Application and Change Control 9.0.1 Hotfix 1 Release Notes

Prev Next

This hotfix contains new features and resolved issues.

Release date — November 14, 2025

Release build: TACC Extension — 9.0.1.84

Rating

The rating defines the urgency for installing this hotfix.

This release is mandatory for all environments. Failure to apply mandatory hotfixes might result in a security breach. Mandatory hotfixes resolve vulnerabilities that might affect product functionality and compromise security. You must apply these hotfixes to maintain a viable and supported product.


What’s new or changed

Automatic provisioning for existing tenants—This release introduces automatic provisioning for existing customers who purchase a Trellix Application and Change Control (TACC) license. Previously, these tenants would not receive a standard provisioning notification. This enhancement ensures a seamless activation experience for existing customers, adding TACC to their subscriptions.


Resolved issues

This hotfix addresses customer-reported issues.

For a list of current known issues, see Application Control 9.x Known Issues (000014345).

Reference

Resolution

MACC-14527

Resolved an intermittent issue where tenant data was not visible in the console after an extension upgrade or a plugin reload. The authentication cache is now reset for the affected tenant to prevent data loss and restore visibility.

MACC-14932

Resolved an issue where Application and Change Control (Solidcore) event properties were incorrectly displayed as available filters on the Automatic Response page. These properties are no longer visible when configuring a new automatic response.

MACC-15567

Resolved an issue by updating multiple third-party components used by the TACC service to address potential security and license risks. Components such as Apache Commons Collections, H2 Database Engine, SnakeYAML, and others have been updated to newer versions.

MACC-15568

Resolved an issue by updating multiple third-party components within the reputation service to address potential security and license risks. These updates eliminated all identified high-severity security and license risks and significantly reduced the number of medium-severity risks.

MACC-15569

Resolved an issue by modifying third-party components within the event parser service to address potential security and license risks. Following these modifications, the number of high-severity security risks was reduced from two to zero, and high-severity license risks were reduced from one to zero.

Installation instructions

For information about installing or upgrading Application and Change Control software, see Trellix Application and Change Control 9.0.x Product Guide.