Product Announcements

Forum Discussion

bisaacs's avatar
bisaacs
Product Team
1 day ago

The Tenable Patch Management July Release is live

Tenable Patch Management (v10.2.973.9) is now available for both SaaS and On-Premise environments. This release introduces real-time post-deployment rescan automation, broadening enterprise Linux package support, and hardening platform security. 

Here is a breakdown of key enhancements and updates included in this release.

1. Post-patch Nessus Agent scan triggers

  • What’s new: Patch deployments can now automatically trigger a Nessus Agent scan the moment installation completes. This relies on a localized trigger file managed by the client.
  • Why it matters: You do not have to wait for your next scheduled vulnerability scan window to verify that a patch took effect. The agent initiates a scan immediately, providing prompt confirmation that a CVE is remediated.
  • Use case: Once a patching process completes on a client, the system creates or updates a specific file (default is patch_trigger), which prompts the Nessus Agent to initiate a Nessus agent scan.

2. Expanded fleet coverage and OS support

  • What’s new: Added native support for Extra Packages for Enterprise Linux (EPEL) across supported Linux distributions, including RHEL, CentOS Stream, AlmaLinux, and Rocky Linux.
  • Why this matters: You can patch community-maintained add-on software using standard patching workflows without writing custom repository scripts or manually handling updates.
  • Use case: Admin utilities, extra developer libraries, and secondary tools pulled from EPEL stay updated on the same schedule as core operating system components. 

3. Critical security & platform hardening

  • What’s new: Default platform encryption is updated from AES-CBC to AES-GCM. Administrators can also provision additional trusted TLS certificates to clients directly from the management server. 
  • Why this matters: AES-CBC without message integrity checks leaves communications open to cipher-mode attacks. Moving to AES-GCM eliminates this vulnerability, while server-side TLS provisioning simplifies client trust updates.
  • Use case: Meet strict enterprise cryptographic auditing requirements while seamlessly rotating endpoint TLS certificates directly from the management console.

4. Performance enhancements and bug fixes

  • Schedule Editor Accuracy: Resolved a defect where setting the "Week of the Month" to 4 would automatically enable the "Last Week of the Month" toggle, preventing unintentional schedule overlaps.
  • Deployment & Delay Logic: Corrected an issue where Delay Deployment routines fired prematurely following a server upgrade outside of defined maintenance windows.
  • Deployment Request Errors: Resolved "Unable to queue deployment request patch" errors causing widespread installation failures.
  • Maintenance Window Integrity: Fixed a defect where legacy Express license attributes persisted post-upgrade, causing unwanted reboots during maintenance hours.
  • Dashboard Acceleration: Updated the underlying database schema to accelerate load times on the Device - CVE Detections dashboard.
  • Integration Reliability: Resolved 502 Bad Gateway errors on the Tenable Vulnerability Management integration page by improving data request handling and session ID generation.
  • Client Queue & Connectivity Fixes: Resolved "Unable to queue deployment request" errors during patch execution, added clearer REST API error messages for permission issues, and resolved Tailscale IP binding issues during client scans
  • Client Installer Authenticity: Resolved an issue where the Windows Client MSI showed an "Unknown Publisher" warning in Microsoft Defender SmartScreen due to an invalid digital signature.
  • Customized Products Bug: Resolved an issue where Duo Authentication for Windows Logon x64 configuration parameters (such as Enable UAC Elevation Protection) were missing in the Customized Products section.

Upgrade instructions

  • SaaS / Cloud deployments: No manual action is required. Your product is updated to version v10.2.973.9 automatically.
  • On-premise deployments: Server admins can download the latest installer from the Tenable Downloads Portal.

Resources

Have feedback or deployment questions? 

Reach out to your Tenable representative, or start a thread right here in Connect!

No RepliesBe the first to reply