Fixed issues
UniconOS Management 2607 (formerly Scout 15)
Release date 2026-08-07
Fixed issues
- After upgrading to 26.05, devices no longer retained locally-changed unlocked settings — Scout re-pushed the complete, all-locked configuration on every device contact, overwriting any locally changed unlocked setting on each boot [SC-2270]
- Concurrent OU/Group creation intermittently failed with a n error. [SC-2225]
- Application icon uploads had no maximum file-size limit. [SBD-2126]
- The License Info widget’s entitlement expiry reflected the monthly-shifting activation-lease expiry instead of the real Citrix License Server contract end date. [SC-2347]
- The external REST API fileEntries DELETE returned HTTP 500. [SBD-2047]
- Clicking the Help (?) icon on the Manager Administrator page opened a documentation URL that no longer existed and returned a 404. [SBD-2021]
- On the Application → Icons page, failed uploads showed no error, icon names were not shown in the table, and the table was not scrollable at page size 40. [SBD-2037]
- Deleted OUs persisted in the “Recently viewed” section. [SBD-2035]
- With “Encrypt data transmission” enabled in Device configuration → Mirroring, a mirroring session could not be established, although the legacy Scout Console session still worked. [SBD-2180#]
- Several keys were missing in the Compare configuration view, so some fields did not display their translated text. [SBD-2019]
- Importing an OU that was exported with its own device/advanced config failed. [SBD-2127]
- During OU configuration import, the target ID resolved to undefined. [SBD-2125]
- The external GET /ou/device/status?path= endpoint returned HTTP 400. [SBD-2099]
- All four base-application REST endpoints returned HTTP 500. [SBD-2039]
- A bodyless DELETE of an advanced-config file entry (base/device/ou) via the public REST API crashed with HTTP 500. [SBD-2133]
- Several public REST device/OU handlers sent the HTTP response twice on a failed lookup [SBD-2142]
- On POST /configuration/{base,ou,device}/diagnostics returned HTTP 500. [SBD-2141]
- GET /config/advanced/base/{wol,update,rules} returned HTTP 500 . [SBD-2135]
- GET /configuration/base/mirror and /configuration/base/firmware returned HTTP 500. [SBD-2040]
- On the public REST API, PUT /labels/{id} and POST /rules/{id}/labels returned HTTP 500. [SBD-2140]
- POST notification/{ou,ddg}/devicerelocation returned HTTP 500. [SBD-2138]
- An application delivered via a rule/label was dropped whenever the rule matched on a client-reported device attribute (e.g. ELUX_HOSTNAME, subnet), so newly added rule/label icons appeared. [SC-2293]
- Entering Edit mode on a device configuration sporadically failed with a false “Someone else has this object in edit mode,”on the user’s own OU with no other editor. [SBD-2041]
- In System Settings → Scout Instances, the “Add Instance / Add Load Balancer” button was missing because the live table stopped importing the toolbar that renders it, leaving no way to register a new instance or load balancer from the UI. [SBD-2045]
- In a Scout Board mirroring session, the “Configure Remote session” button did nothing when clicked. [SBD-2169]
- Downloading a device diagnostic bundle or a Scout server-log file ≥ ~536 MB crashed the ScoutBoardDBLayer service. [SBD-2149]
- The search/filter field in the Configuration Rules and Labels overviews lost input focus after every keystroke, forcing the user to click back into the field for each additional character. [SBD-2166#]
- When installing the newest Scout/ScoutBoard version, the OIDC auth-type page was not scrollable, so the user could not see or enter all the fields needed to proceed. [SBD-2031]
