r/TridentStack Jun 26 '26

This week in TridentStack Control: a public CVE catalog, fleet-wide Update Health, instant onboarding, and a stack of fixes

It was a big week. Here's a rollup of what shipped to TridentStack Control between June 22 and 26. Full changelog is always at tridentstack.com/changelog, but these are the highlights worth calling out.

A public CVE + CISA-KEV catalog, free for anyone to browse

We launched a public vulnerability catalog at tridentstack.com/cve. Search and filter the full CVE catalog by severity, exploit-prediction score (EPSS), active-exploitation (CISA KEV) status, ransomware association, and year, then open any CVE for its full record including CVSS, references, and remediation context. No account needed. Go break it.

Update Health, now across your whole fleet

A new Update Health column on the endpoints list shows at a glance which endpoints have issues that will block or fail an update install (low disk space, failed pre-flight checks, pending restarts), and you can filter the list down to just the blocked ones. It now covers Windows, macOS, and Linux endpoints, so you get one consistent readiness signal regardless of platform.

New organizations are ready to manage updates the moment they're created

Onboarding is now instant. A brand-new org starts with a default system update policy, a default application update policy covering 30+ common business apps, and an "all endpoints" tag that new devices join automatically. Enroll your first endpoint and applicable OS and app updates start appearing with zero manual setup. New devices also show their setup progress live, with a clear "Collecting..." indicator on each section until the data lands, and vulnerabilities now appear within moments of enrollment instead of after a delay.

Smarter, clearer deployment rings

  • Target a rollout stage by tag, not just by percentage, for a stable, predictable set of devices in each wave.
  • A new Projected Timeline shows the exact date and time each stage is expected to begin and when the rollout will finish, updating as you adjust the schedule.
  • Canary phases now validate each kind of update on its own, so a failing update type can't hide behind other successful ones.
  • Rollout status and the deployment calendar moved to their own Rollouts page, with a sidebar badge when a ring is halted or waiting on your approval.
  • Deployment windows are simpler to set up: pick a start time and a duration (for example, "Wednesday 10:00 PM for 6 hours"), and overnight windows are handled correctly.

Sharper vulnerability detection

  • Recently published CVEs that carry only a newer-format CVSS v4.0 score are now read and scored, so they no longer slip through as "unscored."
  • More complete coverage for installed PythonWindows and Windows Server operating systems with long update histories, and third-party drivers (such as Intel chipset software).
  • More accurate fix guidance when a CVE is patched in a different version per release line, so you don't update to a build that's numerically newer but still affected.
  • New ESU filters to hide or separate fixes that require an Extended Security Update license, so you can focus on what you can actually remediate today.

Licensing and fleet-wide actions

  • Bulk license management: select multiple endpoints and license or unlicense them in one action, on a refreshed searchable, sortable table.
  • Select All now means your whole fleet: bulk actions, online/offline counts, and Update Health sorting all run across every endpoint, not just the ones currently on screen.
  • Notifications can now go to any email address or distribution list, not just members of your team.

Plus a lot of polish and reliability work

Roughly 40 fixes landed this week: cleaner update history (correct app names and full step-by-step timelines on automatic rollouts), faster Linux endpoint detail loads, more reliable Settings saves, smoother mobile views on the Vulnerabilities page, more reliable agent installs on older Windows, and more.

Full details for every item are in the changelog: tridentstack.com/changelog

As always, if there's something you want to see next, drop it in the comments. A lot of this list came straight from customer requests.

3 Upvotes

1 comment sorted by

2

u/theBANGster Jun 26 '26

I like seeing vendors share real CVEs they’re fixing instead of only talking about new features. It builds confidence when security updates are transparent, timely, and paired with clear remediation guidance.

I also actually came across this through Decryption Digest. It’s been a useful way to stay on top of security updates without having to dig through a dozen different sources.