Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues:
Jamf Pro Server: Security Issues
Jamf provides the CVE-ID for security issues with high or critical severity when possible.
- [PI186191] Fixed: A cross-site scripting (XSS) issue.
- [PI208395] Fixed: A cross-site scripting (XSS) issue.
- [PI209382] Fixed: The Jamf Pro installers include Spring Framework 6.2.18, which includes multiple vulnerabilities, including CVE-2026-41842 and CVE-2026-41855.
Jamf Pro Server
[PI148391] Fixed: After modifying the custom configuration PLIST for iOS shared device compliance, Jamf Pro fails to redistribute the updated configuration to target devices until they are re-enrolled.
Note: This issue was resolved in Jamf Pro 11.31.0 and was inadvertently omitted from those release notes.
Subscribe to Jamf Learning Hub content
When logged in to the Learning Hub, click the Subscribe button (bell icon) on the release notes page to receive email when that content is updated (i.e., a new version of Jamf Pro is available). For more information about the Subscribe feature, see Jamf Learning Hub Watchlist.
For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro.
Cloud Upgrade Schedule
Your Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance.
To upgrade manually: Log in to Jamf Account, click View details on the Jamf Pro tile, and then click Upgrade on the appropriate instance. Note: This capability is not available for GovCloud environments and is disabled for all instances one day prior to when the scheduled standard upgrades begin.
Subscribe to product alerts to receive real-time updates.
| Hosted Region | Begins | Ends |
| ap-southeast-2 | 21 August at 1400 UTC | 21 August at 2000 UTC |
| ap-northeast-1 | 21 August at 1500 UTC | 21 August at 2300 UTC |
| eu-central-1 | 21 August at 2200 UTC | 22 August at 0900 UTC |
| germanywestcentral Azure | 21 August at 2200 UTC | 22 August at 0000 UTC |
| eu-west-2 | 21 August at 2300 UTC | 22 August at 0600 UTC |
| us-east-1 StateRAMP | 22 August at 0400 UTC | 22 August at 0800 UTC |
| us-east-2 | 22 August at 0400 UTC | 22 August at 1300 UTC |
| central-us Azure | 22 August at 0500 UTC | 22 August at 0700 UTC |
| us-west-2 | 22 August at 0700 UTC | 22 August at 1800 UTC |
