Tenable Patch Management 2025 Release Notes
These release notes summarize updates made to Tenable Patch Management in 2025 and are listed in reverse chronological order.
July 31, 2025

Tenable is pleased to announce the release of Tenable Patch Management 9.3.968.19, featuring major feature upgrades, new database server requirements, quality improvements, critical security, and bug fixes across the platform. Tenable strongly recommends upgrading to 9.3.968.19.
Key Release Highlights
-
Cross Platform Installation Enhancements
-
Cross platform installers now support runtime parameters instead of updating and distributing a config file, allowing installations with switches similar to the Windows installer.
-
Please refer to Tenable Patch Client Installation and Uninstallation in the official documentation for detailed instructions.
-
-
New Client Auto-Upgrade Feature
-
New auto-upgrade process has been developed to get clients up to the version of the server. This will work for all 9.3+ clients. Previous versions will need to use the old process to get clients to 9.3. The old process of auto-upgrade on Windows client will be deprecated in a future release.
-
Please refer to the Upgrade Tenable Patch Clients Using Automatic Deployments in the official documentation for detailed instructions.
-
-
Minimum Version of SQL Server Changed
-
Minimum SQL Server version has changed. SQL Server must be at least SQL Server 2017. Also, the Adaptiva database compatibility level should be 140 or higher. Tenable recommends that SQL Server 2019 or later be used with compatibility level 150 or higher.
-
Please refer to the Database Requirements and Configurations in the official documentation.
-
-
Fix for Missing DLL Causing Dell Driver Installation Failures
-
Resolves an issue where Dell drivers failed to install and Compliance Status showed "Non-Compliant" on Clients running Tenable Patch Management 9.2.XXX due to a missing DLL. The update in this release restores the required DLL, ensuring proper functionality for new installations going forward. Please note: Upgraded clients from version 9.1 or 9.0 do include this DLL and will not experience the issue.
-
-
Resolved SQL Injection Vulnerability found in Tenable Server 9.1, 9.2, and Prior Versions
-
Fixed a SQL injection vulnerability in the login process affecting versions prior to 9.2.XXX, 9.1.XXX, and prior versions. The issue was resolved by implementing parameterized queries. Therefore, Tenable strongly recommends upgrading to 9.3.968.19. See the related Tenable Security Advisory here.
-
-
Microsoft 365 Patching in Tenable Patch
-
Native Patching Support for the following versions of Microsoft Office:
-
Microsoft 365
-
Office 2024 LTS
-
Office 2024
-
Office 2021
-
Office 2019 (EOL scheduled for Oct 2025)
-
Office 2016 (EOL scheduled for Oct 2025)
-
Visio and Project, starting with version 2021
-
-
Fully integrated support for all updates that are released by Microsoft for the above products in Tenable Patch. No more manual blob generation or content packaging. Just select and deploy.
-
Delta Updates = Smaller, Smarter Patching instead of downloading full 3GB updates for each language, Tenable Patch distributes monthly delta updates (30–50 MB), reducing bandwidth usage by up to 95%.
-
Server Updates
Improvements:
-
Dynamic Logging Config: Component logging now reloads automatically when the config file is updated.
-
Optimized Bulk Messaging: Default bulk_messaging_batch size reduced from 100 to 25 to avoid dropped messages due to RVP buffer limits.
-
Secure Login Queries: User emails now passed using parameterized queries during login.
Bug Fixes:
-
Flexible ACR Input: Tenable REST client updated to accept both float and int in the ACR field.
-
Patch Submission Cleanup Bug Fix: Resolved issue where deleting a patch did not remove its submission records from associated strategies..
-
Device Status Filtering Fix: Corrected device status table to only include devices with the relevant product installed.
-
Workflow Validation Enhancement: Improved validation for file system operation nodes using runtime expressions.
-
Patch Deployment Approval Check Fix: Fixed issue where clients could deploy patches missing approvals from cycles or disabled strategies.
-
STRING_AGG Overflow Crash Fix: Resolved crash when STRING_AGG created strings exceeding 8,000 characters.
-
Business Unit and Metadata Health Display Fixes: Fixed business unit filtering in dp_per_patch__device_status and corrected dp_landing_page__patching_system_health to reflect accurate Metadata feed health above 90%.
Client Updates
-
Client Auto-Upgrade Feature in the UI
-
Manage automatic client upgrade settings
-
View current client installation information.
-
Pause / immediately deploy client upgrades.
-
-
Microsoft 365 Auto-Update Logic Update
-
Auto-updates disabled if Windows Patching is licensed and wsus.O365 = true.
-
Enables proper scan classification for Microsoft 365 products.
-
Improvements:
-
AngularJS Version Upgrade: From 19.1.3 to ^19.2.10.
-
Auto-Reload Logging Config on File Change: Automatically reload component logging configuration when the config file is modified.
-
Optimize Linux Memory Usage with jemalloc: Reduce resident memory usage on Linux clients by replacing glibc's allocator with jemalloc, which more efficiently returns unused memory to the OS.
-
Improve Filter Condition Readability: Use more intuitive operator symbols in textual representations of advanced filter conditions.
Bug Fixes:
-
SMTP Email Blocking Startup: Fixed issue where SMTP-based communication provider could block server startup due to invalid user email.
-
Patch Rescan Delay: Fixed issue where removing a patch from the block list wouldn’t immediately trigger a rescan.
-
macOS VPN Connection Failure: Fixed issue preventing macOS clients from connecting to the server over VPN.
-
Compliance State Not Updating: Fixed issue where products remained compliant after consuming new applicable patches.
-
Dashboard Menu Icon Fix (Users): Fixed header menu icon sizing and alignment on user dashboards.
-
Data Provider Switch Error: Fixed errors when changing data provider types in the editor.
-
Advanced Filter UI Constraint: Fixed issue allowing multiple child conditions under a "NOT" operator in filters.
-
Dashboard Menu Icon Fix (Patching): Fixed header menu icon sizing and alignment on patching strategy operations dashboard.
-
Folder Search Override Bug: Fixed issue where parent folder searches were overridden by field searches in object tables.
Download and Install:
Download and install the newest release here.
For more information about these updates, see the Tenable Patch Management Guide or contact your Tenable representative.
June 25, 2025

