Today we are releasing a maintenance version of Jamf Pro; highlights include:
Jamf Conditional Access.app, which is part of the Jamf management framework installed on enrolled computers and used for device compliance with Microsoft Entra, can now report on Microsoft Entra ID Platform SSO registration status and provide additional information about the registration state, including device ID and user UPN.
Jamf Pro Server: Security Issues
Jamf provides the CVE-ID for security issues with high or critical severity when possible.
- [PI141347] Fixed: A known vulnerability in a third-party library (CVE-2025-41249).
- [PI141349] Fixed: A known vulnerability in a third-party library (CVE-2025-41248).
- [PI141856] Fixed: A cross-site scripting (XSS) issue.
- [PI141857] Fixed: A cross-site scripting (XSS) issue.
- [PI120484] Fixed: Jamf Pro's PreStage enrollment displays iOS 17.5 as an available minimum OS version option, but this version is only supported by specific accessory devices (HomePod) according to Apple's Software Update Lookup Service feed. When administrators select iOS 17.5 for iPhone or iPad devices, the minimum OS enforcement fails silently during enrollment because Apple no longer supports this version for those device types, allowing devices to enroll without the required OS update.
- [PI135990] Fixed: When a minimum required OS version is specified in computer and mobile device PreStage enrollments, the OS version is automatically updated to the latest version released by Apple without user input.
- [PI141164] Fixed: In environments using OIDC-based SSO with Jamf Account, Jamf Pro can mishandle user logouts, resulting in unexpected "Access denied" errors, loss of app switcher functionality, and platform sessions ending prematurely.
- [PI141237] Fixed: The /v2/mobile-devices/detail API endpoint returns a 500 error when queried with section=SECURITY for devices that have blank or unknown values in the OS family field.
For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro.
Cloud Upgrade Schedule
Your Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance.
To upgrade manually: Log in to Jamf Account, click View details on the Jamf Pro tile, and then click Upgrade on the appropriate instance. Note: This capability is not available for GovCloud environments and is disabled for all instances one day prior to when the scheduled standard upgrades begin.
Subscribe to product alerts to receive real-time updates.
Hosted Region | Begins | Ends |
ap-southeast-2 | 10 October at 1300 UTC | 10 October at 1900 UTC |
ap-northeast-1 | 10 October at 1500 UTC | 10 October at 2300 UTC |
eu-central-1 | 10 October at 2200 UTC | 11 October at 0900 UTC |
germanywestcentral Azure | 10 October at 2200 UTC | 11 October at 0100 UTC |
eu-west-2 | 10 October at 2300 UTC | 11 October at 0600 UTC |
us-east-1 StateRAMP | 11 October at 0400 UTC | 11 October at 1400 UTC |
us-east-2 | 11 October at 0400 UTC | 11 October at 1400 UTC |
central-us Azure | 11 October at 0500 UTC | 11 October at 0700 UTC |
us-west-2 | 11 October at 0700 UTC | 11 October at 1800 UTC |