DocumentationAPI ReferenceRelease Notes
Release Notes

BT Updater Client 3.6.0 release notes

🆕 New features

Product areaDescriptionResolution
SubscriptionsBT Updater had no subscription for the .NET 10 Hosting Bundle, so the runtime had to be installed and kept up to date outside the Updater.A .NET 10 Hosting Bundle subscription is now available. BT Updater delivers and installs the bundle, and the subscription registers itself, so no manual setup is required.

✨ Enhancements

Product areaDescriptionResolution
Activity FeedWhen the Updater server cancelled a download, the activity feed ended without explaining why.The activity feed now shows the reason the server cancelled a download.
ConfigurationA successful Test Connection confirmed only that the connection succeeded.A successful Test Connection now also reports the version of the Updater server you connected to.
DownloadsThe client retried a download on its own schedule, ignoring any wait requested by the server.The client now honors a server-requested wait before it retries a download.
Web ConsoleThe web console ran on an out-of-date version of its UI framework.The web console has been upgraded to a current supported version of its UI framework.

🔒 Security improvements

Product areaDescriptionResolution
AuthenticationStored credentials were protected with hardcoded encryption keys, and the credential database was protected by a legacy password.The hardcoded keys and the legacy password have been removed, strengthening protection for stored credentials.
DownloadsCertificate validation was disabled for connections to the download server, and the validation callback accepted any certificate.Certificate validation is enforced, and the callback now fails closed instead of accepting any certificate.
DownloadsSSL 3.0 and TLS 1.0/1.1 were explicitly enabled for outbound connections.Legacy protocols are no longer enabled. The Updater now uses the modern TLS version negotiated by the operating system.
GeneralBundled third-party components included versions with published vulnerabilities.Third-party components, including log4net and the web console's npm packages, have been updated.
LoggingPasswords and anti-CSRF tokens were written to application log files, and a debug-level log file was written unconditionally to the working directory.Sensitive values are no longer written to log files, and the unconditional debug log file has been removed.
PackagesPackage extraction did not validate entry paths, so an archive entry could be written outside the target folder.Update packages, web policy and plugin packages, and offline package imports now reject any entry that resolves outside the target folder.
Web ConsoleSigning out could act on the wrong session, issued tokens carried administrative rights unconditionally, and token renewal accepted a client-supplied user identity.Session and token handling have been hardened on all three paths.
Web ConsoleThe support package download endpoint and a set of legacy HTTP handlers were reachable without authentication, and the support package could expose the credential database and log files.These endpoints have been removed or now require authentication.
Web ConsoleThe web console did not send the X-Frame-Options header.The web console now sends the X-Frame-Options header, adding clickjacking protection.

🛠️ Issues resolved

Product areaDescriptionResolution
LicensingWhen more than one license was issued for a serial number, the daily license refresh failed and the local license database was not updated.The license refresh now saves multiple licenses for a single serial number correctly.

📝 Requirements

  • .NET 4.7.2 or later
  • IIS to be enabled on host

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.