The VSA 9.5.27 feature release (build 9.5.27.7592) includes enhancements and fixes described in the following sections. For minimum system and agent requirements, refer to Kaseya Server Minimum Requirements & Configuration and Agent Minimum Requirements.
Release schedule
- SaaS deployment started: Saturday, August 8, 2026
- SaaS deployment completed: Saturday, August 22, 2026
- General Availability (on-premises customers): Thursday, August 27, 2026
Note: SaaS customers will be informed of their maintenance window via status.kaseya.com.
Dates are subject to change at short notice. On-premises customers are advised to check this page again before attempting an upgrade.
Last Update: August 5, 2026: Published.
Important security update
This release includes important security updates. We recommend that on-premises customers upgrade as soon as possible after the General Availability (GA) release date. (No action is required for SaaS customers, as updates are automatically applied).
Dependencies
| Agent |
This release requires agent version 9.5.0.52. After upgrading from an earlier VSA version, you must update your Windows, macOS, and Linux agents using the automatic or manual update process from the agent module.
Note: this version cannot be installed
to some End-of-Life macOS versions. Please reference
the "Updates to macOS and Linux agent supported versions"
section below for further details.
|
| Live Connect Application | When starting a Live Connect or Remote Control session for the first time after installing this release, you will be prompted with a link to download the latest Live Connect build. You must complete the installation before proceeding with the session. |
| Software Management |
This release includes updates to the Software Management client code. Each managed machine will download 120 MB of file updates during the first patch scan or deployment cycle after installing the VSA update. The files will be sourced from the VSA server or a peer endpoint machine on the local network that already has the files. Recommendations to mitigate the impact on network bandwidth:
|
Support policy for prior releases
Kaseya recommends that customers update their environments to the latest patch release as soon as possible after the GA release date.
Our policy is to provide support for the current GA release, one prior Feature Release, and any interim Maintenance Releases. After the 9.5.27 GA date stated in the release schedule, the minimum supported version will be the 9.5.26 Feature Release.
Product lifecycle updates
FIPS 140-3 Enablement and Security Enhancements
VSA 9.5.27 introduces foundational support for FIPS 140-3 compliant communications, including a new FIPS-enabled communication architecture, enhanced certificate validation capabilities, updated cryptographic components, and improved security controls for both server and agent communications.
The release is designed to help customers meet modern security and compliance requirements while providing tooling to simplify migration to FIPS-compliant environments.
For on-premises customers, upgrading to VSA 9.5.27 makes your environment FIPS 140-3 ready. However, to achieve full FIPS 140-3 compliance, the TLS 1.2 Extended Master Secret (EMS) setting must also be enabled in the FIPS Edge configuration file.
For Kaseya-hosted (Cloud) customers, this setting will be enabled automatically before the September 21st, 2026 retirement of FIPS 140-2, requiring no additional action on your part.
To stay informed of maintenance activities and rollout updates, subscribe to the Kaseya Status Page: Kaseya
New Kaseya FIPS Edge Service
VSA 9.5.27 introduces the new Kaseya FIPS Edge Service, which sits in front of the existing VSA Edge Service and assumes responsibility for TLS communications and FIPS-compliant cryptographic operations. This architecture enables the existing Edge Service to continue handling application-specific functionality while the FIPS Edge Service ensures that all cryptographic processing and secure communications adhere to FIPS 140-3 requirements.
Key Capabilities
- TLS termination performed through the FIPS Edge Service.
- Dedicated configuration file and logging framework.
- Support for IPv4 and IPv6 communications.
- Enhanced visibility into FIPS initialization and TLS processing through service logs.
Note: Certain customized settings, if used in the Edge Service configuration file, will be automatically relocated to the FIPS Edge Service during the upgrade process.
Note: The new service introduces a modest increase in resource consumption. During validation testing, Kaseya observed approximately 7% higher CPU usage and 10% higher memory utilization compared to previous versions.
Automated Certificate Repackaging
A new certificate repackaging workflow has been introduced in the installer. Many existing certificates remain cryptographically secure but may not use FIPS 140-3 approved package algorithms. VSA 9.5.27 now detects these certificates during installation and provides remediation options.
New Functionality
- Automatic repackaging of certificate packages.
- Validation of newly created certificate package.
- Preservation of certificate functionality.
- Automatic backup of the original certificate before modification.
Agent Security Enhancements
Agent communications have been updated to support the new FIPS 140-3 architecture.
Note: Administrators may observe larger installation packages due to the inclusion of additional OpenSSL and migration components.
Important: All agents must be upgraded to a compatible version before TLS 1.2 Extended Master Secret (EMS) is enabled. Agents that have not been upgraded will be unable to connect once EMS is enforced.
For Cloud customers, Kaseya will communicate the planned enablement date through the Kaseya Status Page. Please subscribe to receive the latest updates and maintenance notifications.
Important Upgrade Considerations
Legacy Agents
Enabling EMS before all agents are upgraded may result in connectivity issues for older agents that do not meet the new cryptographic requirements.
Legacy Integrations
Customers should validate third-party integrations, custom applications, browsers, and API clients before enabling EMS, particularly when these systems rely on older operating systems or cryptographic libraries.
Saved Installers
Older installer packages retained from previous releases may not function correctly in environments upgraded to 9.5.27. Customers should use current installation packages after upgrading.
Backup and Restore Considerations
Customers should not restore pre-9.5.27 Edge configuration files following upgrade.
Restoring older Edge configuration files may introduce configuration conflicts, incorrect listening ports, and service startup failures.
Removal of support for SUSE Linux Enterprise Server 12.5
SUSE Linux Enterprise Server 12.5 is no longer supported as of this release.
3rd-Party Software 2.0: August updates
No notable updates
Refer to VSA 9 Software Management application catalog.
Bug fixes and other improvements
Installers
- A new button was added to the KInstall interface to allow certificate repackaging when a non-FIPS 140-3 certificate is detected, or the PFX file needs to be repackaged.
- Created a "Fix-it" step to include a check for port 18087 which is used by Kaseya Edge Services and the FIPS Edge Proxy.
Kaseya FIPS proxy
- A new FIPS 140-3 Edge proxy service has been added in front of the existing Kaseya Edge Service.
Monitoring
- Fixed false positive alerts generated by the web server check in external monitoring for VSA, with recent updates improving the agent’s working directory handling. The current fix only applies to new monitors created after deployment.