StigSanctum Logo
StigSanctum
Release Notes
Q2 2026 | April 2026

Q2 2026 Release Notes

This release incorporates the latest DISA STIG updates from the April 2026 quarterly release cycle and adds the newly released STIG benchmarks: Microsoft Windows Server 2025 and Red Hat Enterprise Linux 10.

112
StigID Updates
22
Benchmark Updates
2
New Benchmarks
15
Severity Changes

New Benchmarks

Microsoft Windows Server 2025 - V1R1

Initial Release

DISA published the initial Windows Server 2025 STIG on 26 January 2026.

Red Hat Enterprise Linux 10 - V1R1

Initial Release

DISA published the initial RHEL 10 STIG on 26 February 2026.

DISA STIG Updates (April 2026)

The following summarizes key changes from DISA's quarterly STIG release dated 01 April 2026.

RHEL 8 - V2R7

Severity Upgrades (CAT II → CAT I)

DISA elevated SSH FIPS, BIND FIPS, and IPsec FIPS requirements to CAT I: RHEL-08-010275, RHEL-08-010280, RHEL-08-010290, RHEL-08-010291, RHEL-08-010296, RHEL-08-010297.

Key Changes

RHEL 9 - V2R8

Severity Upgrades (CAT II → CAT I)

SSH MACs/Ciphers, IPsec FIPS, BIND, and crypto-policies STIGs elevated to CAT I: RHEL-09-215100, RHEL-09-215105, RHEL-09-255064, RHEL-09-255065, RHEL-09-255070, RHEL-09-255075, RHEL-09-671020, RHEL-09-672050.

Key Changes

Canonical Ubuntu 22.04 LTS - V2R8

Key Changes

Canonical Ubuntu 24.04 LTS - V1R5

Key Changes

Cisco IOS Router/Switch & IOS-XE Router/Switch NDM - V3R6 / V3R7

Key Changes

Cisco IOS-XR Router NDM - V3R6

Key Changes

Microsoft Defender Antivirus - V2R8

Key Changes

Microsoft Windows 11 - V2R7 / Server 2019 - V3R8 / Server 2022 - V2R8

Key Changes

MS SQL Server 2016 V3R5 / SQL Server 2022 Database V1R3 / Instance V1R4

Key Changes

Microsoft Windows Server DNS - V2R4

Key Changes

StigSanctum Script Updates

The following scripts were updated to align with revised DISA CheckContent procedures:

Windows DNS Private Key Permissions Check

Affected STIGs: WDNS-22-000039

Change: Updated to scan the narrowed DNSSEC private key folder per revised DISA guidance. Recursive permission check covers subfolders and files. Findings raised when any non-administrative principal has greater than read access.

Cisco Redundant Authentication Servers Check

Affected STIGs: CISC-ND-001370

Change: Updated to recognize named authentication lists (in addition to the prior default-list check) per revised DISA guidance. Matches DISA's updated example syntax for redundant AAA server configuration.

RHEL FIPS Mode Verification

Affected STIGs: RHEL-09-671010

Change: Updated to use DISA's revised single-line FIPS verification command for faster, more reliable validation across RHEL 9 systems.

Additional DISA Changes Reviewed

The following DISA changes were reviewed and confirmed that existing StigSanctum scan logic already handles the updated requirements correctly. No scan updates were needed:

Repository Improvements

Recent development activity and platform enhancements since Q1:

Web Dashboard
Remediation Engine Expansion
Trial Product Build

Upgrade Instructions

Upgrade Steps
  1. Back up your StigSanctum database
  2. Run the installer and select the Upgrade option
  3. Update the StigSanctum PowerShell module on any remote scan servers
  4. Verify scan results on test systems before production rollout
Severity Reclassifications

14 RHEL FIPS and crypto-policy STIGs were upgraded from CAT II to CAT I, and 1 was downgraded from CAT I to CAT II. Findings against these StigIDs from prior scans retain their historical severity in scan history; the new severity applies to scans run after this upgrade.

Support

For questions or issues related to this release: