , [2] [1] , [2] [1] , [2] [1] VB365 8 [1] , [2] [1] , [2] [1] , [2] [1] This table lists only actively supported versions . Swipe to show more of the table 1 KB4638: How to Use Existing Veeam Backup & Replication PostgreSQL instance for Veeam Backup for Microsoft 365 Deployment 2 KB4639: Veeam Backup & Replication Install Fails with: "A later version of Veeam Explorer for Microsoft Exchange is already installed." If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case. To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
Release notes and known issues →List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Veeam Kasten for Kubernetes | 7 | 7.5 | 8 | 8.5 | 9 Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: 2026-09-14 Purpose This article describes all security-related fixes and improvements introduced in each release or update of Veeam Kasten for Kubernetes . This article aims to provide our customers' security and compliance teams with detailed information on security improvements. Full product release notes are available here: Veeam Kasten for Kubernetes — Release Notes Security Fixes and Improvements Veeam Kasten for Kubernetes 9.0.5 Upgraded to latest UBI base image to resolve multiple CVEs in base OS packages. Updated the Go runtime to resolve additional upstream Go CVEs. Updated the bundled Prometheus Helm chart to resolve security issues. Veeam Kasten for Kubernetes 9.0.4 Upgraded to latest UBI base image to resolve multiple CVEs in base OS packages. Patched go-ntlmssp in the Dex component to resolve CVE-2026-32952. Updated the Go runtime and golang.org/x/mod dependency to resolve CVE-2026-56865 and additional upstream Go CVEs. Veeam Kasten for Kubernetes 9.0.3 Upgraded go-git to resolve CVE-2026-71556 Upgraded the configmap-reload sidecar to resolve CVE-2026-56852 Upgraded the Prometheus base image to resolve GHSA-hrxh-6v49-42gf - GitHub Advisory Upgraded Dex image dependencies to resolve multiple Critical and High CVEs Veeam Kasten for Kubernetes 9.0.2 Upgraded to the latest UBI base image to resolve multiple CVEs. Updated third-party dependencies (gomplate, logger base image) in the dex and logger components to address known vulnerabilities. Veeam Kasten for Kubernetes 9.0.1 Upgraded to Go 1.26.5 to resolve CVE-2026-39822 & CVE-2026-42505 Updated the UBI minimal base image to incorporate the latest security fixes. Improved logging security for Veeam Backup & Replication API credentials and other sensitive values previously written to Kasten logs. It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out . Upgraded components of Kasten's bundled Prometheus monitoring stack to resolve multiple CVEs Veeam Kasten for Kubernetes 8.5.13 Updated base images used in the Red Hat Marketplace operator bundle to fix multiple Critical and High CVEs Veeam Kasten for Kubernetes 8.5.12 Upgraded to the latest UBI base image to resolve CVE-2026-45186 and CVE-2026-45447 Upgraded to Go 1.26.4 to resolve CVE-2026-42504 Kasten Multi-cluster Permissions : Hardened multi-cluster security by tightening the permissions granted to the impersonation `ClusterRole` on managed secondary clusters and removing sensitive token values from debug logs. Veeam Kasten for Kubernetes 8.5.10 Upgraded to latest UBI base image to resolve CVE-2026-40356 and CVE-2026-4878 Immutability regression in Kasten 8.5.1–8.5.9 (S3 / GCS / Azure) Newly written backup objects were not stamped with a retain-until date at write time and remained deletable until the Blob Lifecycle Manager applied protection on its next refresh cycle. A user, script, or attacker with bucket delete permissions could permanently delete those objects during this window, potentially rendering the affected restore points unrecoverable. Mitigation: Configure a bucket-level Default Object Lock retention so the object store stamps new objects at write time, or upgrade to Kasten 8.5.10. Veeam Kasten for Kubernetes 8.5.5 Upgrade to Go 1.26.1 to address CVE-2026-25679 and CVE-2026-27142 Updated the UBI base image to address CVE-2026-4111 Veeam Kasten for Kubernetes 8.5.3 Upgrade to Go 1.25.7 to address CVE-2025-61732 . Veeam Kasten for Kubernetes 8.5.2 Updated base image used to build Veeam Kasten container images to pull in latest security updates. Veeam Kasten for Kubernetes 8.5.1 Upgrade to Go 1.25.6 to address CVEs: CVE-2025-61726 CVE-2025-61728 CVE-2025-61731 CVE-2025-68119 CVE-2025-68121 Updated base image used to build Veeam Kasten container imag
Release notes and known issues →Release Information for Veeam Backup for Microsoft 365 8.6 KB ID: 4913 Product: Veeam Backup for Microsoft 365 | 8.6 Published: 2026-09-14 Last Modified: 2026-09-14 Requirements This release can be used to: upgrade an existing v8, v8.1, v8.2, v8.3, v8.4, or v8.5 deployment of Veeam Backup for Microsoft 365 to v8.6. install a new deployment of Veeam Backup for Microsoft 365 v8.6. After installing this release, the Veeam Backup for Microsoft 365 build number will be 8.6.0.1102 . Release Information 8.6.0.1102 2026-09-14 Release Notes for Veeam Backup for Microsoft 365 8.6 New Features and Enhancements Added PowerShell cmdlets to remediate data in JET-based repositories, repositories with backup copies, and immutable repositories affected by the issue described in KB4835 . For more information, see KB4874 . When an organization is added or edited, the backup app registrations in Microsoft Entra ID automatically receive the permissions required to support Exchange mailbox protection after EWS retirement. For more information, see KB4820 . Added the ability to place object storage backup repositories into maintenance mode using PowerShell cmdlets or the REST API. While a repository is in maintenance mode, Veeam Backup for Microsoft 365 blocks all operations on that repository, allowing administrators to safely perform storage-level maintenance without interference. Bug Fixes General A retention task gets stuck and times out after the NATS server restarts. Backup and Backup Copy When the public folder hierarchy root stored in the backup no longer matches the root folder reported by Microsoft 365, public folder mailbox backup fails while processing the hierarchy root ( IPM_SUBTREE ) with the error: Object reference not set to an instance of an object In multi-geo organizations where location protection is disabled, SharePoint backup jobs fail with the error: Failed to resolve sites: ambiguous locations found SharePoint incremental backup jobs process all site changes from the beginning instead of continuing from the last backup point after SharePoint rejects a change token as outdated. When redirect site URL lookups are throttled and cannot acquire a request slot within the allowed wait time, even if throttling is not reported at the tenant level, a SharePoint backup job fails at the site resolution stage with the error: Request must be retried In organizations with a hybrid Exchange deployment, some mailboxes are skipped during backup with the warning: Exchange account was not found. A backup job that fails at the resolve stage because of Microsoft 365 throttling is reported as Failed. No restore point is created and no retry is attempted, even when some objects were processed successfully. A backup job processing SharePoint or Teams data does not trigger a retry run when all objects fail with the error: Access to this site is blocked. In multi-geo Microsoft 365 organizations, a throttling event in one geo region causes backup jobs in all other regions to slow down or fail. A Teams backup job fails with an out-of-memory error when processing channels that contain a very large number of messages. In multi-geo SharePoint environments, a backup job fails for sites whose data location cannot be resolved to any configured geo region. A SharePoint backup job intermittently fails during the resolve stage with the error: Object reference not set to an instance of an object When the backup scope includes archived Microsoft Teams, a backup job fails with the error: The response status code does not indicate success: 400 (Bad Request) Restore Browsing or restoring OneDrive and SharePoint data from archive-tier object storage hangs and eventually times out. Search in Veeam Explorer for Microsoft Exchange fails with an ArgumentOutOfRangeException error when a mailbox item contains an RTF-formatted body with emoji or other characters outside the Basic Multilingual Plane. Saving OneDrive items using Veeam Explorer for Microsoft OneDrive fails with
Release notes and known issues →Microsoft's September 2026 cumulative security update for Windows Server 2012 Extended Security Updates.
Release notes and known issues →Tagging release f887bb9 as: deploy@1…
Release notes and known issues →Version: 5.10.270 (longterm) Released: 2026-09-14 Source: linux-5.10.270.tar.xz PGP Signature: linux-5.10.270.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-5.10.270
Release notes and known issues →Version: 6.1.188 (longterm) Released: 2026-09-14 Source: linux-6.1.188.tar.xz PGP Signature: linux-6.1.188.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-6.1.188
Release notes and known issues →Version: 5.10.270 (longterm) Released: 2026-09-14 Source: linux-5.10.270.tar.xz PGP Signature: linux-5.10.270.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-5.10.270
Release notes and known issues →Version: 5.15.221 (longterm) Released: 2026-09-14 Source: linux-5.15.221.tar.xz PGP Signature: linux-5.15.221.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-5.15.221
Release notes and known issues →Version: 6.1.188 (longterm) Released: 2026-09-14 Source: linux-6.1.188.tar.xz PGP Signature: linux-6.1.188.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-6.1.188
Release notes and known issues →Version: 6.6.157 (longterm) Released: 2026-09-14 Source: linux-6.6.157.tar.xz PGP Signature: linux-6.6.157.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-6.6.157
Release notes and known issues →Version: 6.6.157 (longterm) Released: 2026-09-14 Source: linux-6.6.157.tar.xz PGP Signature: linux-6.6.157.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-6.6.157
Release notes and known issues →Version: 5.15.221 (longterm) Released: 2026-09-14 Source: linux-5.15.221.tar.xz PGP Signature: linux-5.15.221.tar.sign Patch: full ( incremental ) ChangeLog: ChangeLog-5.15.221
Release notes and known issues →Beginning in early October 2026, Windows App will begin using three new wildcard fully qualified domain names (FQDNs) for client-side service traffic to Azure Virtual Desktop. These domains are already included in the cloud-side connectivity requirements.
Release notes and known issues →Announcing public preview support for HTTP/3 over QUIC on Azure Application Gateway. HTTP/3 is the next evolution of HTTP and uses QUIC to improve connection setup time, reduce latency, and provide better resiliency for modern web applications and APIs. W
Release notes and known issues →v0.315.0-rc.0
Release notes and known issues →[CHANGE] PromQL: A range query whose end was not aligned to step caused subqueries inside it to evaluate past the parent's last actual step, inflating peakSamples in the query stats and against the query.max-samples limit, and wasting storage I/O reading samples that were never used in the result. Add tests to prevent regression of the fix made in #18081 . #18598 [CHANGE] PromQL: Do not register a start timestamp reset if the start timestamp hasn't changed between subsequent samples. #19454 [CHANGE] Logging: Deprecate --log.level ; use runtime.log_level configuration to supply the default level. #19511 [FEATURE] Configuration: Allow changing the process log level through runtime.log_level on configuration reload. #19511 [FEATURE] Prometheus: Add --auto-gomemlimit.refresh-interval flag to periodically re-detect the container or system memory limit and update GOMEMLIMIT at runtime. #18843 [FEATURE] Scraping: Add support for scraping targets via Unix Domain Sockets. #12024 . #18091 [FEATURE] scrape: Implement OM2.0 scrape format. #18606 [ENHANCEMENT] Reduce TSDB head CPU utilization when initializing. #18001 [ENHANCEMENT] Docker SD: Add labels __meta_docker_container_image and __meta_docker_container_image_id . #19386 [ENHANCEMENT] Mixin: Add a p95/p99 remote-write send-batch latency panel to the remote-write dashboard. #19500 [ENHANCEMENT] Mixin: Support native histograms in the remote-write send-batch latency panel. #19522 [ENHANCEMENT] PromQL/TSDB: The --enable-feature=st-storage flag now automatically enables XOR2 float chunk encoding and ST-capable histogram chunk encoding, so you no longer need to pass xor2-encoding and histograms-st-encoding alongside it. #19518 [ENHANCEMENT] Remote write / Alertmanager: upgrade sigv4 to v0.5.0, adding session_name and tags fields for STS AssumeRole sessions. The previously undocumented service_name field is now also documented. #19569 [ENHANCEMENT] Scraping: Support zstd-compressed scrape responses, enabled via feature flag zstd-scrape . #19502 [ENHANCEMENT] TSDB: Stabilize the XOR2 float chunk encoding. --enable-feature=xor2-encoding is deprecated; use storage.tsdb.chunk_encoding.floats: xor2 instead. Check that other software reading the TSDB directly (e.g. Thanos sidecar) supports XOR2 before enabling. #19461 [ENHANCEMENT] TSDB: add prometheus_tsdb_head_appenders_created_total metric. #19411 [ENHANCEMENT] Tracing: add more spans to scrapes, API queries and rule evaluations. #19410 [ENHANCEMENT] UI: Show the effective configuration for each scrape pool on the Targets and Service Discovery pages. #19384 [ENHANCEMENT] scrape: Enable start time synthesis for summary _count and _sum series in scrape appender v2. #19323 [ENHANCEMENT] scrape: stop all pools in parallel for faster shutdowns. #19295 [ENHANCEMENT] storage/remote: Add undocumented failed_request_logging config field to debug log remote write V2 requests on send errors. #19249 [ENHANCEMENT] TSDB: Add fast path for XOR chunk decompression to speed up queries. #18049 [ENHANCEMENT] UI: Improve native histogram table formatting and add a background bar indicating the bucket count. #19332 [ENHANCEMENT] TSDB: Add prometheus_tsdb_head_series_pending_commit_underflow_total to report pending-sample reservation underflows. #19470 [PERF] AWS SD: Build RDS cluster labels once per cluster instead of once per instance. #19504 [PERF] AWS SD: Describe RDS instances of different clusters concurrently, bounded by request_concurrency . #19506 [PERF] AWS SD: Describe each ElastiCache resource once per refresh instead of twice. #19585 [PERF] Remote read: Avoid cloning labels for sampled reads when no external labels are configured. #19503 [PERF] Remote write: Reuse OTLP converter scratch state between requests. #19388 [PERF] scrape: conversion from classic to native histograms should only parse start times when enabled. #19446 [BUGFIX] PromQL: Fix info() enrichment for composite expressions with mixed @ /offset references or selector-free vector branc
