2026.x Feature Release Change Log
The content of this user guide is based on the current release: 2026.2.5
Asset Manager topics are related to GA 5.7 released May 14, 2026.
This version is a Feature Release.
The Feature Release supports ongoing feature development within an Enterprise Release. Its aim is to introduce new features aligned with the Enterprise Release over time. It integrates new features, hardware support, and bug fixes. Multiple Feature Releases occur within each Enterprise Release, functioning as a container for Maintenance Releases (e.g., 2026.2).
Feature Releases occur monthly and include the latest maintenance release along with any newly added features.
More detailed information about FireMon's release process can be found here: FMOS Release Process
Below are listed any changes to topics as a result of the monthly Feature release.
|
2026.2.5
july 31, 2026
|
-
Improved Azure NVA Discovery: The system now automatically identifies deconstructed Azure virtual machines (VMs) that function as Network Virtual Appliances (NVAs) and represents them as a single device, preventing duplicate VM assets. If a detected NVA does not already exist in the system, it is automatically created when a matching device mapping is configured in the Administration module.
-
Azure Subscription Device View: Added a Devices page under the Overview navigation menu for Azure subscriptions. This page displays all child devices associated with the Azure subscription in Security Manager.
-
Enhanced Revision Filtering: Added Device Type, Device Name, and Parent Device Name filters to Change > Revisions at the domain and device group levels, making it easier to locate specific revision records.
-
Enhanced Device Type Filtering: Added an Exclude option to the Type filter in device lists at the domain and device group levels, allowing you to exclude selected device types from the results.
-
Improved Check Point GAIA Gateway Retrieval Efficiency: Enhanced change detection for Check Point GAIA gateways to reduce unnecessary back-to-back retrievals. The system now consolidates duplicate gateway change notifications by introducing a short delay before initiating retrieval, minimizing redundant retrieval operations while ensuring local policy changes are detected.
-
Frontend Component Standardization: Updated frontend components across the application by standardizing on common UI frameworks. These updates provide a more consistent user experience, improved UI behavior, and a stronger foundation for future enhancements.
|
|
2026.2.4
June 26, 2026
|
-
Device: Palo Alto Strata Cloud Manager support for levels 1-3
Palo Alto Strata Cloud Manager
-
Device: Azure Cloud Nine:
-
Azure Express Route Gateway implements discovery, retrieval, normalization and behavior of Azure ExpressRoute Circuits and Azure ExpressRoute Gateways. Now APA can traverse from cloud to on-prem and vice-versa via Azure ExpressRoutes. This functionality requires the new deconstructed Azure subscription provider device pack.
-
Azure Native Firewall implements discovery, retrieval, normalization and behavior for Azure native firewalls. Azure native firewall can now participate in APA. This functionality requires the new deconstructed Azure subscription provider device pack.
-
Compliance and Assessment & Control Report: Added pass/fail result indicators to the Compliance and Assessment and Controls Report CSV exports. Includes Pass, Fail, Info, Skip, and Error statuses for reported controls and devices.
-
Policy Planner - Bulk Object Removal in Rule Create and Modify: Added bulk object removal capabilities to create and modify rule modals in Policy Planner. Remove all objects from a field with a single action, rather than individually removing each object.
-
Workbench - Manual Change Actions for Rule Recommendation Errors: Added action menu to the Rule Recommendation Errors table. Initiate a manual change directly from an error table - allows user to continue designing changes when a recommendation cannot be generated.
-
FMOS - Support Incremental System Backup: Incremental system backups provide considerable storage savings over standard (full) backups in that differential backups will only contain files that have changed since the last primary backup. Schedule an Automatic Backup
The following updates have been made:
-
Primary backup – similar to our current backup
-
Differential backup – based upon the last primary backup
-
Automated primary and differential backups
-
Restore to a specific primary or differential backup
-
Human-readable header to allow use of head on a backup file
-
Support OCI Marketplace for FMOS Images: FPM is now available for Oracle Cloud Infrastructure (OCI). We uploaded the current VMDK. Allows creation through FMOS-CPL and user data. SSH public keys are successfully uploaded. The default password is the last eight digits of the machine ID.
-
Support new Microsoft Exchange requirements for sending email: To prepare for Microsoft's planned retirement of SMTP basic authentication in Exchange Online (Microsoft 365) in December 2026, FMOS now supports email relay through the Microsoft Graph API. This enhancement ensures continued email delivery through Microsoft 365 after basic authentication is no longer supported. Graph API-based email relay can be enabled in Server Control Panel.
SMTP Relay
-
Platform Modernization and Performance Enhancements: Upgraded to Spring Boot 4, providing a modernized platform foundation, improved dependency management, remediation of numerous security vulnerabilities, and continued open-source support. This upgrade also enables Java 25 support and introduces Java virtual threads by default, improving scalability and reducing memory consumption during I/O-intensive operations. Virtual threads can be disabled through an environment property if needed.
As part of the upgrade, the backend API server has been standardized on Apache Tomcat, the default and industry-standard web server for Spring Boot applications.
Additionally, Elasticsearch has been upgraded to version 9, delivering a reduced memory footprint and improved query and aggregation performance through the underlying Lucene 10 enhancements.
-
Vulnerability mitigation: Updated core platform dependencies and security frameworks to improve stability, address security vulnerabilities, and maintain ongoing platform support.
|
|
2026.2.3
May 27, 2026
|
-
Azure Explode Network in a Box: Explode Network in a Box (ENIAB) introduces granular cloud topology modeling within SIP by decomposing cloud environments into distinct network elements, enabling improved visibility and accurate Access Path Analysis (APA) across cloud infrastructure.
