> For the complete documentation index, see [llms.txt](https://newdocs.keeper.io/en/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://newdocs.keeper.io/en/release-notes/desktop/web-vault-+-desktop-app/vault-release-18.6.0.md).

# Vault Release 18.6.0

## Overview

Keeper Web Vault & Desktop 18.6.0 delivers security and stability improvements across both platforms. Updates include password-strength enhancements, Nested Shared Subfolder enforcement fixes, PAM and Discovery improvements, and modernized dependencies.

## New Features

### **Connection Expiration Countdown Timer**

Users can now see a real-time countdown timer when an active PAM connection is approaching its access limit, giving them time to save their work before the session ends.

#### **How it works**

When a connection has 60 seconds or less remaining, two banners appear simultaneously:

**Record Detail Banner** — A warning banner appears directly on the record with a visual progress bar, showing the exact time remaining before access expires. This gives users immediate visibility from within the vault without needing to switch to the active connection window.

<figure><img src="/files/cWWK3MX7nFXUQh57tWr7" alt=""><figcaption></figcaption></figure>

**Connection Window Banner** — A dismissible countdown banner also appears at the top of the active connection window itself. This banner can be minimized so it doesn't interfere with the working area, while still keeping the user informed that their session is about to end.

<figure><img src="/files/NhzXiGBBLdsKuXgZMOG3" alt=""><figcaption></figcaption></figure>

Together, these notifications ensure users are never caught off guard by an unexpected session termination, reducing the risk of lost work and improving the overall experience for time-limited privileged access sessions.

### Passkey Authentication with Hardware Keys

With the latest version of Keeper Web Vault and Browser Extension, we now support FIDO2 cross-platform (roaming) authenticators - such as hardware security keys - in addition to platform authenticators, for passkey login. This replaces password + second-factor authentication with a single phishing-resistant credential.

<figure><img src="/files/9Y8fMASBXz3DvH5JmUFl" alt=""><figcaption></figcaption></figure>

### New CNAPP Remediation Action — Remove Standing Privilege

We've added a new CNAPP / Wiz remediation action which removes standing privilege from a cloud identity.

<figure><img src="/files/3oiUjKNdXX7hidlIAKKX" alt=""><figcaption></figcaption></figure>

During the remediation process, you can remove entitlements, such as Group or Role assignment.

<figure><img src="/files/pMwT3NVRzSAm4Mi91bmq" alt=""><figcaption></figcaption></figure>

## Improvements

* **VAUL-8885:** Added new CNAPP Remediation Action — Remove Standing Privilege
* **VAUL-9207:** Added 'Match All' option for tag filtering of CNAPP issues
* **VAUL-8457:** Implemented improved password strength scoring for create/edit and password generator
* **VAUL-6323:** Implemented improved password strength scoring for Master Password
* **VAUL-8925:** Added support for hardware security keys (FIDO/YubiKey) for Passkey biometric login
* **VAUL-9012:** Added deep link directly to a PAM session recording in Session Activity
* **VAUL-8493:** Added deep link options to specify connection type and credential ID on record launch
* **VAUL-9244:** Minor UI updates to JIT settings for IDP elevation
* **VAUL-9236:** Made "Operating System" field a dropdown and removed Service Machines Windows filter
* **VAUL-9238:** Enabled Single-User and MFA workflow options for PAM Cloud records
* **VAUL-7658:** Added support for clearing security audit data
* **VAUL-7332:** Made KSM UI consistent with given permissions for shared apps
* **VAUL-7610:** Implemented new API for configuration record update
* **VAUL-9123:** Added ability to pass FIDO/YubiKey through RBI sessions. Documentation will be posted to customers on the process for enabling this capability.
* **VAUL-8800:** Changed Create Account link to Start Free Trial and updated the URL
* **VAUL-8823:** Added missing translation keys
* **VAUL-9320:** Resolved NPM issues in dompurify dependency
* **KDE-2160:** Updated Importer NPM module
* **VAUL-8923, KDE-2086:** Updated React to v19
* **VAUL-8881, KDE-2078:** Updated Redux and introduced Redux Toolkit
* **VAUL-8725, KDE-2127:** Updated ESLint configuration
* **VAUL-8678, KDE-2179:** Replaced moment library with dayjs
* **VAUL-8822, KDE-2077:** Removed Bluebird dependency
* **VAUL-9126:** Replaced var with let/const across the codebase
* **VAUL-9178:** Unified the display and editing of PAM Configurations
* **KDE-2128:** Sanitized unsafe server-message HTML rendering to prevent XSS
* **KDE-2148:** Removed the unused cleanup.js file
* **KDE-2190:** Updated tray's record list scrollbar styling
* **KDE-1511:** Remediated pen test finding for Dylib injection (RTQ) on macOS
* **KDE-2196:** Removed dev dependencies from distributed app
* **KDE-2219:** Changed Create Account link to Start Free Trial and updated the URL
* **KDE-2112:** Improved Wayland support on Snap for the Linux desktop app and fixed known crashes