- The latest published StickWizz.exe triggered a certificate-expiration warning on execution. [SC-2242]
- In UniconOS Device Configuration → Security → User rights, locking features under Security while leaving Info fields unlocked made the device’s info 1–3 fields non-editable. [SC-2211]
Security
- SQL injection fixes [SBD-2024, SC-2312, SC-2204, SC-2227]
- LDAP/LDAPS TLS certificate validation is now enforced in the auth/admin helpers [SBD-1989]
- Weak unsalted double-SHA-256 device root-password verification replaced with a stronger scheme. [SBD-2026]
- Over-permissive CORS on the Scout Board API tightened. [SBD-2067]
- Device/OU config REST routes evaluate the correct target-scope permission (CWE-863). [SBD-2132]
- Server-Side Request Forgery (CWE-918) in Scout Server. [SC-2093]
UniconOS 2607 (formerly eLux 7)
Release date 2026-08-07
Fixed issues
- Monitor layout and primary monitor settings were not retained after reboot. [ELUX-7373]
- Application windows moved unexpectedly when the monitor configuration changed. [ELUX-6552]
- The screen of a mobile device went blank when an external monitor was rotated. [ELUX-6696]
- External displays were disconnected when the laptop lid was closed while docked. [ELUX-6228]
- DisplayPort outputs were incorrectly labeled as HDMI in Quick System Access output settings. [ELUX-5798]
- Desktop icons disappeared when the system bar was hidden after repeated clicks. [ELUX-5578]
- The UniconOS desktop displayed an empty application list after login. [ELUX-6254]
- The Start menu appeared empty in rare scenarios after launching specific applications. [ELUX-6070]
- Icons could be dragged out of the Start menu. [ELUX-6382]
- Quick System Access closed when multimedia keys were pressed. [ELUX-5057]
- The taskbar froze while applications remained responsive. [ELUX-6888]
- The taskbar displayed an incorrect icon for the local Zoom client. [ELUX-6376]
- The “Forgot your password” option displayed an unclear message on the Imprivata login screen instead of a user-friendly notification. [ELUX-6517]
- Inserting a second card during a SmartCard pause ended the pause and triggered a logoff. [ELUX-6546]
- Smart card insert and removal actions stopped working after repeated card cycles on UniconOS 2601. [ELUX-6194]
- The device information hotkey could be used from the AD logon dialog. [ELUX-5601]
- OIDC login displayed unclear status notifications. [ELUX-4159]
- The PureAuth login screen overlay blocked the “Sign In” button until the dialog was closed. [ELUX-6308]
- Citrix Workspace App for Linux configured as a Service App failed to launch. [ELUX-4980]
- Built-in browser native launch on StoreFront 2507 displayed the “Detect Citrix Workspace app” page for every session. [ELUX-6990]
- ICA and RDP files did not automatically open in all browsers. [ELUX-5131]
- Firefox language and proxy settings were not applied after migration from eLux RP 6 to UniconOS. [ELUX-6928]
- Monitor layout was not retained after migrating from RP 6 to UniconOS on Dell OptiPlex 7020. [ELUX-5268]
- Applications could not be launched after resuming from sleep. [ELUX-5840]
- Citrix SelfService was intermittently disrupted when the monitor layout was changed. [ELUX-6718]
- Japanese input did not work in launched applications (e.g. Chrome) when the desktop language was Japanese. [ELUX-6764]
- Japanese text was truncated or clipped in the Start menu and Quick System Access panels. [ELUX-6786]
- The Teams timezone was not updated after the UniconOS timezone was changed. [ELUX-6481]
- A Magic Mouse center press was incorrectly interpreted as a middle-click, causing Chrome tabs to close. [ELUX-6910]
- Power Management profile selection under User Rights was incorrect. [ELUX-6630]
- The 802.1X UI failure notification parameter was not written to terminal.ini when configured in Scout Board. [ELUX-5486]
- Devices failed to onboard correctly to the endpoint management system, and the UniconOS system bar was not displayed. [ELUX-6121]
- Local updates could not be started while the device was running on battery power. [ELUX-6451]
- UniconOS entered a boot loop when the EST configuration contained an incorrect password. [ELUX-6703]
- An image update failed on HP t640, causing a status mismatch between Scout Board and update logs. [ELUX-5266]
- The SCG health probe generated excessive Scout handshake traffic by using a full TLS manager connection for liveness checks. [ELUX-6603]
- The USB printer was not set as the default printer at first boot. [ELUX-6597]
- Bluetooth devices lost their connection and required re-pairing to function again. [ELUX-5964]
- Cisco 322 MS headset call controls did not function with the Cisco Jabber VDI plugin. [ELUX-6695]
- The local audio device was disabled after an extended idle period, although audio continued to function within the Citrix session. [ELUX-5970]
- Lenovo E14 Gen 7 became unresponsive after locking. [ELUX-6251]
- Signature processing on StepOver sign pads was delayed. [ELUX-6245]
- The screensaver ignored the configured delay and activated after one minute while the device was locked. [ELUX-6347]
- The screensaver was triggered during Zoom meetings. [ELUX-6234]
- WPA Supplicant did not start when IEEE 802.1X was enabled. [ELUX-6715]
- Split DNS intermittently failed after multiple consecutive updates. [ELUX-6807]
Security
- Upgraded Linux kernel to version 6.18.38. [ELUX-6249]
- Security updates for alsa due to the critical vulnerability CVE-2026-25068. [ELUX-5600]
- Security updates for GStreamer due to the critical vulnerability CVE-2023-50186. [ELUX-4203]
- Security updates for libsoup3 due to the critical vulnerabilities CVE-2026-1467, CVE-2026-1536, and CVE-2026-1539. [ELUX-6230]
- Security updates for openjpeg due to the critical vulnerability CVE-2026-6192. [ELUX-6229]
- Security updates for xorg due to the critical vulnerabilities CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, and CVE-2025-26601. [ELUX-3669]
- Resolved an issue where an editable home directory shared between users allowed one user to run arbitrary commands as another. [ELUX-5304]
- Raised the NetworkAccessControl default RSA key length to 4096 bits. [ELUX-6215]
- Added HTTPS support for SCEP enrollment. [ELUX-6129]
- Security updates for Firefox ESR due to the critical vulnerabilities CVE-2026-5731–5732, CVE-2026-5734, CVE-2026-6746–6754, CVE-2026-6757, CVE-2026-6759, CVE-2026-6761–6767, CVE-2026-6769–6772, CVE-2026-6776, CVE-2026-6785–6786, CVE-2026-7320–7323, CVE-2026-8090–8092, CVE-2026-8094, CVE-2026-8388, CVE-2026-8391, CVE-2026-8401, CVE-2026-8946–8947, CVE-2026-8949–8950, CVE-2026-8953–8959, CVE-2026-8961–8962, CVE-2026-8968, CVE-2026-8970, CVE-2026-8974–8975, CVE-2026-12289–12292, CVE-2026-12294–12299, CVE-2026-12302, CVE-2026-12304–12315, CVE-2026-12324–12325, CVE-2026-12327–12330 [ELUX-6589]
- Security updates for base OS due to the critical vulnerabilities CVE-2017-9814, CVE-2019-6461, CVE-2019-6462, CVE-2023-52890, CVE-2025-0167, CVE-2025-7519, CVE-2025-61143, CVE-2025-61144, CVE-2026-1965, CVE-2026-3731, CVE-2026-3783, CVE-2026-3784, CVE-2026-3832, CVE-2026-3833, CVE-2026-4873, CVE-2026-4878, CVE-2026-4897, CVE-2026-5260, CVE-2026-5545, CVE-2026-5773, CVE-2026-6192, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-7168, CVE-2026-27135, CVE-2026-28387–28390, CVE-2026-29111, CVE-2026-31431, CVE-2026-31789, CVE-2026-31790, CVE-2026-33416, CVE-2026-33636, CVE-2026-33845, CVE-2026-33846, CVE-2026-34757, CVE-2026-35058, CVE-2026-40215, CVE-2026-40706, CVE-2026-41989, CVE-2026-42009–42015 [ELUX-5612]
- Security updates for PXE recovery due to the critical vulnerabilities CVE-2017-9814, CVE-2019-6461, CVE-2019-6462, CVE-2025-0167, CVE-2026-1965, CVE-2026-3731, CVE-2026-3783, CVE-2026-3784, CVE-2026-3832, CVE-2026-3833, CVE-2026-4873, CVE-2026-4878, CVE-2026-5260, CVE-2026-5545, CVE-2026-5773, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-7168, CVE-2026-27135, CVE-2026-28387–28390, CVE-2026-29111, CVE-2026-31431, CVE-2026-31789, CVE-2026-31790, CVE-2026-33416, CVE-2026-33636, CVE-2026-33845, CVE-2026-33846, CVE-2026-34757, CVE-2026-41989, CVE-2026-42009–42015 [ELUX-5612]
- Security updates for system libraries due to the critical vulnerabilities CVE-2025-5918, CVE-2025-60753, CVE-2026-4111, CVE-2026-4424, CVE-2026-4426, CVE-2026-5121, CVE-2026-6192, CVE-2026-24401, CVE-2026-34933, CVE-2026-42046 [ELUX-5612]
- Security updates for base printer due to the critical vulnerabilities CVE-2026-24401, CVE-2026-34933 [ELUX-5612]
- Security updates for desktop environment due to the critical vulnerabilities CVE-2017-9814, CVE-2019-6461, CVE-2019-6462, CVE-2025-5918, CVE-2025-60753, CVE-2026-2340, CVE-2026-2921, CVE-2026-3012, CVE-2026-3238, CVE-2026-4111, CVE-2026-4408, CVE-2026-4424, CVE-2026-4426, CVE-2026-4480, CVE-2026-5121, CVE-2026-5201, CVE-2026-28295, CVE-2026-28296, CVE-2026-34080, CVE-2026-41254, CVE-2026-46529 [ELUX-5612]
- Security updates for eLux desktop due to the critical vulnerabilities CVE-2026-46529 [ELUX-5612]
- Security updates for GStreamer due to the critical vulnerabilities CVE-2026-464, CVE-2026-2921, CVE-2026-3083, CVE-2026-3085, CVE-2026-46469, CVE-2026-46470 [ELUX-5612]
- Security updates for PulseAudio due to the critical vulnerabilities CVE-2026-2921 [ELUX-5612]
- Security updates for Firefox (jq) due to the critical vulnerabilities CVE-2026-32316, CVE-2026-33947, CVE-2026-33948, CVE-2026-39956, CVE-2026-39979, CVE-2026-40164 [ELUX-5612]
- Security updates for devel tools due to the critical vulnerabilities CVE-2025-10158, CVE-2026-25749, CVE-2026-26269, CVE-2026-28417–28422, CVE-2026-29518, CVE-2026-33412, CVE-2026-34982, CVE-2026-39881, CVE-2026-41035, CVE-2026-41411, CVE-2026-42307, CVE-2026-43617–43620, CVE-2026-44656, CVE-2026-45130, CVE-2026-45232 [ELUX-5612]
- Security updates for SSH client due to the critical vulnerabilities CVE-2025-61984, CVE-2025-61985, CVE-2026-3497, CVE-2026-35385–35388, CVE-2026-35414 [ELUX-5612]
- Security updates for SSH server due to the critical vulnerabilities CVE-2025-61984, CVE-2025-61985, CVE-2026-3497, CVE-2026-35385–35388, CVE-2026-35414 [ELUX-5612]
- Security updates for video libraries due to the critical vulnerabilities CVE-2026-3731 [ELUX-5612]
- Security updates for Squid due to the critical vulnerabilities CVE-2026-32748, CVE-2026-33515, CVE-2026-33526 [ELUX-5612]
- Security updates for Fujitsu MAPT due to the critical vulnerabilities CVE-2026-25749, CVE-2026-26269, CVE-2026-28417–28422, CVE-2026-33412, CVE-2026-34982, CVE-2026-39881, CVE-2026-41411, CVE-2026-42307, CVE-2026-44656, CVE-2026-45130 [ELUX-5612]
- Security updates for QEMU Guest Agent due to the critical vulnerabilities CVE-2024-6519, CVE-2026-2243 [ELUX-5612]
- Security updates for Python3 due to the critical vulnerabilities CVE-2017-9814, CVE-2019-6461, CVE-2019-6462 [ELUX-5612]
Fixed issues
Copied!
Failed!