Platform Engineering
IaC, container orchestration, service mesh, and internal developer platforms.
v8.2.2
(10d)
CVE fix + bug fixes
v2.24.5
(21d)
Azure identity hardening
v2.29.13
(21d)
Security fixes + Go upgrade
v2.31.12
(21d)
CVE security fixes
v2.32.2
(21d)
CVE-2026-33814 fix
v2.33.3
(21d)
CVE fixes
⚠ Upgrade required
- Final release for ESCU v5.x; starting with ESCU v6.0, content will be validated, packaged, and published using new internal tooling instead of contentctl.
Security fixes
- CVE-2026-31431 – Linux Auditd Copy Fail Privilege Escalation detection added to identify unprivileged users writing controlled data to page cache and escalating to root.
Notable features
- Cisco Secure Access Analytics analytic story using firewall telemetry
- Expanded Windows threat detection analytics covering PowerShell abuse, process injection, privilege escalation, cloud/Azure activity, RMM tools, and C2 frameworks
Security fixes
- Patched vulnerable frontend dependencies (#15661)
Security fixes
- Fixed access token renewal bypassing important checks
- Blocked callback URLs with javascript: and data: protocols
Notable features
- Admins can now revoke user passkeys
- Added auth method claim (amr) to OIDC tokens
- Added TLS support for HTTP/2 server
Security fixes
- CVE-2026-33186 — grpc-go authz bypass patch in CLI and enclave-manager
Notable features
- shm size ulimits adjustments for GPU environments
Security fixes
- LDAP filter injection vulnerability
Upgrade now
Dependencies
Dependabot security alerts
vteamcity-mcp-v2.6.1
(1mo)
axios upgrade fixes SSRF
Security fixes
- CVE-2026-33186 — security vulnerability fixed in upgrade
- CVE-2026-1229 — security vulnerability fixed in upgrades
- CVE-2026-33747 — security vulnerability fixed in deployment upgrade
Notable features
- Upgrade Moodle to version 5.1.3
- Upgrade apphub to 0.2.7 and fix FastAPI compatibility issue
- Upgrade deployment to 2.40.0
Security fixes
- GHSA-hr2v-4r36-88hr: Chart extraction path traversal via dot-segment in Chart.yaml
Security fixes
- dep: High and critical security vulnerabilities in dependencies
Notable features
- Performance optimization: cap count queries and use native UUID operations for audit and connection logs
⚠ Upgrade required
- Release notes reference RELEASE-NOTES.md for important upgrade information from previous releases
Security fixes
- Bumped golang.org/x/crypto from 0.48.0 to 0.49.0 (cryptographic library update with potential security implications)
Security fixes
- GHSA-hr2v-4r36-88hr: Chart extraction path traversal
- GHSA-q5jf-9vfq-h4h7: Plugin verification fails open when .prov missing
- GHSA-vmx8-mqv2-9gmg: Plugin metadata path traversal
Security fixes
- Fixed SQL injection vulnerabilities in label search
v1.3.7
(2mo)
Fixed SQL injection, validated AI Copilot
Security fixes
- Dependency vulnerabilities fixed
Security fixes
- CVE-2026-33186 grpc-go mitigation
Get this as a security brief. Track Platform Engineering releases straight to your inbox.