A new version of the Patch Management Engine is being made available to N-central and N-sight. This release focuses on improving patch reliability, handling of Microsoft update formats, cache management, and overall resilience of patch detection and installation workflows.
Improvements Included
- Improved handling of Microsoft patch file types and metadata accuracy: Resolves an issue where incorrect patch file types could be selected when multiple formats (e.g., MSU, CAB, EXE) were available. This improves reliability of patch installation and reduces mismatches in patch delivery. (PMCM-10657)
- Improved resilience of patch scans under error conditions: Enhancements to error handling improve the stability of patch detection and scanning, particularly in environments where Windows Update or network-related issues occur. (PMCM-11330, PMCM-11357, PMCM-11360)
- Updated bundled components for improved security: Replaces the version of 7-Zip used by the Third-Party Patch engine with the latest version, addressing known vulnerabilities. (PMCM-11413)
- Increased cache capacity for large patch downloads: Increases the File Cache Service Agent (FCSA) cache size to better handle larger updates, such as recent Microsoft Cumulative Updates, improving reliability when multiple large patches are required. (PMCM-11497)
- Improvements in gathering install dates during PME detection scans (PMCM-11456). NOTE: we rely on the device to inform us when a patch was installed. We still cannot guarantee install dates for every patch – this has always been the case – but we are improving this situation by resolving an issue where WMI does make this data available and we did not use it.
- Improve installation status reporting around Feature Updates (PMCM-11306)
- Improved software signing to reduce security tool interference: PME artifacts are now signed using Extended Validation (EV) certificates, reducing the likelihood of false positives from endpoint protection and application control tools.



You must be logged in to post a comment.