> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/release-notes/desktop/web-vault-+-desktop-app/vault-release-18.6.0.md).

# Vault Release 18.6.0

## Overview

**Keeper 18.6.0 (Web Vault & Desktop Electron)** was a security-driven release with broad fixes across both platforms, covering critical vulnerability patches, password strength improvements, KeeperDrive/NSF enforcement fixes, PAM/Discovery enhancements, and a significant tech debt push. Both clients also saw substantial tech debt modernization with React upgraded to v19, Redux Toolkit introduced, and legacy dependencies including Bluebird and Moment.js replaced.4

Key highlights:

* Critical stored XSS patches across both platforms (Notification Center, Delete from Shared Folder dialog)
* zxcvbn password strength scoring fully shipped across the Vault
* Hardware security key support (FIDO/YubiKey) for 1FA, 2FA, and RBI sessions
* Desktop: `--ignore-certificate-errors` removed; scoped certificate validation implemented
* Desktop: YubiKey authentication reliability fixed across Windows, idle, and SSO scenarios
* NSF sharing enforcement and sync bugs resolved
* PAM/Discovery: NASCAR custom fields, session countdown timer, session recording deep links
* React v19, Redux Toolkit, Moment.js → Day.js, Bluebird removed across both clients

#### **Connection Expiration Countdown Timer**

Users can now see a real-time countdown timer when an active PAM connection is approaching its access limit, giving them time to save their work and wrap up gracefully before the session ends.

**How it works:**

When a connection has 60 seconds or less remaining, two banners appear simultaneously:

* **Record Detail Banner** — A warning banner appears directly on the record with a visual progress bar, showing the exact time remaining before access expires. This gives users immediate visibility from within the vault without needing to switch to the active connection window.

<figure><img src="/files/cWWK3MX7nFXUQh57tWr7" alt=""><figcaption></figcaption></figure>

* **Connection Window Banner** — A dismissible countdown banner also appears at the top of the active connection window itself. This banner can be minimized so it doesn't interfere with the working area, while still keeping the user informed that their session is about to end.

<figure><img src="/files/NhzXiGBBLdsKuXgZMOG3" alt=""><figcaption></figcaption></figure>

Together, these notifications ensure users are never caught off guard by an unexpected session termination, reducing the risk of lost work and improving the overall experience for time-limited privileged access sessions.

* **VAUL-9019:** Surface custom fields (Alternative Login) from DiscoveryObject in Vault for NASCAR Discovery
* **INT-143:** CNAPP/Wiz Integration v4 Release
* **VAUL-8925:** Added support for hardware security keys (FIDO/YubiKey) for biometric login (1FA & 2FA)

## Improvements&#x20;

* **VAUL-8885:** Added new CNAPP Remediation Action — Remove Standing Privilege
* **VAUL-9207:** Added 'Match All' option for tag filtering of CNAPP issues
* **VAUL-8457:** Implemented zxcvbn password strength scoring for create/edit and password generator
* **VAUL-6350:** Made loading of the zxcvbn package dynamic to reduce initial bundle size
* **VAUL-6323:** Implemented zxcvbn for Master Password strength scoring
* **VAUL-8875:** Feed record content as userInputs for more accurate zxcvbn password strength scoring
* **KDE-1448:** Implemented zxcvbn for Master Password strength scoring
* **VAUL-7022:** Exclude 2FA from Security Audit score when the admin has opted for exclusion on the Console
* **VAUL-9012:** Added deep link directly to a PAM session recording in Session Activity
* **VAUL-8493:** Added deep link options to specify connection type and credential ID on record launch
* **VAUL-9244:** Minor UI updates to JIT settings for IDP elevation
* **VAUL-9236:** Made Operating System field a dropdown and removed Service Machines Windows filter
* **VAUL-9238:** Enabled Single-User and MFA workflow options for PAM Cloud records
* **VAUL-7658:** Added support for clearing security audit data
* **VAUL-7332:** Made KSM UI consistent with given permissions for shared apps
* **VAUL-7610:** Implemented new API for configuration record update
* **VAUL-9123:** Added ability to pass FIDO/YubiKey through RBI session
* **VAUL-8800:** Changed Create Account link to Start Free Trial and updated the URL
* **VAUL-8823:** Added missing translation keys
* **VAUL-9200:** Abstracted build/deploy Slack messaging in GitHub Actions
* **VAUL-9201:** Abstracted SBOM process in GitHub Actions
* **VAUL-9251:** Fixed Web Vault Deploy Slack Messages for 18.6.0 pipeline
* **VAUL-9320:** Resolved NPM issues in dompurify dependency
* **KDE-2160:** Updated Importer NPM module
* **VAUL-8923, KDE-2086:** Updated React to v19
* **VAUL-8881, KDE-2078:** Updated Redux and introduced Redux Toolkit
* **VAUL-8725, KDE-2127:** Updated ESLint configuration
* **VAUL-8678, KDE-2179:** Replaced moment library with dayjs
* **VAUL-8822, KDE-2077:** Removed Bluebird dependency
* **VAUL-9126:** Replaced var with let/const across the codebase
* **VAUL-9178:** Unified the display and editing of PAM Configurations
* **KDE-2128:** Sanitized unsafe server-message HTML rendering to prevent XSS
* **KDE-2148:** Removed the unused cleanup.js file
* **KDE-2190:** Updated tray's record list scrollbar styling
* **KDE-1698:** Resolved form-data issues
* **KDE-1511:** Remediated pen test finding for Dylib injection (RTQ) on macOS
* **KDE-2196:** Removed dev dependencies from distributed app
* **KDE-2219:** Changed Create Account link to Start Free Trial and updated the URL
* **KDE-2112:** Improved Wayland support on Snap for the Linux desktop app and fixed known crashes

## Bug Fixes

* **VAUL-9014:** Fixed critical stored HTML injection in Notification Center (senderFullName) and PAM Workflow reason field
* **VAUL-8924:** Fixed stored XSS vulnerability in delete from shared folder workflow
* **VAUL-9093:** Fixed RBI autofill not passing MFA code with "launch as"
* **VAUL-8846:** Fixed NSF team restrictions not being enforced
* **VAUL-9264:** Fixed BreachWatch incorrectly flagging strong passwords as High risk
* **VAUL-9314:** Fixed Console not displaying breached passwords from imported records
* **VAUL-9121:** Fixed Security Audit showing incorrect password count for admin user in free trial account
* **VAUL-8702:** Fixed NSF GRE sharing enforcement issues
* **VAUL-9073:** Fixed NSF sharee with view-only permissions being allowed to move a nested folder to their vault
* **VAUL-9280:** Fixed inability to send first sharing invite for NSF record
* **VAUL-8872:** Fixed offline alert when attempting to set access expiration for multiple NSF users
* **VAUL-7470:** Fixed re-authentication not triggering for edit while offline
* **VAUL-8514:** Fixed KDBX export writing XML-invalid control characters causing unreadable exports
* **VAUL-8286:** Fixed importing too many Shared Folders causing throttling error
* **VAUL-5203:** Fixed importing a JSON file with 20k shared folders triggering a throttling error
* **VAUL-8229:** Fixed Vault import/export issues with custom record types (JSON) vs Commander
* **VAUL-8238:** Fixed missing VNC parameters on PAM connections
* **VAUL-9083:** Fixed "Can Create Shared Folder" enforcement not blocking folder sharing workaround
* **VAUL-9085:** Fixed sharing a NSF folder with a group that has parent access incorrectly moving folder to root
* **VAUL-9079:** Fixed folder sharing restriction dialog displaying incorrect messaging
* **VAUL-8989:** Fixed inability to move a record into a NSF folder
* **VAUL-9193:** Fixed unexpected error during record deletion from NSF folder
* **VAUL-8871:** Fixed NSF deleted folder not automatically syncing for other users
* **VAUL-9142:** Fixed NSF record in vault root showing attachment as a distinct record in List View
* **VAUL-9199:** Fixed vault layout reflow causing horizontal scroll at 320px viewport
* **VAUL-7852:** Fixed Security Audit Score text not matching Enterprise data
* **VAUL-7330:** Fixed Security Audit translations routing user to different page
* **VAUL-9157:** Fixed KSM documentation links pointing to wrong page
* **VAUL-9116:** Fixed KeeperDB launch colors being incorrect
* **VAUL-9144:** Fixed console error when selecting record with non-image attachments (failed thumbnail downloads)
* **VAUL-8379:** Fixed Sticky Password dropzone spacing for multiple translations
* **VAUL-9191:** Fixed CNAPP "External Exposure" risk type missing translation
* **VAUL-9087:** Fixed CNAPP missing translations for "view documentation" on Cloud Security Zero-State
* **VAUL-9088:** Fixed CNAPP missing translations for "None Selected" on Cloud Security Zero-State
* **VAUL-7885:** Fixed error publishing PAM User from discovery
* **VAUL-8968:** Fixed discovery publishing incorrect data
* **VAUL-9271:** Fixed inability to open a record after opening an Application
* **VAUL-9288:** Fixed PAM Configurations pill not showing up in Advanced Search
* **VAUL-9324:** Fixed editing rotation of NSF record throwing an error
* **VAUL-8379:** Fixed Sticky Password dropzone spacing for multiple translations
* **KDE-2150:** Fixed RCE in Keeper Desktop via stored XSS in the "Delete from Shared Folder" dialog
* **KDE-2139:** Fixed 32-bit MSI crashing on SSO-related browser actions
* **KDE-2027:** Removed --ignore-certificate-errors flag and implemented scoped certificate validation
* **KDE-1845:** Fixed Windows Hello "Security Key" option not shown for SSO users
* **KDE-2116:** Fixed KeeperFill for Apps Global Hotkeys stopping after app has been open for some time
* **KDE-2138:** Fixed re-authentication not triggering for edit while offline
* **KDE-2162:** Fixed and updated less-common login workflows (basic-authorization, sso-basic-authorization, select-client-certificates)
* **KDE-2192:** Fixed wake lock failing to obtain when importing from CSV
* **KDE-2061:** Fixed sidebar overlapping hotkeys on detailed records (KFFA)
* **KDE-2201:** Removed debug startup log options from production build to reduce log output

## Web Vault Update Instructions

* To ensure you're using the latest Web Vault, simply reload the vault login page (or Shift+Ctrl/Cmd+R to force refresh)

## Desktop Update Instructions

* If you installed Keeper Desktop directly from the Keeper website, download the latest version from:\
  <https://www.keepersecurity.com/download.html?t=d>
* If you installed Keeper Desktop from the Mac App Store or Microsoft Store, visit the store to perform the update.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/release-notes/desktop/web-vault-+-desktop-app/vault-release-18.6.0.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