Tenable is pleased to announce the release of Tenable Patch Management 9.2.967.22, featuring minor quality improvements and bug fixes across the platform
Server Updates
Fixed:
-
Fixed issue where Business Units by Waves column in cycle tables were empty if no deployment waves exist for the cycle owner.
-
Modified the patch server framework component to depend on the feed server, preventing a race condition during registration.
-
Fixed bug where patching cycles could lose business unit information after a server restart.
-
Improved update process for supported platforms within existing workflows and activities during server upgrades.
Client Updates
Fixed:
-
Change to WUAHttpServer to include content-length header on full GET request for a file. Resolves the Window Server 2016 patch download issue.
Download and Install:
Download and install the newest release here.
For more information about these updates, see the Tenable Patch Management Guide or contact your Tenable representative.
May 29, 2025

Tenable is pleased to announce the release of Tenable Patch Management 9.2.967.21, featuring minor quality improvements and bug fixes across the platform
Server Updates
Fixed:
-
Resolved an issue where approval chains were not validated correctly in scenarios requiring more approvals than available approvers in a role.
-
Fixed a bug where business unit exports defaulted to All Clients and failed on import due to missing objects.
-
Updated logic to run client device summarization when a client is added, removed, or updated.
-
Addressed an issue where dashboard exports to Excel did not include all rows.
-
Restored the missing patching_exceptions_count field in [patch].[dp_landing_page__patching_metrics].
-
Corrected SMTP email functionality by properly storing authentication credentials.
-
Prevented configuration overrides for server content library and server temp folder paths.
Client Updates
Fixed:
-
Resolved an issue where the APT Package Dependency sensor failed due to null return codes.
-
Corrected the startup sequence for the byte-range data receiver to prevent registration failures during client initialization.
UI Updates
Fixed:
-
Addressed a bug where the patch selection state was not accurately reflected in the Applicable Patch Presentation overlay after enabling a patching strategy.
-
Fixed the multi-select checkbox behavior in table headers and footers to correctly reflect indeterminate "select-all" states.
-
Prevented saving of workflows with empty target platforms when the Select All checkbox is unchecked.
Removed:
-
Removed the Select All menu item from table header menus.
-
This menu item only selected rows that were visible on the current page, which was not clear.
-
This behavior is also redundant to the checkbox in the table header and footer.
Download and Install:
Download and install the newest release here.
For more information about these updates, see the Tenable Patch Management Guide or contact your Tenable representative.
May 15, 2025

