A consolidated, always-current changelog for the Exium platform — covering endpoint clients, Cyber Gateways, and the management portals. Entries are listed newest-first.
Reading the tables. A
—in the Date column means the exact release date isn't on record for that build. Newer releases include precise dates where available.
The Windows client delivers the Exium tunnel, telemetry, and security tooling to desktops and laptops.
| Release | Date | New Features | Issues Fixed |
|---|---|---|---|
| 6.0.3 | — | Bug fixes associated to tunnel expiry reseting. | — |
| 6.0.2 | — | Addressed reconfigure cooldown mechanism when handshake fails. | — |
| 6.0.0 | — | Improvised network change based tunnel reseting logic. | — |
| 5.9.7 | — | Improvised connectinvity checks for tunnel state. | — |
| 5.8.6 | — | Added a monitoring mechanism for supportive processes. Reworked DNS timeout handling and revised the Auto Tunnel Recovery logic. |
— |
| 5.8.2 | — | Updated bundled security software components. | — |
| 5.8.0 | — | Migrated to the latest .NET framework to take advantage of its newer capabilities. | — |
| 5.7.3 | — | Introduced Auto Reconfiguration and a tunnel recovery mechanism. | — |
| 5.6.3 | — | Rebuilt the installer on a native framework. | — |
| 5.5.0 | — | Added a native bridge for libraries and code files for improved performance. | — |
| 5.1.3 | — | — | Configuration file now updates correctly during subnet changes. |
| 5.1.0 | — | Added automatic and delayed tunnel startup. Added blocking of client connections from specific public IPs. |
— |
| 5.0.6 | — | — | Corrected the uninstall procedure. |
| 5.0.0 | — | Added captive-portal connectivity for hotel and airport Wi-Fi networks. | — |
| 4.9.8 | — | Optimized client install and upgrade. | — |
| 4.9.7 | — | Updated the telemetry agent. Added an option to run only the telemetry agent alongside the tunnel. |
— |
| 4.9.3 | — | Added a configurable reconnect timer. | — |
| 4.8.9 | — | Excluded the machine's local subnet from tunneling. | — |
| 4.8.7 | — | Optimized notifications for NSLookup timeouts and unreachable DNS. | — |
| 4.8.6 | — | Activate the tunnel during updates for SSO users. | — |
| 4.8.5 | — | Added user authentication and recovery from connectivity failures. | — |
The macOS client offers a unified desktop and tray experience with one-click connectivity.
| Release | Date | New Features | Issues Fixed |
|---|---|---|---|
| ==4.6.6== | 07/21/2026 | — | Reduced tunnel connection time by ~10 seconds |
| ==4.6.5== | 07/21/2026 | IPv6 network support for connect and disconnect | — |
| ==4.6.4== | 07/17/2026 | — | Fixed monitor service not loading after install on some systems |
| ==4.6.3== | 07/17/2026 | — | Improved install sequencing; fixed SSO prompt appearing before installation completes |
| ==4.6.2== | 07/15/2026 | — | Improved DNS cleanup on disconnect; reduced false alerts; DMG installer reliability improvements |
| ==4.6.1== | 07/14/2026 | — | Improved device registration at install time |
| ==4.6.0== | 07/14/2026 | — | Infrastructure and packaging updates |
| ==4.5.9== | 07/14/2026 | — | Further CPU improvements; improved DNS handling on disconnect |
| ==4.5.8== | 07/10/2026 | — | Fixed high CPU usage (airportd) when inactive USB network adapters are connected |
| ==4.5.7== | 07/09/2026 | — | Improved tunnel startup reliability |
| ==4.5.6== | 07/09/2026 | — | Fixed UI showing incorrect state after authentication; improved handling of empty config |
| ==4.5.5== | 07/07/2026 | — | Fixed auto-reconnect for non-SSO deployments; improved manual disconnect handling |
| ==4.5.4== | 07/06/2026 | Tunnel stays connected during SSO re-authentication | Improved handshake recovery; telemetry agent registration fixes |
| ==4.5.3== | 07/02/2026 | — | General stability improvements |
| ==4.5.2== | 06/30/2026 | — | Fixed race conditions during SSO sign-in; install now prevents concurrent runs |
| ==4.5.1== | 06/29/2026 | — | Fixed client retrying endlessly after a failed reconnect |
| ==4.5.0== | 06/23/2026 | — | Improved SSO sign-in routing; enhanced auto-reconnect reliability |
| ==4.4.7== | 06/22/2026 | — | Connection stability improvements |
