Skip to content

2026-09 Hotfix Release Notes#

This month's Hotfix release includes the following fixes. If you have any questions about the release contents, please contact our support desk.

2026-09-10 Release Notes#

Fixed a bug where the version and CPE were not updated when re-registering software registered in CSV format#

This fix does not require a scanner update

This bug was on the FutureVuls (server) side, so you do not need to update your scanner or rescan.

When you registered software in CSV format, assigned a CPE by specifying a vendor name and product name, and then re-registered a CSV with the same product name, the following occurred:

  • First re-registration: No error, but the version and CPE were not updated
  • Second and subsequent re-registrations: The error CPEの形式が誤っています (The CPE format is invalid) occurred, and none of the software in the CSV was registered

During this time, vulnerabilities for the affected software continued to be detected using the CPE of the old version.

Software to which a CPE was assigned by directly specifying the CPE string is not affected.

Affected Customers#

Customers who performed all of the following operations are affected.

  1. Registered software in CSV format
  2. Assigned a CPE to that software by specifying a vendor name and product name (for example, via bulk assignment)
  3. Re-registered a CSV with the same product name

What Was Fixed#

When you re-register a CSV with the same product name, the version of the existing software is now updated, and the assigned CPE follows the new version. Because the existing software is updated, the detected vulnerabilities and tasks are carried over.

How to Apply the Fix#

This fix has been applied on the FutureVuls side, so no special action is required on your part. If a CSV previously failed to register, registering it again will update the version and CPE.

If the same error still occurs after this fix, delete the CPE assigned to the affected software, register the CSV again, and then assign the CPE again. Deleting the assignment also deletes the vulnerability and task information detected with that CPE.