In this article
About this release
On August 31, 2026, we released version 4.2.13 of Segura® Platform. This release includes 38 changes across 12 modules.
- Release date: 2026-08-31
- Patch: segura | v4.2.13-1
For information on how to update Segura® Platform, see Update Segura®.
Changelog
API
Added
| Item |
Description |
| SSGR-10034 |
Added an SSH keys resource to the PAM Core API v2, with endpoints to list, read, activate, deactivate, check in, and rotate SSH keys. |
| SSGR-10035 |
Added API v2 endpoints to activate, deactivate, and check in credentials in PAM Core, where check-in releases the custody currently held over the credential. |
| SSGR-10044 |
Added API v2 endpoints to list remote sessions and retrieve the details of a single session in PAM Core. |
| SSGR-11590 |
Added an API v2 endpoint to rotate a credential password on demand, which returns a job reference the caller can poll, cancel, or retry. |
| SSGR-11591 |
Added an API v2 endpoint that returns the audit trail of a credential, covering accesses, rotations, custody releases, and configuration changes, including denied attempts. |
Approval Workflow
Fixed
| Item |
Description |
| SSGR-11422 |
Fixed an issue in the scheduling of session requests. |
Authentication
Fixed
| Item |
Description |
| SSGR-11414 |
Fixed an issue where web sessions ended before the configured session timeout. |
| SSGR-11803 |
Fixed an issue where, after Active Directory synchronization, users belonging to more than one AD group that granted the same Segura access group would lose access to their credentials. |
Certificate Manager
Changed
| Item |
Description |
| SSGR-8455 |
Improved the visibility of the publishing reports. The report now includes plugin and profile columns, the Status column shows clearer statuses, and new filters have been added. See the documentation: - Publishing status. - Publishing profiles. |
Fixed
| Item |
Description |
| SSGR-11383 |
Fixed an error when publishing a wildcard certificate through the Netscaler plugin due to file naming restrictions. Wildcard certificates containing special characters in the name are now published correctly. |
| SSGR-11660 |
Fixed an issue where importing a valid, externally generated CSR would incorrectly display a network error. |
EPM Admin Web Interface
Fixed
| Item |
Description |
| SSGR-11324 |
Fixed an issue in the application access policy form. |
| SSGR-11925 |
Fixed an issue where new users provisioned in PAM through automatic LDAP synchronization were not being linked to the access policies required for EPM usage, resulting in access unavailability for new users. |
EPM Windows
Added
| Item |
Description |
| SSGR-9833 |
Application Scan for Windows no longer includes native Windows applications in the Applications, Application usage, and Scan Statistics screens. See the documentation: About Application Scan. |
Fixed
| Item |
Description |
| SSGR-8854 |
Fixed an issue that prevented local users from signing in when Enable multifactor authentication at login? was enabled. |
| SSGR-11575 |
Fixed an issue that prevented some users from elevating applications. |
| SSGR-11936 |
Fixed an issue in the way automatic elevation was applied on managed workstations. |
Executions
Fixed
| Item |
Description |
| SSGR-10116 |
Fixed an issue in the Content field when editing a template that uses the Ansible executor. |
| SSGR-11705 |
Fixed an issue where, when performing a password change in an Aruba switch using Selenium templates on devices via Network Connector, a connection error was displayed and the password change was not performed. |
| SSGR-11982 |
Fixed an issue where the krb5-user package was not being installed via the orbit update command, causing a failure when attempting to perform password rotation via LDAPS with Kerberos authentication. |
Framework
Changed
| Item |
Description |
| SSGR-11162 |
Improved SCIM provisioning with Azure Entra ID so that users receive roles inherited from groups automatically, once the Microsoft Graph credential is configured on the Segura application. See the documentation: How to set up Azure AD identity provisioning. |
Fixed
| Item |
Description |
| SSGR-10674 |
Fixed an issue in the provider selection for individual users. |
| SSGR-11000 |
Fixed an issue where a valid self-signed certificate could not be installed in the application. |
| SSGR-11161 |
Fixed an issue where the email sent to a newly created user arrived in Portuguese when the application's default language was neither Portuguese nor English. It is now sent in English. |
| SSGR-11388 |
Fixed an issue where the User group field on the LDAP/AD group configuration screens was not filtering the groups shown in the report. |
| SSGR-11468 |
Fixed an issue where Private SaaS environments received infrastructure alerts from Orbit that did not apply to them. |
| SSGR-11681 |
Removed the disk space, CPU, and memory usage global notifications from SaaS and Private SaaS environments. |
| SSGR-11800 |
Fixed an issue in the information shown on the Application activation screen. |
MySafe
Fixed
| Item |
Description |
| SSGR-9902 |
Fixed an issue in the response returned by the MySafe API for password update requests. |
Orbit
Fixed
| Item |
Description |
| SSGR-11465 |
Fixed an issue in the syslog output. |
| SSGR-11706 |
Fixed an issue where Orbit Server Manager kept showing the pending tuning alert after the suggested values were applied successfully. |
PAM Core
Changed
| Item |
Description |
| SSGR-11835 |
Added a Connection Broker option to RemoteApp registration, so RemoteApps can be published in environments that route RDP sessions through a Remote Desktop Connection Broker. See the documentation: How to register a RemoteApp. |
Fixed
| Item |
Description |
| SSGR-11194 |
Fixed an issue in the records created by the Forget User action. |
| SSGR-11427 |
Fixed an issue in the Audit tracking report. |
| SSGR-11585 |
Fixed an issue where the Home showed connectivity options that did not apply to Linux devices when starting a session. |
| SSGR-11721 |
Fixed an issue where HTTP web sessions (VNCHTTP) were displayed zoomed out on macOS clients. |
| SSGR-11746 |
Fixed an issue where privilege elevation in EPM was denied to users whose access policy allowed it. |
Proxy
Fixed
| Item |
Description |
| SSGR-11573 |
Fixed an issue where SUDO automation did not complete privilege elevation in SSH sessions. |