- Added security check to ensure renewed certificates match the session’s attached certificate.
- Introduced support for Hashi‑built external plugins in the UI and upgraded Go runtime to 1.25.6.
- Fixed numerous bugs: Vault Agent token caching on transient errors, HSM seal crash, default auth root handling, PKI SCEP digest errors, UI login form query handling, and Kubernetes CA certificate field type.