| ==4.4.6== | 06/22/2026 | — | Reduced alert noise; improved notification accuracy; fixed username handling during install |
| ==4.4.5== | 06/18/2026 | — | Improved Homebrew compatibility on macOS |
| ==4.4.4== | 06/18/2026 | — | General reliability improvements |
| ==4.4.3== | 06/17/2026 | — | Fixed an issue that could cause duplicate device registrations |
| ==4.4.2== | 06/16/2026 | — | Duplicate user fix added , tray icon animation issue |
| ==4.4.1== | 06/10/2026 | — | Added fixes for CPU issues in monitor |
| ==4.4.0== | 06/10/2026 | — | WireGuard security vulnerability issues fixed (compramised keys are added under keychain) |
| ==4.3.4== | 06/06/2026 | — | Dmg installer changes are added |
| ==4.3.3== | 06/05/2026 | Cancel sign in option added at time of authentication | Few bug fixes related to SSO fixed |
| ==4.2.6== | 05/28/2026 | — | when laptop wakes after sleep , SSO reauth cases fixed |
| ==4.2.3== | 05/27/2026 | — | SSO expiry cases and it's stability handled |
| ==4.1.4== | 05/26/2026 | — | Fixed WireGuard path-export and connectivity issues. |
| 4.1.2 | 05/21/2026 | — | Fixed Command Line Tools (CLT) installation issues. |
| 4.1.0 | 05/11/2026 | Added control recovery procedures. | Critical bug fixes. |
| 4.0.6 | 05/07/2026 | — | Fixed an nslookup timeout that could stall the monitor cycle. |
| 4.0.2 | 04/14/2026 | New, user-friendly Mac client UI. Connect/Disconnect control with live status. Unified Desktop and Tray app, with the option to launch the Desktop app from the tray. |
— |
| 3.2.3 | — | Better handling of user-control settings from the management portal. Improved auto-reconnect support. |
Fixed a case where tunnel activation could fail during installation on some systems. |
| 3.2.2 | — | Added automatic retry for API calls during installation. | More reliable installation over slow or intermittent networks. Fewer timeout-related install failures (e.g., when the laptop sleeps mid-install). |
| 3.2.0 | — | Improved Homebrew install compatibility for RMM-deployed setups. Enhanced event tracking (ClientId on all events). Better error reporting and logging. |
Fixed various edge cases in the installation flow. |
| 3.1.0 | — | Added handshake-failure detection and alerting. Improved notifications with device identification. |
— |
| 3.0.0 | — | Redesigned utility scripts with enterprise-grade error handling. Improved dependency management and validation. Greater stability across all client operations. |
— |
| 2.4.0 | — | Security improvements. Better error handling and cleanup throughout installation. |
Critical bug fixes. |
| 2.0.4 | — | — | Bug fixes. |
| 2.0.1 | — | Optimized reconfiguration procedures. | — |
| 1.9.6 | — | Added critical events to the platform. | Optimized reconnect and recovery procedures. |
| 1.9.2 | — | — | Optimized reconnect and recovery procedures. |
| 1.9.1 | — | Reuse an existing WireGuard installation from other apps (e.g., Perimeter 81, the native WireGuard app). | — |
| 1.9.0 | — | Captive-portal optimizations. Added recovery checks for internet failures. |
Fixed reconnection after subnet changes. |
| 1.8.2 | — | — | Installer fix for path-related issues on some Macs. |
| 1.8.0 | — | Installer optimizations. | Fixes for captive-portal access. |
| 1.7.6 | — | Installer update for quick install. | — |
| 1.7.5 | — | Telemetry agent update. | — |
| 1.7.3 | — | Allow authentication on captive-portal sites. | Fixed wireless-network scanning on some Macs. |
| 1.6.0 | — | Added a configurable reconnect timer. | — |
| 1.5.0 | — | Send the public IP to the platform for Geo policies. | — |
| 1.4.0 | — | Exclude the machine's local subnet from tunneling. | — |
| 1.3.0 | — | Unique device names by appending the serial number to the hostname. | — |
| 1.2.2 | — | User authentication via SSO. | — |
The Linux client delivers the Exium tunnel, telemetry, and security tooling to Ubuntu based Linux systems
| Release | Date | New Features | Issues Fixed |
|---|---|---|---|
| 2.0.0 | — | SSO support | — |
| 1.0.1 | — | Initial version | — |
Release notes for the Single-Interface (SIF) and Multi-Interface (MIF) Cyber Gateways.
