Service Packs

This page details Service Pack features that have related Help site documentation as well as other must-read information. iMIS 2017 Service Packs are cumulative; only the most recently released service pack is available for download.

Download the iMIS 2017 Service Pack.

Review the ReadMe file (included in the above download) for information about what was fixed in the Service Pack.

🚧

Warning

After applying the Service Pack, do not use the Reset functionality located in the DB Maintenance Utility. Initiating any resets will overwrite database changes made in a Service Pack.

Service Pack 2026 (20.2.66.1665): September 2026

Security enhancements

This service pack improves the additional safeguards added in Service Pack 2026 Q3.1 (20.2.66.1644) to sanitize malicious code from text input fields and WYSIWYG editors. Spaces and special characters in web addresses are written as substitute codes, such as %20 for a space, as in the following HTML: <a href="https://www.example.org/documents/Annual%20Report.pdf">Annual Report</a>. Sanitization now evaluates these codes, allowing staff users to link to files with spaces or special characters in their names when editing RiSE pages. Disallowed input, such as malicious scripts, is still sanitized. Review the Tech Alert for details.

Additionally, security updates to third-party components (Telerik controls) render certain iMIS Desktop screens inoperable. Review the Tech Alert for details.

DataVault

No change.

Service Pack 2026 Q3.2 (20.2.66.1647): August 2026

Fixes an issue that prevented users from logging into Desktop and caused Staff site navigation items to go missing.

DataVault

No change.

Service Pack 2026 Q3.1 (20.2.66.1644): August 2026

Security enhancements

This service pack includes additional safeguards to detect and remove potentially malicious server-side code from text input fields and WYSIWYG editors (such as the Content Html content item) upon saving. This protection is applied automatically and does not require any configuration by staff users.

DataVault

No change.

Service Pack 2026 Q3 (20.2.66.1591): July 2026

Security enhancements

This service pack includes a critical Telerik security update. All clients on iMIS 2017 should apply this service pack immediately, unless you have already applied the web.config mitigation published in the Tech Alert below.

Review the Tech Alert for details.

DataVault

No change.

Service Pack 2026 Q2.1 (20.2.66.1590): May 2026

Security enhancements

Review the Tech Alert for details.

DataVault

No change.

Service Pack 2026 Q2 (20.2.66.1567): April 2026

Controlling RESTΒ APIΒ access to panel sources

To enhance security for panel sources accessed through the REST API, new configuration options are available to control which panel sources can be accessed externally. Administrators can now explicitly define REST API availability on a per–panel source basis, helping prevent unauthorized access to sensitive data.

A new Panel Source Security page has been added (RiSE > Panel Source > Security), where you can select a panel source and configure its REST API access settings. A drop-down list displays all available panel sources, allowing you to manage security individually. Out-of-the-box panel sources that use locked business objects cannot be modified and will remain restricted.

See Panel Designer for details.

Other security enhancements

See the Tech Alert for details.

DataVault

No change.

Service Pack 2025 Q4 (20.2.66.1465): October 2025

Includes security and performance enhancements.

DataVault

No change.

Previous Service Packs

See Historical Service Pack Releases.



Did this page help you?