Released July 27, 2026
Updates
Security
Applied a mitigation for CVE-2026-46333, an SSH key-signing vulnerability affecting Linux systems (“ssh-keysign-pwn”). No customer action is required beyond upgrading to this release.
Name resolving
Fixed a Google Cloud Platform resolver variable substitution issue during cache refresh.
Portal
Addressed an issue where the Portal went into a redirect loop under certain circumstances.
Stability
Addressed an issue in which Collectives under a heavy load struggled to scale beyond seven Controllers.
Fixed an issue where the session info API could return duplicate subnet entries within firewall rule details.
Fixed an issue where client sessions could remain marked as active on the Gateway after an internal communication failure between backend services, which could result in inaccurate active session counts. Affected sessions are now cleaned up once the underlying condition is detected.