A streamlined gateway for single-network deployments.
| Release | Date | New Features | Issues Fixed |
|---|---|---|---|
| ==1.1.8== | 07/29/2026 | Auto disk cleanup enhancement. Failover time optimization (Under 50 seconds). CPU limit reduction under 40% for recovery procedures |
|
| 1.1.3 | 07/09/2026 | Removed unwanted remote access utility | |
| 1.1.2 | 07/08/2026 | Switchover time optimization during HA | |
| 1.0.0 | 07/01/2026 | Diagnostics service to run in the background, reducing operational interruptions. CPU usage management for performance-related processes. |
Added handling of rare failover timing scenarios |
| 0.6.6 | 06/17/2026 | — | Minor fixes in HA state transition handling |
| 0.6.4 | 06/08/2026 | Disable auto backend jobs if CPU limit reaches threshold. Added recovery logic to pull mesh configuration if SPA connectivity fails |
|
| 0.6.2 | — | — | Bug fixes for the internet-access audit. |
| 0.6.1 | — | Send uptime and machine-state events during internet-failure recovery. | — |
| 0.6.0 | — | Enable the High Availability (HA) flag dynamically. | — |
| 0.5.9 | — | Auto-update the trust path when the LAN interface or default gateway changes. | — |
| 0.5.8 | — | Validate internet access before install/upgrade. | — |
| 0.5.7 | — | Threat removal on the gateway machine. | — |
| 0.5.6 | — | — | Minor health-monitoring and service-auditing fixes. |
| 0.5.5 | — | NetFlow support for broader network visibility. | — |
| 0.5.4 | — | Overlapping-subnet support. | — |
| 0.5.3 | — | High Availability optimizations. | — |
| 0.5.2 | — | Performance-metrics optimization. | — |
| 0.5.1 | — | Performance-metrics support. | — |
| 0.5.0 | — | Security: migrated cloud-shell to HTTPS. | — |
| 0.4.0 | — | Updated reboot-recovery mechanism. Optimized internet-access checks. HA updates. |
HA fixes. |
| 0.3.9 | — | WireGuard tunnel service update. | — |
| 0.3.8 | — | Optimizations. | Bug fixes. |
A full-featured gateway supporting multiple LAN/VLAN and WAN interfaces, firewalling, and DHCP/DNS services.
| Release | Date | New Features | Issues Fixed |
|---|---|---|---|
| ==2.6.8== | 07/14/2026 | Firewalld Auto-Recovery — gateway automatically unmasks and restarts the firewall service if it stops; firewall rules remain enforced without manual intervention. iPerf3 Improvements — enhanced in-device network performance testing. |
AdGuard DNS — bind address corrected; DNS service reliably starts after config updates. Cold-start link stability — Energy Efficient Ethernet (EEE) disabled on CGW interfaces to prevent hardware-level link drop on cold boot. MWAN — false WAN-down alerts suppressed on first boot when interface has never connected. Duplicate NGCN unreachable notifications eliminated. |
| 2.6.7 | 07/10/2026 | — | Wireshark diagnostic tools now install correctly on Ubuntu 24.04. Firewall NAT mode correctly preserved when MWAN load balancing is disabled. Docker API compatibility fix for Ubuntu 20.04 ARM64 (NanoPi). |
| 2.6.6 | 07/09/2026 | — | Upgrade fix — primary LAN subnet no longer reordered during upgrade; interface-to-subnet mapping correctly preserved. CGW status display formatting fixed (version and uptime on separate lines). |
| 2.6.5 | 07/07/2026 | — | False xmesh "tunnel recovered" alerts suppressed — recovery notifications only sent when a prior down alert was actually delivered. NGCN latency reporting edge-case values corrected. |
| 2.6.4 | 07/06/2026 | cgw-config.ini — new centralized configuration file; notification thresholds, cooldown intervals, and alerting parameters are tunable without firmware changes. MWAN Failover Delay — configurable confirmation window before declaring a WAN link down, reducing false failovers on transient link blips. |
AdGuard DNS automatically binds to all LAN/VLAN subnets in multi-subnet deployments — no manual configuration needed. VLAN ACL now supports multiple source subnets per rule. Latency alerting default threshold corrected to 50ms. |
| 2.6.3 | 07/02/2026 | — | DHCP reliability — server now waits for VLAN interfaces to fully initialize before starting; no longer probes physically disconnected interfaces. Notifications consolidated to failure-only with configurable rate limits across all audit scripts. |
| 2.6.2 | 06/23/2026 | — | MWAN — false WAN-down alerts suppressed during boot; routing conflict between systemd-networkd and MWAN resolved. Wazuh recovery now handles stale lock files and incomplete registrations without manual cleanup. |
| 2.6.1 | 06/22/2026 | — | Tunnel recovery extended to all mesh peers, not just the primary NGCN peer. LAN IP assigned earlier in startup when an interface is slow to come up. Alert noise reduced — never-connected peers generate a single notification with periodic reminders only. |
