Blog

NBUSA Patch Tuesday 2026

Monthly updates and upgrades for 2026

Monthly updates and upgrades

For 2026

September 2026

On September 1, 2026, Network Box began a phased rollout of this Patch Tuesday release through its regional Security Operations Centers. Deployment is expected to take place over 14 days.

NBRS-5

  • Introduce configuration change pre-verification so NOVA can test configurations before applying them, improving AI responses and advice.
  • Support mail recipient aliasing in the SMTP server.
  • Enhance the cluster synchronization service to improve reliability and performance, especially when Internet connectivity is poor.

NBRS-8

  • Introduce configuration change pre-verification so NOVA can test configurations before applying them, improving AI responses and advice.
  • Support mail recipient aliasing in the SMTP server.
  • Enhance the cluster synchronization service to improve reliability and performance, especially when Internet connectivity is poor.
  • Align the output of show gms faults with show gms sensors for consistency.
  • Add automatic firewall rules for WireGuard VPN servers.
  • Enhance provisioning and signature push systems.

NBSIEM+

  • Improve horizontal and vertical scrolling of attached images in web browsers.
  • Add support for downloads and exports in CSV and PDF formats.
  • Reduce the timeframe used for recently closed tickets.
  • Support more than one custom date and time range filter.
  • Enhance date filtering in the incident ticket list.
  • Add verified user attributes for email addresses and WhatsApp, LINE, and Signal accounts.
  • Disable the HTTP OPTIONS method.
  • Change the login PIN, or one-time passcode, for improved compatibility with two-factor authentication in password assistants.
  • Make assets on the map clickable.
  • Allow customer administrators to maintain their own user accounts.
  • Support the display and maintenance of owner, or customer, account records.
  • Improve the SD-WAN Overview screen’s table view.
  • Improve two-way, real-time synchronization between Box Office and NBSIEM+.
  • Update the user interface library to the latest version.
  • Bring general NBSIEM+ end-user functionality into parity with Box Office.

Most changes should not affect running services or require a device restart. Some configurations may require a restart, in which case the local SOC will coordinate the work.

August 2026

NBRS-8

  • Infrastructure migrations for signature and provisioning to support new clustered global server infrastructure. Improving speed of delivery and regional reliability.
  • Improvements to entity LDAP sync facility.
  • Renewal of package management security key.
  • Provide for automatic restart of wireguard VPN services.
  • Re-resolve wireguard vpn peer DNS names by default.

July 2026

NBRS-8

  • Introduce support for layer 2 bridged VLANs.
  • Infected LAN and Frontline IPS support for layer 2 bridged VLANs.
  • Support for multiple layer 2 bridges.
  • Enhance mid-stream season pickup in IPS module.
  • Improvements to factory reset.

June 2026

NBRS-8

  • Enhancements to NFS file systems to support resilient connections
  • Improvements to DNS SEC client support
  • Support existing session authentication credentials in direct web proxy
  • Fix for firmware package searches in administrative console
  • Improvements to networking related to re-assignment of interface IP addresses
  • Enhancement to support “no_track” default for virtual IP addresses

May 2026

NBRS-8

  • Smarter Categorisation: Improved URL and app categorisation for more accurate filtering and policy enforcement.
  • TCP MSS Clamp for ADSL: Adds TCP MSS clamp support to optimise ADSL connections and reduce fragmentation.
  • Flexible ADSL Settings: Enhanced MTU and LCP configurability for finer control over ADSL interfaces.
  • Faster Inline IPS: Performance boosts for inline IPS, especially on new multi-core hardware.
  • Robust NTLM Support: Improved NTLM authentication for more reliable access control.
  • Scalable SSL VPN: Enhanced scalability for devices managing dozens or hundreds of SSL VPN servers.
  • Enhanced SMTP SSL: Strengthened SMTP server SSL support with integration for customer certificate authorities.

April 2026

NBRS-5

NBRS-8

  • Enhanced VPN Monitoring: Back-ported improvements from NBRS-8 give clearer logging and status displays for VPN sessions.

  • Flexible Platform Selection: Choose boxes by platform (NBRS-5, NBRS-8, etc.) for easier configuration and deployment.

  • Smarter VPN Visibility: Logging and status displays now provide clearer insights into active sessions, helping admins troubleshoot faster.

  • Flexible Platform Selection: Choose boxes by platform (NBRS-5, NBRS-8, etc.) for easier configuration and deployment.

  • Stronger Threat Detection: Deploy the Proxy Infected LAN signature set to catch compromised traffic more effectively.

  • Enhanced User Access: Improved authentication streamlines the User Portal GUI login experience.

  • Granular Web Control: Multi-level URL categorisation delivers more precise filtering and policy enforcement.

  • Advanced IPS Handling: Mid-stream session pickup and asynchronous stream support enhance inline IPS performance.

  • Optimised Performance: Miscellaneous refinements to boost overall speed, stability, and reliability.

March 2026

NBRS-5

NBRS-8

  • More intelligent intrusion defence: Adds HTTP Host-based bypass control to the IDS and Active IPS modules for more precise, adaptable protection.

  • Improved visibility: User Portal reporting has been enhanced to deliver quicker, more actionable insights.

  • Enhanced sensors: Upgrades to the DNS Client GMS sensor improve both detection capability and response speed.

  • Stronger historical tracking: Configuration history reports now include a last-month view to support simpler auditing.

  • Smoother mail handling: The anti-spam engine now bypasses RBL checks for loopback and private IPs, helping reduce false positives.

  • WireGuard improvements: Expanded control over tunnel operations, including a new “service restart wireguard” command for simpler VPN administration.

  • Consistent IP handling: Primary IP assignment now correctly updates following configuration changes.

  • More robust proxies: Connection setup and teardown now handle timeouts more reliably under heavy load.

  • Stronger default security: TLS 1.3 is now enabled for cluster synchronization connections, enhancing encryption standards.

  • Enhanced mail protection: Live signature updates for mail scanning provide faster threat detection.

  • Hardened VPN security: Updated default OpenVPN cipher settings strengthen encryption.

  • Hardware-ready updates: Support added for upcoming E-1008i and 2008i appliance models.

  • Greater API capability: Added support for NBSYNC direct and cluster synchronization protocols.

February 2026

NBRS-8

  • Configuration History Fix: Resolved an issue where results were not displayed when using the “last month” date range.

  • Enhanced TLS Security: Optimised the order of SSL cipher suites for TLS 1.3 to improve both security and compatibility.

  • Smarter Spam Filtering: Updated spam checks so that real-time blackhole list (RBL) lookups are no longer performed for loopback or private IP addresses.

  • Reliable Signature Updates: Improved signature database downloads to ensure greater stability in network environments with high error rates.

January 2026

NBRS-5

NBRS-8

  • Smarter LDAP visibility: Refined query filtering display for clearer, faster insights.

  • Stronger authentication: Added support for entity dual-factor configuration to boost security resilience.

  • Deeper transparency: Enhanced logging during manual service restarts for improved traceability.

  • Streamlined interfaces: Revised display ordering for BOND and VLAN types for easier management.

  • Greater flexibility: Added support for setting MAC addresses on PPPoE links.

  • Sharper intelligence: Upgraded IP geolocation for more accurate tracking and analysis.

  • Smarter categorisation: Added URL multi-categorisation and application identification for finer policy control.

  • KIOSK mode innovation: Added directed proxy support to strengthen secure, managed browsing environments.

  • Stronger outbound safeguards: Enhanced disclaimer functionality with added support for policy acknowledgements and greylisting.

  • Clearer LDAP visibility: Improved query filtering display for faster, more accurate administration.

  • Tougher authentication: Added support for entity dual-factor configuration to reinforce access security.

  • Deeper transparency: Enhanced logging during manual service restarts for better traceability.

  • Streamlined interfaces: Revised display ordering for BOND and VLAN types to simplify management.

  • Timezone accuracy: Fixed User Portal access via Box Mail for consistent global usability.

  • Modernised encryption: Enhanced SSL cipher groups and removed obsolete ciphers for a stronger security posture.

  • Sharper DNS control: Improved logging and policy support options in the DNS client proxy.

  • Resilient SSL proxying: Improved handling of self-signed trusted CAs incorrectly placed in intermediate chains.

  • Enhanced intelligence: Upgraded IP geolocation for more precise tracking and analysis.