StigSanctum Logo
StigSanctum
Release Notes
Q1 2026 | February 2026

Q1 2026 Release Notes

This release incorporates the latest DISA STIG updates from the January 2026 quarterly release cycle, along with enhanced scanning scripts and platform improvements.

492
StigID Updates
35
Benchmarks
2
Script Updates
21
Consolidated StigIDs

DISA STIG Updates (January 2026)

The following summarizes key changes from DISA's quarterly STIG release dated 05 January 2026.

MS SQL Server 2016 - V3R4 (Database) / V3R6 (Instance)

Major Consolidation

DISA consolidated multiple duplicate requirements into combined checks. The following StigIDs have been removed:

Script Changes

Microsoft Windows 11 - V2R6

Key Changes

Microsoft Windows Server 2019 - V3R7

Key Changes

Microsoft Windows Server 2022 - V2R7

Key Changes

Active Directory Domain - V3R6

Key Changes

Canonical Ubuntu 22.04 LTS - V2R7

Key Changes

Canonical Ubuntu 24.04 LTS - V1R4

Key Changes

Cisco ACI - V1R2 (L2S) / V1R2 (NDM)

Key Changes

Cisco ASA - V2R4

Key Changes

Cisco IOS Router - V3R6

Key Changes

Cisco IOS Switch - V3R6

Key Changes

Cisco IOS-XE Switch - V3R5

Key Changes

Cisco IOS-XR Router - V3R5

Key Changes

Cisco ISE - V2R3 (NDM) / V2R3 (NAC)

Key Changes

Cisco NX-OS Switch - V3R6 (NDM) / V3R3 (L2S)

Key Changes

Juniper EX Switches - V2R4 (L2S) / V2R4 (NDM)

Key Changes

Mozilla Firefox - V6R7

Key Changes

MS Defender Antivirus - V2R7

Key Changes

Microsoft Edge - V2R4

Key Changes

MS IE11 - V2R6

Key Changes

MS Office System 2016 - V2R5

Key Changes

MS SQL Server 2022 - V1R3 (Instance) / V1R2 (Database)

Key Changes

RHEL 8 - V2R6

Key Changes

RHEL 9 - V2R7

Key Changes

Previous Quarter Updates (Reference)

The following benchmarks were not updated in the January 2026 release. Their most recent DISA revision details are included for reference.

MS Azure SQL MI - V1R1 (23 September 2025)

Active Directory Forest - V3R2 (02 July 2025)

MS DotNet Framework 4.0 - V2R7 (02 July 2025)

MS Exchange 2019 - V2R3 (02 July 2025)

MS Azure SQL DB - V2R3 (02 July 2025)

Google Chrome - V2R11 (02 July 2025)

MS Windows Server DNS - V2R3 (02 April 2025)

Juniper SRX SG - V3R3 (NDM/ALG) / V3R2 (VPN) (30 January 2025)

Juniper Router - V3R2 (NDM/RTR) (30 January 2025)

MS Exchange 2016 - V2R6 (30 January 2025)

MS Windows Defender Firewall - V2R2 (09 November 2023)

StigSanctum Script Updates

The following scripts were updated to align with revised DISA CheckContent procedures:

Local Administrator Password Age Check

Affected STIGs: WN19-00-000020, WN22-00-000020

Change: Updated scan to align with revised DISA check procedure targeting the built-in Administrator account by SID. Returns a finding if password exceeds 60 days. Handles disabled and missing accounts as Not A Finding.

SQL Schema Ownership Check

Affected STIGs: SQL6-D0-001200, SQLD-22-001200

Change: Updated to exclude standard database schema principals (dbo, db_owner, sys, INFORMATION_SCHEMA, etc.) per revised DISA guidance. Reduces false positives by only flagging non-standard schema ownership.

Additional DISA Changes Reviewed

The following DISA changes were reviewed and confirmed that existing StigSanctum scan logic already handles the updated requirements correctly. No scan updates were needed:

Repository Improvements

Recent development activity and platform enhancements:

Network Device Scanning
Linux Scanning
Azure SQL Enhancements
Platform Improvements

Upgrade Instructions

Upgrade Steps
  1. Back up your StigSanctum database
  2. Run the installer and select the Upgrade option
  3. Update the StigSanctum PowerShell module on any remote scan servers
  4. Verify scan results on test systems before production rollout
Breaking Changes

21 SQL Server 2016 StigIDs have been consolidated by DISA. Historical scan results referencing removed StigIDs will no longer have corresponding StigDetail records. Update any custom reports or queries that reference the removed StigIDs.

Support

For questions or issues related to this release: