HCL BigFix is pleased to announce some enhancements to BigFix Remote Control.
Web Based Controller support for Unattended Sessions
This release introduces Web Controller support for unattended sessions. Operators can now start active or monitor unattended sessions directly from a browser via the Remote Control Lite Web Portal (LWP). The Web Controller currently has limited functionality compared to the standalone application, and we plan to add features in future releases.
Redesigned Lite Web Portal Homepage
The Lite Web Portal now features a completely redesigned homepage for an improved user experience.
REST API Support for Unattended Sessions
The Web Session Validation REST API now returns the loginURI required to establish an unattended session from the Lite Web Portal using the Web Controller.
New Fixlet to repair the duplicate GUID issue
new Fixlets are now available to force the Remote Control Target to generate a new Target GUID:
- 420 - Generate new GUID for Windows Targets
- 421 - Generate new GUID for Linux Targets
- 422 - Generate new GUID for macOS Targets
Update of IBM WAS Liberty, IBM Java, and OpenSSL
This release includes the following updates:
- Open Liberty version is 26.0.0.5
- Semeru Java version is 25.0.3.0
- OpenSSL version is 3.5.7
**Known limitation on SSO**
Starting from Remote Control Server version 10.1 FP6, due to an Open Liberty limitation, if SSO is enabled, a new server.env file must be manually created after a fresh install or upgrade.
(https://openliberty.io/blog/2026/04/21/26.0.0.4.html#ltpa)
- Path: [server_installation_path]/wlp/usr/servers/trcserver
- Content: keystore_password=<strong_password>
SSO can be used after restarting the Server service. This file avoids the CWWKS4118E: LTPA configuration error.
**Fixed vulnerabilities**
This release addresses the following vulnerabilities:
- CVE-2026-42579 related to Netty.
- CVE-2026-42581 related to Netty.
- CVE-2026-42584 related to Netty.
- CVE-2026-42585 related to Netty.
- CVE-2026-42587 related to Netty.
- CVE-2026-45674 related to Netty.
- CVE-2026-47691 related to Netty.
- CVE-2026-45416 related to Netty.
- CVE-2026-44249 related to Netty.
Affected component: Remote Control Server.
Affected version: Remote Control version 10.1.0 FP5 and earlier.
**Resolved Defect Articles:**
KB0131692 - Pull file feature is not working during an Active session
KB0131683 - DOC: Update the Broker Certificate page to include information about the new Client/Server Authentication policies
KB0131586 - DOC: Update the procedure to enable the Controller logs
KB0131648 - DOC: Change the Certificate Management section for CA signed certificate to remove ikeyman tool references
KB0130633 - SAN Certificate for Remote Control not working
KB0130622 - Controller port value is -1 on controller main panel, ignoring the default controller port property
KB0129960 - Add an error in the Remote Control Broker log when the certificate lacks TLS Web Client Authentication.
KB0130183 - DOC: Adding a certificate to the truststore
KB0129946 - Broker Session Collaboration URL for broker session refers to serverURL
KB0131286 - Controller: Scaled view is broken when Screen Scaling is applied
KB0127575 – DOC: Add documentation related to the backup of the DB instance before Server update
**Database deprecation**
Oracle Database is now deprecated as a supported backend for the BigFix Remote Control Server. Support will be fully removed in the March 2027 release. This decision is part of our ongoing effort to streamline the BigFix Remote Control product and focus support resources on database platforms that best serve our customer base.
Deprecation effective: immediately
Support removal: March 2027 release
We strongly recommend that affected customers plan and execute a migration to one of the supported database backends before the March 2027 release
If you have questions or concerns, please reach out to HCL Support.
**Published site version:**
Remote Control, site version 85 (Build Number 10.1.0.0630)
With kind regards,
The BigFix Remote Control Team