Overview
This article lists all available hot fixes and patches for ProfileUnity with FlexApp, organized by release. The current supported release is 6.9.5. Customers on older releases are encouraged to upgrade; versions at End of Life receive no further fixes.
Supported versions reflect the minimum build required. For OS compatibility refer to the ProfileUnity Client Side OS Support Matrix. For component build numbers by version see the ProfileUnity Version Matrix.
Every GA and hot fix release is inventoried in the ProfileUnity with FlexApp — Third-Party & Open Source Software Inventory, which publishes a per-release list of the CVEs resolved — enumerated by CVE identifier and by the component whose update addressed them — alongside the component list and the CycloneDX 1.6 SBOM. Refer to that article when you need to confirm which vulnerabilities a given hot fix remediates.
| Contents | |
|
› Latest Patches — 6.9.5 CURRENT RELEASE |
MongoDB Update Tool — Mongo 7.0.41 .NET Core Runtimes — .NET Core 10.0.12 | 8.0.31 Client Tools — 6.9.5 HF3 Management Console — 6.9.5 HF3 FlexApp One and Packaging Console — 6.9.5.9750 |
| › Older Releases |
6.8.7 R2 EXTENDED SUPPORT — Client HF4 | HF3 | HF2 | HF1 Console HF2 | HF1 6.8.7 R1 EXTENDED SUPPORT — Client HF3 | HF2 | HF1 Console HF1 6.8.6 GA & R1 LIMITED SUPPORT — Client HF3 | HF2 | HF1 6.8.5 EOL — Client HF7 (latest on file) 6.8.4 and Earlier EOL — Contact Support for archived files |
| › End of Life Versions | Full EOL version list with support end dates |
Latest Patches — 6.9.5
MongoDB Update Tool
| Mongo 7.0.41 Updated 9-15-26 • Release Notes | |
|
Download Choose by your Console version |
ProfileUnity 6.9.5 and aboveProfileUnity.Mongo.Setup_7.0.41.exe ChecksumsMD5
04aece48d32c5b6c02ab0c89306cf90aSHA256
eccc979ad47096ba9d370069719df170c37c8c632c71db768ba046060860fac8
ProfileUnity 6.8.7 R2 and belowProfileUnity.Mongo.Setup_7.0.41.exe ChecksumsMD5
f4788a4c560b6ace4f6aa16f4a545dd1SHA256
b18a3dc36461540bbd0fa4be274d35af07b4938003fdf3e7cc38d5c9500f2249
|
| Fixes & Changes |
|
| Upgrade Instructions: See Upgrade to Mongo 5.0.32/7.0.28 and Above Using Mongo Update Tool | |
.NET Core Runtimes
| .NET Core Runtimes Updated 9-15-26 | |
|
Download Choose by your ProfileUnity version |
ProfileUnity 6.9.5 EditionProfileUnity 6.8.7 Editions |
| Changes |
|
Client Tools — 6.9.5
| Client HF3 (6.9.5.9750) Updated 9-15-26 | |
| Download |
Console deployment package ChecksumsMD5
e553bcb330f398421ba5b7673a9abf27SHA256
3ea0187089d640ca0a4a0adaaecfd5166c762c122c74d2d210997f2eca99ec30
NOTE: Review the README.txt for full installation details.
Standalone client installers ProfileUnityClient.Setup_6.9.5hf3.exe ChecksumsMD5
8fe529d34a99a150ac6496d18f9d3160SHA256
e1536f2971ba28b3e5643ad2fe0f5f1a1d38afd14feed07a15e04d99e6737e84
ProfileUnityClient.Setup_6.9.5hf3.msi ChecksumsMD5
0fb8718a308ee2ac55debf5da7d1bf0dSHA256
0be6f90786a936e8a4d559f5731d3124f61c254d197946ea3ac2b07ae6bdb3ca
KNOWN ISSUE — Start Menu Fails on ProfileDisks Created by HF2 or HF3: On HF2 and HF3, the Windows Start Menu does not open for a user whose ProfileDisk has just been created. New users and any existing user whose ProfileDisk is recreated are affected; ProfileDisks created by an earlier build are not. See Start Menu Does Not Open on a Newly Created ProfileDisk with ProfileUnity 6.9.5 HF2 & HF3 for symptoms, confirmation steps, and an interim workaround. Fix expected in HF4.
|
| Fixes & Changes |
|
Client HF2 (6.9.5.9721) SUPERSEDED BY HF3
▼ Show
Superseded by HF3, which is cumulative and includes every fix listed here.
Client HF2 (6.9.5.9721) — 9-1-26
- Updated 7-Zip to 26.2
- Updated .NET Core to 10.0.11
- Updated the FlexApp filter driver to the 2024 GA version for improved performance and stability
- Resolved an issue where new files and folders could not be created in a FlexApp package's protected directories even though the granted permissions were applied
- Resolved an issue where a failed AD group enumeration left an incomplete cache that persisted until the cache was cleared or a full enumeration succeeded
- Resolved an issue where a Drive Mapping rule failed before the credentials defined in the rule were applied when the user lacked access to the target path
- Resolved an issue where Application Restriction rules did not match folder names beginning with a dot
- Resolved an issue where Application Restriction policies were skipped when an installer candidate failed elevation
- Resolved an issue where Application Restriction candidates were re-hashed for every hash rule, delaying enforcement on large or UNC binaries; the candidate is now hashed once
- Resolved an issue where a user could open and edit their own Application Restriction policy (.pol) file
- Removed default whitelist hashes for legacy tools that are no longer shipped and updated the stale
rsync.exehash - Resolved an issue where an upgrade run as SYSTEM reported success but did not install when an existing
LwL.ProfileUnity.Client.Startup.Update.exe.configremained inC:\Windows\Temp
Client HF1 (6.9.5.9678) SUPERSEDED BY HF2
▼ Show
Superseded by HF2, which is cumulative and includes every fix listed here.
Client HF1 (6.9.5.9678) — 7-2-26
- Updated 7-Zip to 26.1
- Resolved an issue where SID-scoped cache tokens weren't matched by suffix at logoff, leaving FileCache token files uncleaned
- Resolved an issue where app modules called by triggers could run their logoff more than once
- Resolved an issue where an incomplete AD group list could be cached and used by Filters
- Resolved an issue where Application Restrictions generated spurious policy directory notifications during staging file promotion
- Resolved an issue where Application Restrictions policy mode incorrectly switched from blacklist to whitelist when the default whitelist rules were the only Allow rules present
- Resolved an issue where client failed to remove duplicate entries for Application Restriction policies with escaped special characters
- Resolved an issue where running startup/update exe as SYSTEM user wiped the
C:\Windows\Tempfolder - Resolved an issue with FlexApp Shortcut Validation vs. CAP Playback timing
- Resolved an issue where CmdService stopped firing
- Resolved an issue where a license check was performed during engine deactivation of FlexApp One packages
ProfileUnity & FlexApp Management Console — 6.9.5
| Console HF3 (6.9.5.9750) Updated 9-15-26 | |
| Download |
ProfileUnityConsole_6.9.5-HF3.zip ChecksumsMD5
1aba2c779242da5d0d418457b3337e0aSHA256
30090d50c0ba088158c8e82aa9079adee579205cb097db60a0060fa7d35c953b
NOTE: Review the README.txt for full installation details.
|
| Fixes & Changes |
|
| Prerequisite: This hot fix applies only to Console 6.9.5. If your Console is not yet running 6.9.5, upgrade to that release before applying this hot fix. | |
Console HF2 (6.9.5.9721) SUPERSEDED BY HF3
▼ Show
Superseded by HF3, which is cumulative and includes every fix listed here.
Console HF2 (6.9.5.9721) — 8-14-26
- Updated 7-Zip to 26.0.2
- Updated MailKit, MimeKit and SharpCompress to address reported security vulnerabilities
- Updated Microsoft.OpenApi in the Console and License Server to address a reported security vulnerability
- Updated chart.js and moment.js to address reported security vulnerabilities
- Fixed an issue where Console logon failed for users with an alternate UPN suffix, including lookups across trusted forests
- Fixed an issue with logon resolution and domain stamping in large and multi-domain Active Directory environments
- Fixed an issue where AD domains were enumerated on every Console load; domains are now enumerated at service startup and served from a cached list, and the list still completes when a subdomain is unreachable
- Fixed an issue where adding a node to a cluster returned a 500 error on the added node's Console
- Fixed an issue where "Go to Stand-Alone" returned a node to standalone mode without removing it from the remaining cluster nodes
- Fixed an issue where Secure Banner text was displayed as plain text instead of HTML
- Fixed an issue where saving a Configuration with an App-V rule Action of "Remove All" returned an error and the Configuration was not saved
- Fixed an issue where
ProcessUtil.RetryProcess task create process returnedentries were not formatted correctly in the log
Console HF1 (6.9.5.9678) SUPERSEDED BY HF2
▼ Show
Superseded by HF2, which is cumulative and includes every fix listed here.
Console HF1 (6.9.5.9678) — 7-2-26
- Updated 7-Zip to 26.1
- Fixed an issue where CAC messages filled the ProU log when Debug is enabled
- Fixed an issue where Configuration PDF export was missing rule filter fields for User Defined Scripts
- Fixed an issue where Administrative Templates "Update ADM files" did not work
- Fixed an issue where larger configurations with retention would get a document size error
FlexApp One and Packaging Console — 6.9.5
| FlexApp (6.9.5.9750) Updated 9-15-26 | |
| Download |
FlexAppOneBundler_6.9.5.9750.zip ChecksumsMD5
63efd2ca0aed7842873cbfdd26336eabSHA256
60f6c223d0ebbee1f023fcc4f6e49787e0220ee77816b56d9a5c811340804790
FlexAppOnePackagingConsole_6.9.5.9750.exe ChecksumsMD5
827c59b441b905b80ec8cf4c337ada61SHA256
830e031d2d5f59f001980cd8e2c5760c8687bb3b0384901ba9ed7e0a4c3cb847
|
| Fixes & Changes |
|
FlexApp (6.9.5.9721) SUPERSEDED BY 6.9.5.9750
▼ Show
Superseded by 6.9.5.9750, which is cumulative and includes every fix listed here.
FlexApp (6.9.5.9721) — 9-1-26
- Resolved an issue where a FlexApp package written to a cloud location lost its
.fa1companion file — the child disk merge and cloud upload path stripped the.fa1from the uploaded package, affecting the create, clone, import, and extend workflows
FlexApp (6.9.5.9678) SUPERSEDED BY 6.9.5.9721
▼ Show
Superseded by 6.9.5.9721, which is cumulative and includes every fix listed here.
FlexApp (6.9.5.9678) — 7-2-26
- Resolved an issue where a license check was performed during the deactivation of FlexApp One engines
Older Releases
6.8.7 R2 (Build 6.8.7.9216) EXTENDED SUPPORT
▼ Show
Client Tools — Updated 9-18-25
client-tools_687-r2-hf4.zip | README.txt
R2 Client HF4 (6.8.7.9390) — 9-18-25
- .NET Core updated to 8.0.20; 7-Zip updated to 25.01
- Adds support for Windows 11 25H2 (10-07-25)
- Resolves an issue where ProfileDisk users may receive a temporary profile on persistent machines that are not regularly rebooted
R2 Client HF3 (6.8.7.9343) — 7-31-25
- .NET Core updated to 8.0.18; 7-Zip updated to 25.00
- Added configurable retries to FlexApp module when attempting to read remote package XML files
R2 Client HF2 (6.8.7.9309) — 6-27-25
- .NET Core updated to 8.0.17
- Added support for Omnissa Horizon 8 2412 (8.14) and 2503 ESB (8.15)
- Added support in FlexApp for capturing Black Ice ColorPlus and other printers with multiple, custom port names
- Resolved an issue with hung login.microsoftonline.com calls
- Resolved an issue in R2-HF1 with the default value for OfflineTestDnsEntry, now set to
%LOGONSERVER% - Resolved an issue with AD group Filter and offline logins caching incomplete AD group token
- Resolved an issue with AppData entries for on-boot, cloaked FlexApp assignments only replaying for the first user to login
- Resolved an issue reversing some FlexApp packages with Fonts that was preventing subsequent playbacks in persistent scenarios
R2 Client HF1 (6.8.7.9256) — 5-5-25
- .NET Core updated to 8.0.16; Updated FlexApp Filter Drivers (2024)
- Updated AppStream 2.0 Pre-warm Manifest for early EBS volume block hydration
- Resolved an issue where anti-virus scanning FlexApp paths can cause excess memory usage
- Resolved an issue relating to multi-threading FlexApp playbacks
- Resolved an issue bulk mounting FlexApp packages now allowing for faster mount times
- Resolved an issue handling malformed Entra ID Filter information that prevented Client from running
- Resolved an issue where Windows only returns a subset of an AD user's group memberships if the machine is offline and rebooted
- Added
VirtFsService.dll.configFlexApp settingProcessShortPaths— set toFalseto disable legacy 8.3 DOS paths for improved I/O efficiency
Lwl.ProfileUnity.Client.exe.config via OfflineTestDnsEntry. If using a laptop, set a DNS name resolvable only when on VPN, such as a Domain Controller.ProfileUnity Console — Updated 9-18-25
ProfileUnityConsole_6.8.7R2-HF2.zip | README.txt
R2 Console HF2 (6.8.7.9390) — 9-18-25
- Updates ProfileUnity Management Console to 6.8.7.9390 (9-16-25)
- Updated 7-Zip to 25.01
- Adds new
ProfileUnity.Host.exe.configoptionGetForestChildren— whenfalse, disables gathering child Domain information from other AD Forests. Enable if not seeing all Domains.
ProfileUnityConsole_6.8.7R2-HF1.zip | README.txt
R2 Console HF1 (6.8.7.9320) — 7-8-25
- Improves reliability of Active Directory-related communications
- Resolves an issue in 6.8.7.9216 (R2) preventing AVD App Attach sync process from completing
6.8.7 R1 (Build 6.8.7.9083) EXTENDED SUPPORT
▼ Show
Client Tools — Updated 01-15-25
client-tools_687-hf3.zip | README.txt
R1 Client HF3 (6.8.7.9146) — 01-15-25
- Resolves an issue in 6.8.7 affecting the execution of Shortcut Cleanup and AppV Module
- .NET Core updated to 8.0.12
R1 Client HF2 (6.8.7.9138)
- Resolves an issue with certain combinations of filter conditions
R1 Client HF1 (6.8.7.9106)
- .NET Core updated to 8.0.11
- Resolves an issue processing Entra ID group filters — Also requires ProfileUnity Console 6.8.7 R1 HF1 or later
ProfileUnity Console — Updated 01-07-25
ProfileUnityConsole_6.8.7-HF1.zip | README.txt
R1 Console HF1 (6.8.7.9112) — 01-07-25
- Resolves an issue logging into 6.8.7 with certain complex passwords
- Resolves an issue preventing the mixing of Entra ID group filters with different Tenant IDs in a single Configuration Module
- Resolves an issue creating new Entra ID group filters
6.8.6 GA (8711) and R1 (8805) LIMITED SUPPORT
▼ Show
Client Tools — Updated 5-24-24
client-tools_686r1-hf3.zip | README.txt
HF3 (6.8.6.8906) — 5-20-24
- Resolves an issue with missing FlexApps during simultaneous user logons with matching assignments
- Updates .NET Core Hosting Bundle and Desktop Runtimes to 6.0.30
HF2 (6.8.6.8872) — 4-22-24
- Resolves an issue where an RDS/AVD user may not see any FlexApp shortcuts
- Resolves an issue where some FlexApp Ones, on the second logon, cause Winlogon to hang, instantly sign out, or ask to start the LW Container Service
HF1 (6.8.6.8838) — 3-15-24
- Resolves an issue with Azure Security Group lookup failures causing delays
- Resolves an issue in 6.8.6 R1 processing INI paths containing environment variables
- Resolves an issue in 6.8.6 R1 reading prior versions' Azure Security Group info from INI
- Resolves an issue in 6.8.6 R1 affecting offline processing of previously-cached INI files
6.8.5 (8490 / 8507 R1) EOL
▼ Show
Client Tools — Updated 8-15-23
client-tools_685r1-hf7.zip | README.txt — HF7 through HF1 fixes on file; refer to the archived README for full details.
6.8.4 and Earlier EOL
▼ Show
Version history covered: 6.8.4 R2, 6.8.4 G4/R1, 6.8.3 R2/R1, 6.8.2.
End of Life Versions
For a complete list of ProfileUnity versions at End of Life, including support end dates: › End-of-Life for Versions of ProfileUnity
| Product | Liquidware ProfileUnity with FlexApp |
| Applies To | ProfileUnity 6.8.4 R2 and later |
| Updated | September 15, 2026 |