Wazuh 4.11.0 - Smarter, Stronger, More Secure

Modified on Fri, 25 Apr at 6:07 PM

This release is cumulative, meaning it includes all previous enhancements and fixes from past versions.


You can explore the official release notes here for deeper technical details.


Highlights of Wazuh 4.11.0


The 4.11.0 release focuses on three main areas:


  • Improved vulnerability detection with prioritized CISA data.

  • Base OS updates for cloud and virtual deployments.

  • Enhanced software detection through Syscollector improvements.


Key Features and Enhancements


Vulnerability Detection CNA Enhancement


The vulnerability scanner now prioritizes CISA-sourced vulnerability data over NVD data.


This change leads to:


  • More accurate vulnerability assessments

  • Reduced false positives

  • Better alignment with official cybersecurity advisories

    Learn more about the Wazuh Vulnerability Detector.


AMI and OVA Base OS Update


Due to vulnerabilities and end-of-life issues with Amazon Linux 2 (AL2), Wazuh has updated its base operating systems for AMI and OVA images to Amazon Linux 2023 (AL2023).


This ensures that Wazuh deployments are:


  • More secure out-of-the-box

  • Compatible with the latest AWS infrastructure


Syscollector’s Software Detection Improvements


Syscollector — Wazuh’s system inventory module — now offers better software detection:


  • Improved package identification for macOS (.pkg installations).

  • Expanded detection of Python pip and Node.js npm packages.

  • Integration with Windows WMI for more accurate system update capture.

    Check out Syscollector documentation for more details.


Wazuh Manager


  • Improved delimiters on XML (#27771)

  • Enhanced File Integrity Monitoring (FIM) decoder (#27893)

  • Improvements in SCA and Syscheck decoders (#27835)

  • Improved CISCAT decoder messages (#27914)

  • Added CISA vulnerability content, prioritized over NVD (#27692)

  • Changed ms-graph page size (#28195)


Wazuh Agent


  • Better Syscollector hotfix coverage on Windows via WMI and WUA APIs (#26706)

  • Expanded Syscollector detection for .pkg packages (#26782)

  • Updated Python and NPM package paths in Syscollector (#26236)


Wazuh Dashboard


  • Refined layout of the agent details view (#7193)

  • Adjusted column widths and table layout (#7195)

  • Removed unused node_build field in plugin manifest (#7245)

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article