Release notes and known issues →RabbitMQ 4.3.6 is a maintenance release in the 4.3.x release series . It is strongly recommended that you read 4.3.0 release notes in detail if upgrading from a version prior to 4.3.0 . Minimum Supported Erlang Version The minimum supported Erlang version for this release series is 27.0 . RabbitMQ and Erlang/OTP Compatibility Matrix has more details on Erlang version requirements for RabbitMQ. Nodes will fail to start on older Erlang releases. Changes Worth Mentioning Release notes can be found on GitHub at rabbitmq-server/release-notes . Core Server Bug Fixes Deleting an exchange did not delete the bindings that pointed to it as a destination. A few related cases around auto-delete exchanges, transient queue cleanup and virtual host deletion were fixed along the way. GitHub issues: #17255 , #17257 Quorum queue continuous membership reconciliation could add more replicas than the configured target. GitHub issues: #17310 , #17311 Certain malformed urn:uuid: correlation or message ID caused exceptions during message format conversion. Such values are now rejected. GitHub issue: #17328 An operation that refers to an unknown queue type now fails with a precondition_failed channel exception instead of an exception and abrupt channel termination. GitHub issue: #17327 Classic queue recovery counted some message store references more than once. GitHub issue: #17351 x-max-age values are now compared as durations, so redeclaring a stream with 1D when it was declared with 24h no longer fails with a PRECONDITION_FAILED (non-equivalent argument) exception. With contributions from @Vishal-770 . GitHub issues: #8509 , #17259 AMQP 1.0 SQL filters: the value matched by a LIKE pattern with several wildcards is now bounded independently of the message size limit. GitHub issue: #17332 Direct connections (used by the shovel and federation plugins) now enforce channel_max_per_node the same way network connections do. Contributed by @Ayanda-D . GitHub issue: #16610 Enhancements New rabbitmq.conf setting: channel_tx_message_max . It bounds the number of publishes a channel buffers in an open AMQP 0-9-1 transaction, and defaults to 10,000. Going over the limit results in a precondition_failed channel exception. Most applications won't be affected by this change and likely will not have to increase the default limit. GitHub issue: #17331 New rabbitmq.conf setting: listeners.startup_delay . It delays the start of client connection listeners by the specified number of seconds, for environments where applications begin connecting as soon as a port is open, before the node has finished booting. Contributed by @Vishal-770 . GitHub issues: #13153 , #17289 Several channel interceptors can now be registered for the same AMQP 0-9-1 operation, as long as they use different priorities. Previously, if two enabled plugins intercepted the same operation, for example basic.publish , channels could not be opened at all. Priorities are set per interceptor module in rabbitmq.conf . Lower values run first, and omitted interceptors are assumed to have the priority of 0 : channel_interceptor.priorities.rabbit_timestamp_interceptor = 1 channel_interceptor.priorities.rabbit_routing_node_stamp_interceptor = 2 channel_interceptor.priorities.rabbit_sharding_interceptor = 3 Contributed by @Ayanda-D . GitHub issue: #17182 Shovels now support a new AMQP URI query parameter, customize_hostname_check , that controls how the target hostname is matched against the server certificate, for example with wildcard certificates. Contributed by @jiangranwang . GitHub issue: #17221 CLI Tools Bug Fixes rabbitmq-diagnostics check_certificate_expiration now handles certificate files that cannot be read, and certificates that use the RFC 5280 UTCTime format, the same way the HTTP API health check does. Contributed by @Vishal-770 . GitHub issues: #12464 , #17345 Enhancements Two new commands, rabbitmqctl list_channel_interceptors and rabbitmqctl set_channel_interceptor_priorities , list the active
Release notes and known issues →MOODLE_40514
Release notes and known issues →MOODLE_50010
Release notes and known issues →MOODLE_5017
Release notes and known issues →MOODLE_5023
Release notes and known issues →A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Release notes and known issues →Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Release notes and known issues →A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
Release notes and known issues →An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Release notes and known issues →Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Release notes and known issues →Cloudflare CASB policies introduce a native automation engine built directly on the Cloudflare developer platform to remediate SaaS risks automatically. Security teams can now design event-driven logic to revoke risky file shares and send webhooks without manual intervention.
Release notes and known issues →