Version 2.18.6 (July 2026)
Version 2.18.6 (July 2026)
Welcome to the Zowe Version 2.18.6 release!
See New features and enhancements for a full list of changes to the functionality. See Bug fixes for a list of issues addressed in this release.
Download v2.18.6 build: Want to try new features as soon as possible? You can download the v2.18.6 build from Zowe.org.
New features and enhancements​
Zowe Version 2.18.6 contains the enhancements that are described in the following topics.
Zowe CLI​
Zowe CLI Imperative Framework​
- Added
isSubPath,containsBacktrack, andevaluatesToDirhelper functions to theIOclass. (#2741)
Bug fixes​
Zowe Version 2.18.6 contains the bug fixes that are described in the following topics.
Zowe CLI​
Zowe CLI (Core)​
-
Updated the
zowe zos-files ds editcommand to store temp files in a dedicated subdirectory with owner-only permissions (0o700). (#2773) -
Added extra filesystem checks when downloading configuration files with the
zowe config importcommand. (#2741) -
Added extra filesystem checks when downloading data sets and USS files. (#2741)
-
Added extra filesystem checks when downloading job spool. (#2741)
-
Breaking Updated the
zowe zos-files (ds/uss) editcommand to prompt the user to trust custom editors. (#2742) -
Restricted access to daemon-related files and directories to only the current user on all platforms. The daemon directory,
~/.zowe/bindirectory, the extracted native executable, the daemon PID file, and the Unix domain socket are now given owner-only permissions (0o700/0o600on POSIX, owner-only ACL on Windows) to prevent other local users from accessing them. The daemon directory, the~/.zowe/bindirectory, and the native executable inside it are also re-restricted when they already exist, so that artifacts created before this fix with looser permissions are corrected on the nextzowe daemon enableorzowe daemon restart. (#2743) -
Updated the
lodash,brace-expansion, anddiffdependencies to resolve technical currency. (#2711) -
Updated the
picomatch,brace-expansion,flatted,handlebars, andtardependencies to resolve technical currency. (#2707) -
Updated the
tar,minimatch,flatted, andunderscoredependencies to resolve technical currency. (#2701)
Zowe CLI Imperative Framework​
- Added the
base64EncodedAuthsession property to the list of session properties redacted from Imperative debug logs. (#2780) - Removed environment variables from the log messages produced when an exception is caught during Imperative.init. (#2765)
- Placed
imperative_debug.loginto the Zowe Home directory's logs subdirectory (or as a fallback into the user's home directory), instead of the current directory. (#2765) - Reduced the encoding of URIs to the minimum that still allows Zowe SDK operations to work successfully in the current z/OS environment. (#2750)
- Updated the
WebDiffManagerclass'sopenDiffsfunction to better process input data. (#2770) - Added extra filesystem checks when downloading configuration files with the
zowe config importcommand. (#2741) - Updated the
lodash,brace-expansion, anddiffdependencies to resolve technical currency. (#2711) - Updated the
jsonschema,qs, andmarkdown-itdependencies for technical currency. (#2680)
DB2 Plug-in for Zowe CLI​
- Updated the
axiosdependency for technical currency. (#204) - Updated the
lodashdependency for technical currency. (#200) - Updated the
axiosandlodashdependencies for technical currency. (#197)
MQ Plug-in for Zowe CLI​
- Breaking: Changed the default value of the
--reject-unauthorized(--ru) option fromfalsetotrue, so server certificates are validated by default. Connections to endpoints with self-signed or otherwise untrusted certificates now fail unless you explicitly opt out with--reject-unauthorized false. (#128) - Breaking: Changed the default value of the
--protocoloption fromhttptohttps, so connections are encrypted by default. Endpoints that only serve plaintext HTTP now require you to explicitly set--protocol http. (#128) - Added missing npm-shrinkwrap.
Zowe Explorer​
Zowe Explorer (Core)​
- See the Zowe Explorer changelog for updates included in this release.
Zowe Explorer API​
- See the Zowe Explorer API changelog for updates included in this release.
Zowe Explorer for IBM z/OS FTP​
- See the Zowe® Explorer for IBM® z/OS® FTP changelog for updates included in this release.
Zowe Explorer ESLint Plug-in​
- See the Zowe Explorer ESLint Plug-in changelog for updates included in this release.
Vulnerabilities fixed​
Zowe discloses fixed vulnerabilities in a timely manner giving you sufficient time to plan your upgrades. Zowe does not disclose the vulnerabilities fixed in the latest release as we respect the need for at least 45 days to decide when and how you upgrade Zowe. When a new release is published, Zowe publishes the vulnerabilities fixed in the previous release. For more information about the Zowe security policy, see the Security page on the Zowe website.
The following security issues were fixed by the Zowe security group in version 2.18.5:
- CVE-2025-48976 (BDSA-2025-5248)
- CVE-2026-23907 (BDSA-2026-3678)
- CVE-2026-24734 (BDSA-2026-2348)
- CVE-2025-58754 (BDSA-2025-11547)
- CVE-2026-25639 (BDSA-2026-1821)
- CVE-2026-2739 (BDSA-2026-2722)
- BDSA-2025-7426 (CVE-2025-7783)
- BDSA-2026-3570 (CVE-2026-29063)
- BDSA-2026-5762
- BDSA-2025-42323 (CVE-2025-66453)
- CVE-2025-67735 (BDSA-2025-62789)
- CVE-2026-33870 (BDSA-2026-5656)
- CVE-2026-33871 (BDSA-2026-5659)
- CVE-2025-7339 (BDSA-2024-10785)
- CVE-2025-15284 (BDSA-2025-87749)
- CVE-2026-2391 (BDSA-2026-1885)
- CVE-2025-56200
- CVE-2025-12758 (BDSA-2025-35151)