Enhanced Azure cloud topology modeling provides improved visibility and path analysis across virtual networks, native Azure components, and third-party security devices, enabling organizations to view cloud infrastructure as an extension of the enterprise network.
APA will route through Azure firewalls, but will not evaluate policy in 2026.2.3, this functionality is deferred until 2026.2.4.
Microsoft Azure Subscription Provider
-
Vendor Tags: UI improvements to the page include the addition of an SIQL search and filtering bar, along with enhanced linking functionality.
About Vendor Tags
-
Policy Planner Workbench:
-
Added support for importing requirements into Workbench from existing workflow tickets, including the ability to review and edit requirements before import.
-
Added CSV import support for Manage Object and Remove Connectivity requirement types, enabling bulk import of requirements directly into Workbench.
|
|
2026.2.2
Apr. 29, 2026
|
-
Workbench (GA) in Policy Planner: Workbench introduces a redesigned experience for interacting with policy data, delivering improved performance and scalability through new backend APIs that enrich the policy content displayed in the UI. About Workbench
-
At GA, Workbench must be enabled via an API call with assistance from FireMon Support before it becomes visible in the Policy Planner interface.
-
Once enabled, it supports requirement types including Add Connectivity, Clone Server, Decommission Server, Remove Connectivity, Manage Object, and Ticket Revert, along with Rule Recommendation support (including error handling) and General and None change types.
-
At GA, only Access Request workflow is supported.
-
New Device: Extreme Networks Fabric Engine (VOSS) Switch is now supported through Level 4, for versions 9.0 to 9.3. Usage is tracked by hit counters. Hit counts are collected at the policy level rather than per rule. As a result, each rule within a policy displays the same hit count value. This value reflects total policy usage and cannot be used to determine whether a specific rule was matched. Extreme Networks Switch
-
Network APA UX Improvement: Network APA no longer requires the network map to render before users can enter queries, eliminating delays that previously blocked input. This update streamlines interaction and enables faster, more responsive query entry.
-
APA – Follow All Gateways: Improved packet path analysis when multiple interfaces share the same IP address. APA now follows all matching gateways on a network segment instead of only the first detected gateway, resulting in more accurate analysis outcomes.
-
Change Detection – User Identification: Change detection retrievals with change verification enabled now correctly identify the user associated with detected configuration changes.
-
Post-Backup Action – AWS S3 Bucket Checks: Added a Disable bucket checks option to Post-Backup Actions for AWS S3 buckets. When enabled, backups can be copied even if the account lacks permissions to list or create buckets; the parameter is disabled by default.
Post Backup Actions
-
Retrieval Health Check Filtering: Improved device status filtering to ensure results reflect each device’s current health status, rather than matching against historical records, providing more accurate and reliable filtering results.
|
|
2026.2.1
Mar. 25, 2026
|
-
Fortinet Intra-Zone Traffic Map APA: Added ability to map Fortinet intra-zone traffic using APA. For Intra-Zone traffic to display in APA, you must disable the default enabled option to block intra-zone traffic. To do this, in the Fortinet FortiGate device CLI, go to Edit Zone, disable the Block intra-zone traffic option to allow traffic to be visible in the config.
-
Arista and Cumulus Overlays. Introduced an Overlay Routing model that uses PBR and traditional routing to add (push), remove (pop), or forward overlays. Overlay context is now attached directly to packets, eliminating placeholder (fake) objects. This allows behavior to understand and model layer 2 and layer 3 connectivity and routing between remote VXLAN switches.
-
Illumio updates: Implemented ZTNA licensing and APA mapping. Syslog Parsing Scripts now support JSON-based syslog messages.
-
Policy Optimizer: Added the Rule Name (when available) to the Rule column of the All Reviews ticket list, providing additional context and improving review efficiency.
-
Elasticsearch: Added support for configuring the maximum HTTP request size in Elasticsearch. A default limit of 1000 MB is now applied if not specified, with support for values up to 2 GB. Requests exceeding this limit will be rejected by Elasticsearch. This setting is available in the UI when Advanced Options are enabled.
-
Data Collector Status: Added icons to visually represent the Last Status Update of the data collector.
-
Google Cloud Storage (GCP): Added support for storing FMOS backups in a Google Cloud Storage (GCP) bucket. Users can now configure a GCP bucket as an object store and provide Service Account credentials either by uploading a JSON file or entering them manually.
-
Google Cloud Storage (GCP): Added GCP Guest Environment / OS Config Agent functionality for FMOS.
-
Control Panel: SecMgr was renamed System. SecMgr was renamed System Settings. The Application Server option of SecMgr is the same.
|
|
2026.2.0
Feb. 25, 2026
|
-
Illumio integration: Added Illumio with Level 2 support. Security Manager can connect to the Illumio Policy and retrieve and normalize the following: Security Rules - Workloads - Labels (Application, Environment, Role, Location) - VENs (Virtual Enforcement Nodes) and their status. Illumio PCE
-
Improved memory health monitoring: Memory health monitoring now evaluates Available Memory instead of Free Memory and replaces the fixed 256MB warning limit with role-based percentage thresholds for more accurate, context-aware alerts. The updated UI displays total, used, and available RAM, reducing false low-memory warnings and unnecessary RAM upgrade recommendations.Control Panel Home \ Health Settings
-
SAML and OIDC deep-linking: Adding this support in the UI allows users to land directly on a specific page or resource after authentication enabling seamless navigation from third-party systems and supports more advanced workflows that require linking to reports, devices, policies, or other contextual views immediately after login.
|