Skip to main content
Version: v3.1.x LTS

Version 2.18.6 (July 2026)

Version 2.18.6 (July 2026)

Welcome to the Zowe Version 2.18.6 release!

See New features and enhancements for a full list of changes to the functionality. See Bug fixes for a list of issues addressed in this release.

Download v2.18.6 build: Want to try new features as soon as possible? You can download the v2.18.6 build from Zowe.org.

New features and enhancements​

Zowe Version 2.18.6 contains the enhancements that are described in the following topics.

Zowe CLI​

Zowe CLI Imperative Framework​

  • Added isSubPath, containsBacktrack, and evaluatesToDir helper functions to the IO class. (#2741)

Bug fixes​

Zowe Version 2.18.6 contains the bug fixes that are described in the following topics.

Zowe CLI​

Zowe CLI (Core)​

  • Updated the zowe zos-files ds edit command to store temp files in a dedicated subdirectory with owner-only permissions (0o700). (#2773)

  • Added extra filesystem checks when downloading configuration files with the zowe config import command. (#2741)

  • Added extra filesystem checks when downloading data sets and USS files. (#2741)

  • Added extra filesystem checks when downloading job spool. (#2741)

  • Breaking Updated the zowe zos-files (ds/uss) edit command to prompt the user to trust custom editors. (#2742)

  • Restricted access to daemon-related files and directories to only the current user on all platforms. The daemon directory, ~/.zowe/bin directory, the extracted native executable, the daemon PID file, and the Unix domain socket are now given owner-only permissions (0o700/0o600 on POSIX, owner-only ACL on Windows) to prevent other local users from accessing them. The daemon directory, the ~/.zowe/bin directory, and the native executable inside it are also re-restricted when they already exist, so that artifacts created before this fix with looser permissions are corrected on the next zowe daemon enable or zowe daemon restart. (#2743)

  • Updated the lodash, brace-expansion, and diff dependencies to resolve technical currency. (#2711)

  • Updated the picomatch, brace-expansion, flatted, handlebars, and tar dependencies to resolve technical currency. (#2707)

  • Updated the tar, minimatch, flatted, and underscore dependencies to resolve technical currency. (#2701)

Zowe CLI Imperative Framework​

  • Added the base64EncodedAuth session property to the list of session properties redacted from Imperative debug logs. (#2780)
  • Removed environment variables from the log messages produced when an exception is caught during Imperative.init. (#2765)
  • Placed imperative_debug.log into the Zowe Home directory's logs subdirectory (or as a fallback into the user's home directory), instead of the current directory. (#2765)
  • Reduced the encoding of URIs to the minimum that still allows Zowe SDK operations to work successfully in the current z/OS environment. (#2750)
  • Updated the WebDiffManager class's openDiffs function to better process input data. (#2770)
  • Added extra filesystem checks when downloading configuration files with the zowe config import command. (#2741)
  • Updated the lodash, brace-expansion, and diff dependencies to resolve technical currency. (#2711)
  • Updated the jsonschema, qs, and markdown-it dependencies for technical currency. (#2680)

DB2 Plug-in for Zowe CLI​

  • Updated the axios dependency for technical currency. (#204)
  • Updated the lodash dependency for technical currency. (#200)
  • Updated the axios and lodash dependencies for technical currency. (#197)

MQ Plug-in for Zowe CLI​

  • Breaking: Changed the default value of the --reject-unauthorized (--ru) option from false to true, so server certificates are validated by default. Connections to endpoints with self-signed or otherwise untrusted certificates now fail unless you explicitly opt out with --reject-unauthorized false. (#128)
  • Breaking: Changed the default value of the --protocol option from http to https, so connections are encrypted by default. Endpoints that only serve plaintext HTTP now require you to explicitly set --protocol http. (#128)
  • Added missing npm-shrinkwrap.

Zowe Explorer​

Zowe Explorer (Core)​

  • See the Zowe Explorer changelog for updates included in this release.

Zowe Explorer API​

Zowe Explorer for IBM z/OS FTP​

Zowe Explorer ESLint Plug-in​

Vulnerabilities fixed​

Zowe discloses fixed vulnerabilities in a timely manner giving you sufficient time to plan your upgrades. Zowe does not disclose the vulnerabilities fixed in the latest release as we respect the need for at least 45 days to decide when and how you upgrade Zowe. When a new release is published, Zowe publishes the vulnerabilities fixed in the previous release. For more information about the Zowe security policy, see the Security page on the Zowe website.

The following security issues were fixed by the Zowe security group in version 2.18.5:

  • CVE-2025-48976 (BDSA-2025-5248)
  • CVE-2026-23907 (BDSA-2026-3678)
  • CVE-2026-24734 (BDSA-2026-2348)
  • CVE-2025-58754 (BDSA-2025-11547)
  • CVE-2026-25639 (BDSA-2026-1821)
  • CVE-2026-2739 (BDSA-2026-2722)
  • BDSA-2025-7426 (CVE-2025-7783)
  • BDSA-2026-3570 (CVE-2026-29063)
  • BDSA-2026-5762
  • BDSA-2025-42323 (CVE-2025-66453)
  • CVE-2025-67735 (BDSA-2025-62789)
  • CVE-2026-33870 (BDSA-2026-5656)
  • CVE-2026-33871 (BDSA-2026-5659)
  • CVE-2025-7339 (BDSA-2024-10785)
  • CVE-2025-15284 (BDSA-2025-87749)
  • CVE-2026-2391 (BDSA-2026-1885)
  • CVE-2025-56200
  • CVE-2025-12758 (BDSA-2025-35151)