- Critical remote authentication bypass (CVE‑2025‑49825) fixed by removing special handling for SSH certificate authorities in CertChecker.
- Multiple bug fixes: pagination added to WindowsDesktop APIs, duplicate DynamoDB inventory entries resolved, idle‑timeout termination for Windows desktops corrected, and a Kubernetes Access memory‑leak repaired.
- Go runtime upgraded to 1.23.10 and a new update‑status flag added to modify exit codes based on Teleport update status.