| 2.6.0 | 06/15/2026 | VLAN ACL — inter-VLAN access control with IP and subnet-based filtering; define exactly which VLANs can reach which. Configurable HA LAN IPs — per-node LAN IP assignment for high-availability deployments. MWAN Preferred WAN — set which WAN interface takes priority when both links are active. NGCN Tunnel Auto-Recovery — gateway automatically re-establishes lost connections to the cloud network controller. |
Log rotation and packet capture file cleanup prevent disk fill over time. Pre-shutdown diagnostics snapshot saved before reboot. Firewall container updated to v1.0.10; management agent updated to v2.4.12. |
| ==2.4.1== | 05/12/2026 | Firewall Rules — configure firewall rules per VLAN, with multi-port support. Ubuntu 26.04 support added. |
WAN IP Recovery — more reliable recovery after link loss; now compatible with Ubuntu 22.04 and newer. VLAN ACL — more reliable removal of VLAN access-control rules. Docker Recovery — improved Docker reinstallation during recovery scenarios. |
| 2.3.4 | — | — | Critical bug fixes for Multi-WAN (MWAN) failure recovery. |
| 2.3.1 | — | WAN interface failure notifications in Multi-WAN deployments. | — |
| 2.3.0 | — | Per-interface Upstream DNS — set a custom DNS server per LAN/VLAN interface for DHCP clients. Per-interface DHCP Relay — each LAN/VLAN interface can independently use a relay server. Dynamic network-buffer optimization for better throughput under load. Enhanced Multi-WAN recovery with automatic system recovery for persistent issues. |
More reliable installs with automatic retry on package-download failures. Stability and error-handling improvements for configuration updates. |
| 2.2.7 | — | Pre-installation validation — portal connectivity and package-availability checks before any system change. Improved Multi-LAN and VLAN configuration handling. AdGuard Home DHCP integration improvements. |
Velociraptor endpoint detection and installation fixes. General stability improvements. |
| 2.2.6 | — | High Availability — improved failover reliability and config sync between primary and secondary nodes. Multi-WAN recovery — automated recovery for WAN connectivity issues. Static DHCP lease management. DNS intercept and traffic monitoring. AdGuard Home as a DHCP-server option alongside ISC DHCP. |
Improved portal notifications and status reporting during installation. |
| 2.0.0 | — | New GA release (version bump). | — |
| 1.7.3 | — | Install-notification optimization. | — |
| 1.7.2 | — | Support for Ubuntu 25.04. | — |
| 1.7.0 | — | WAN alias IP support. Port-forwarding policies for WAN alias IPs. |
— |
| 1.6.3 | — | Dynamic IDS signature updates. | NanoPi R5S Docker install fixes. |
| 1.6.0 | — | Dynamic IDS configuration updates. Dynamic packet-capture portal password. |
— |
| 1.5.0 | — | Network Access Control — captive-portal user authentication for internet access. | — |
| 1.4.0 | — | Gateway Local UI now served over HTTPS. DNS suffix support. |
Optimizations in gateway update procedures. |
| 1.3.2 | — | Updated control version. Support for multiple subnets in port forwarding. |
Improved installation mechanism. |
| 1.3.0 | — | WireGuard tunnel service updates. | Fixed internet failures in some deployments. |
| 1.2.1 | — | Telemetry agent update. Improved WAN-interface selection and validation during install. |
Added a recovery mechanism for the DHCP server. |
| 1.2.0 | — | Display LAN and WAN interfaces in the admin console. Dynamic Single→Multi WAN upgrade (no redeploy). Dynamic Single→Multi LAN upgrade (with redeploy). Improved interface selection during install. |
Retain DNS customer-filtering rules during version upgrades. |
| 1.1.6 | — | Reduced Multi-WAN link-failure detection time. Audit-mechanism enhancements. |
Multi-WAN fixes. NanoPi optimizations. |
| 1.1.1 | — | Dedicated inter-LAN communication flag for Multi-LAN deployments. Optimizations for Multi-LAN / Multi-WAN deployments. |
— |
| 1.0.1 | — | Multi-LAN updates when the gateway is deployed with Multi-WAN. Site-local firewall policy enhancements. Performance-metrics support. |
— |
| 1.0.0 | — | Static IP selection per WAN interface in Multi-WAN. DHCP range configuration per LAN interface in Multi-LAN. Optimized DHCP-server selection. Public IP as trust path for ZTNA access. Security: cloud-shell migrated to HTTPS. |
— |
| 0.9.1 | — | Random password on new gateway creation. Shared password across DNS Security, cloud-shell, Webmin, and others. Updated Local UI layout. |
Installation optimizations for WAN failures and other error cases. |
| 0.9.0 | — | WireGuard tunnel service updates. LAN scan now includes VLAN interfaces. |
— |
| 0.8.9 | — | DNS suffix support on gateways. Custom DHCP range support on VLANs. Static leases on LAN and VLAN. |
— |
Exium's Zero-Trust, multi-tenant, multi-service SASE platform for MSPs provides both an MSP-level portal and a client workspace administration console. Release notes for both portals are below.
| Release | Release Month | New Features |
|---|---|---|
| ==5.1.4== | June 2026 | Device Posture Enhancements Preferred Cybernodes Support Default Group/workspace for Trustpaths Partner Level Reports Configuration |
| 5.1.3 | May 2026 | New Onboarding UI Overhaul SPA Domain policies, Grouped IP Policies with common ports Device Posture Must haves DPA Enhancements Generic SIEM Integration VLAN ACL, Agentless Auth Support |
| 5.1.2 | April 2026 | New onboarding flows, mail templates, and easy email-based sign-in. New iOS and Android apps with desktop-equivalent control from the platform. PingOne SCIM support. Policy View updates. |
| 5.1.1 | March 2026 | UI overhaul with branding synchronization. Reports reorganization. MIF gateway advanced features — DHCP Relay and DNS Interception. |
| 5.1.0 | February 2026 | Granular VLAN controls. PingOne as an SSO mechanism. Additional enhancements. |
| 5.0.0 | January 2026 | Cyber AI support in the Admin Console and Partner Portal. XDR, IAM, and GCR — easier credential handling. Reports reorganization. |
| 4.20.3 | December 2025 | Blocked apps in Policy View APIs. Platform enhancements. |
| 4.20.2 | November 2025 | MIF gateway port-forwarding feature. Platform enhancements. |
| 4.20.1 | October 2025 | Company Portal roles support. NFR for partner organizations. |
| 4.20.0 | September 2025 | MIF gateway port-forwarding feature. NFR for partner organizations. Platform enhancements. |
| 4.19.0 | August 2025 | DPA enhancements. Local Sites — IDP policy APIs. |
| 4.18.0 | July 2025 | Mobile device support. Egress Geo policy support. DPA enhancements. |
| 4.17.0 | June 2025 | Device Posture support. Direct Private Access — Phase 1. Malicious IPs support. |
| 4.16.0 | May 2025 | Multi-Interface Gateway configuration on a single page. Custom Geo ingress policy support. Group-level traffic-steering apps. |
| 4.15.0 | April 2025 | Group- and user-level SSO authentication settings. Auto-release of unused devices. IPv6. Partner-level Geo policies in Policy View. |
| 4.14.0 | March 2025 | DNS Security — CNAME support. Custom malicious-domain support. DNS Security — application policy support. Gateway Policy View. |
| 4.13.0 | February 2025 | DoH domains support. Isolate/Unisolate a device from the Admin Console. Auto-apply partner policies to workspaces. Auto-upgrade at group, user, and partner level. Captive-portal settings at workspace/group/user level. |
| 4.12.0 | January 2025 | Integrated Windows EXE delivered via email. GRCN activation/deactivation support. Exium IAM as an SSO method. |
| 4.11.8 | December 2024 | SuperOps PSA integration. Agentless activation/deactivation support. ZTNA firewall support for Meraki devices. Exclude LAN subnet support. |
| 4.11.3 | November 2024 | Secure Chromebooks support. SSO/MFA-based authentication for Secure Private Access. Adjustable MTU for optimized network performance. |
| 4.11.2 | October 2024 | Granular conditional access controls. Enhanced threat prevention with AI and premium intelligence. Flexible SIA and SPA services for diverse remote-access needs. |
| 4.11.1 | September 2024 | Comprehensive vulnerability scans. Custom splash pages for blocked websites. Comprehensive visibility and dashboards for web and SaaS security. Greater control over security-incident and network-connection alerts. |
| 4.11.0 | August 2024 | Tailored security controls across hierarchical levels. Support for multiple private (upstream) DNS servers. Group-level DNS suffix configuration. |
Need a hand? For expert guidance on implementing SASE, XDR, IAM, and GRC solutions, reach out to Exium at partners@exium.net.
Ready to get started? Explore our testing and onboarding process.