Tenable is pleased to announce the release of Tenable Patch Management 9.2.967.20.
This release includes support for additional operating systems, critical bug fixes, performance enhancements, and improvements across the platform.
Highlights:
-
New OS support for Red Hat Enterprise Linux, namely, RHEL 8 and RHEL 9.
-
Stability and upgrade-related bug fixes.
-
Updated Java Runtime and core libraries for improved performance.
Common Updates:
Changed
-
Added support for Red Hat Enterprise Linux (RHEL 8 and RHEL 9) for on-premises Tenable Patch Management deployments.
-
Upgraded Java 17 JRE to version 17.0.15.
-
Updated Apache POI library to version 5.4.0.
Server Updates:
Changed
-
Restored WhatsApp Support:
-
Modified WhatsApp notifications to use Meta-approved templates.
-
Background: Meta platform changes disrupted WhatsApp notifications via Twilio/SendGrid.
-
-
Updated Patch Notification Bots behavior:
-
Bots can no longer mix WhatsApp Communication Provider with other providers.
-
Action Required: Review and modify any custom Patch Notification Bots using WhatsApp.
-
-
Improved SQL Express installation:
-
Adjusted download method to avoid issues with Internet Explorer Enhanced Security Configuration (ESC).
-
Fixed
-
Resolved issue preventing newly created business workflows from opening.
-
Fixed server performance degradation caused by excessive group evaluations during client additions.
-
Addressed upgrade failure during Business Unit migration.
-
Resolved issue where RHEL clients did not appear in RHEL 8 and RHEL 9 Business Units.
-
Fixed server startup issue due to improperly formatted Tenable Security Center URIs.
-
Corrected issue where clients were not added to Windows Business Unit when reporting Windows build number.
Client Updates:
Fixed
-
Resolved version comparison issues on pkg-based and rpm-based Linux distributions.
-
Fixed requirement for /qn switch on MSI-based patch installations.
UI Updates:
Changed
-
Updated the Patch Notification Bot editor:
-
UI now restricts combining WhatsApp with other Communication Providers.
-
Output Expression field is hidden when WhatsApp is selected.
-
Fixed
-
Resolved issue with the Rank widget on the User Dashboard not displaying expected results.
Download and Install:
Download and install the newest release here.
For more information about these updates, see the Tenable Patch Management Guide or contact your Tenable representative.
April 10, 2025

Tenable is pleased to announce the release of Tenable Patch Management 9.2.967.18.
This release contains the following updates:
Server Updates
-
Fixed issues with custom product sensor actions, export/import of business units, and PatchStatusQuery processing.
-
Updated built-in and non-built-in sensors/actions with platform info.
Client Updates
-
Deprecated SHA256Hash output from FileDetails sensor for better performance.
For more information about these updates, see the Tenable Patch Management Guide or contact your Tenable representative.
April 8, 2025

Tenable is pleased to announce the release of Tenable Patch Management 9.2.967.17.
This release contains the following updates:
Server Updates
-
Added
-
Removed orphaned rows during upgrade and added prevention.
-
Support for validating Tenable access settings and configuring asset & CVE update intervals.
-
-
Fixed
-
Issue with child business units not inheriting settings.
-
Performance improvements for large Client Table ID lists.
-
Index-out-of-bounds error in trigger property routing.
-
Client Updates
-
Changed
-
Increased buffer space allocation (higher than previous heap size).
-
Reduced server activation check interval from 24 to 4 hours.
-
-
Fixed
-
Fixed CAB scan failure crash.
-
Corrected issues with Linux package version comparison and scan detection in non-English locales.
-
Fixed reboot reminder notifications after sleep.
-
Corrected cycle compliance calculation and patch status consideration.
-
Fixed index issue with ClientFeedInstalled.
-
-
Removed
-
Removed gsettings dependency for Linux system proxy retrieval.
-
UI Updates
-
Changed
-
Disabled rename option for built-in folders.
-
-
Fixed
-
Fixed sorting issues with Approval Requests and Blocked Patches.
-
Resolved issues with checkbox groups, "Save and Deploy" behavior, and UI menu items.
-
Fixed Workflow Designer issues with copy/paste, dynamic node properties, and node renaming.
-
For more information about these updates, see the Tenable Patch Management Guide or contact your Tenable representative.
March 21, 2025

Tenable is pleased to announce the release of Tenable Patch Management 9.2.967, which adds macOS and Linux support, along with Mozilla Firefox compatibility.
This release contains the following updates:
-
Cross-platform support — You can now install Tenable Patch Management on macOS Ventura and later, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, CentOS Stream 9, CentOS Stream 10, Debian 11, and Debian 12.
-
Mozilla Firefox support — Tenable Patch Management is now compatible with Mozilla Firefox.
-
Patching Strategy enhancements — You can now delete, submit, or resubmit patches without first disabling their Patching Strategy.
For more information about these updates, see the Tenable Patch Management Guide or contact your Tenable representative.