## Bug Fixes

* **VAUL-9093:** Fixed RBI autofill not passing MFA code with "Launch As"
* **VAUL-9014:** Fixed stored HTML injection security issues in 2 areas
* **VAUL-8924:** Fixed stored XSS vulnerability issues in one screen
* **VAUL-8238:** Fixed missing VNC parameters (Compression level, Display quality, Display encodings) on PAM connections
* **VAUL-8846:** Fixed NSF team restrictions not being enforced
* **VAUL-9264:** Fixed BreachWatch incorrectly flagging strong passwords as High risk
* **VAUL-9314:** Fixed Console not displaying breached passwords from imported records
* **VAUL-9121:** Fixed Security Audit showing incorrect password count for admin user in free trial account
* **VAUL-8702:** Fixed NSF GRE sharing enforcement issues
* **VAUL-9073:** Fixed NSF sharee with view-only permissions being allowed to move a nested folder to their vault
* **VAUL-9280:** Fixed inability to send first sharing invite for NSF record
* **VAUL-8872:** Fixed offline alert when attempting to set access expiration for multiple NSF users
* **VAUL-7470:** Fixed re-authentication not triggering for edit while offline
* **VAUL-8514:** Fixed KDBX export writing XML-invalid control characters causing unreadable exports
* **VAUL-8286:** Fixed importing too many Shared Folders causing throttling error
* **VAUL-5203:** Fixed importing a JSON file with 20k shared folders triggering a throttling error
* **VAUL-8229:** Fixed Vault import/export issues with custom record types (JSON) vs Commander
* **VAUL-9083:** Fixed "Can Create Shared Folder" enforcement not blocking folder sharing workaround
* **VAUL-9085:** Fixed sharing a NSF folder with a group that has parent access incorrectly moving folder to root
* **VAUL-9079:** Fixed folder sharing restriction dialog displaying incorrect messaging
* **VAUL-8989:** Fixed inability to move a record into a NSF folder
* **VAUL-9193:** Fixed unexpected error during record deletion from NSF folder
* **VAUL-8871:** Fixed NSF deleted folder not automatically syncing for other users
* **VAUL-9142:** Fixed NSF record in vault root showing attachment as a distinct record in List View
* **VAUL-9199:** Fixed vault layout reflow causing horizontal scroll at 320px viewport
* **VAUL-7852:** Fixed Security Audit Score text not matching Enterprise data
* **VAUL-7330:** Fixed Security Audit translations routing user to different page
* **VAUL-9157:** Fixed KSM documentation links pointing to wrong page
* **VAUL-9116:** Fixed KeeperDB launch colors being incorrect
* **VAUL-9144:** Fixed console error when selecting record with non-image attachments (failed thumbnail downloads)
* **VAUL-8379:** Fixed Sticky Password dropzone spacing for multiple translations
* **VAUL-9191:** Fixed CNAPP "External Exposure" risk type missing translation
* **VAUL-9087:** Fixed CNAPP missing translations for "view documentation" on Cloud Security Zero-State
* **VAUL-9088:** Fixed CNAPP missing translations for "None Selected" on Cloud Security Zero-State
* **VAUL-7885:** Fixed error publishing PAM User from discovery
* **VAUL-8968:** Fixed discovery publishing incorrect data
* **VAUL-9271:** Fixed inability to open a record after opening an Application
* **VAUL-9288:** Fixed PAM Configurations pill not showing up in Advanced Search
* **VAUL-9324:** Fixed editing rotation of NSF record throwing an error
* **VAUL-8379:** Fixed Sticky Password dropzone spacing for multiple translations
* **KDE-2150:** Fixed RCE in Keeper Desktop via stored XSS in the "Delete from Shared Folder" dialog
* **KDE-2139:** Fixed 32-bit MSI crashing on SSO-related browser actions
* **KDE-2027:** Removed `--ignore-certificate-errors` flag and implemented scoped certificate validation
* **KDE-1845:** Fixed Windows Hello "Security Key" option not shown for SSO users
* **KDE-2116:** Fixed KeeperFill for Apps Global Hotkeys stopping after app has been open for some time
* **KDE-2138:** Fixed re-authentication not triggering for edit while offline
* **KDE-2162:** Fixed and updated less-common login workflows (basic-authorization, sso-basic-authorization, select-client-certificates)
* **KDE-2192:** Fixed wake lock failing to obtain when importing from CSV
* **KDE-2061:** Fixed sidebar overlapping hotkeys on detailed records (KFFA)
* **KDE-2201:** Removed debug startup log options from production build to reduce log output

## Web Vault Update Instructions

* To ensure you're using the latest Web Vault, simply reload the vault login page (or Shift+Ctrl/Cmd+R to force refresh)

## Desktop Update Instructions

* If you installed Keeper Desktop directly from the Keeper website, download the latest version from:\
  <https://www.keepersecurity.com/download.html?t=d>
* If you installed Keeper Desktop from the Mac App Store or Microsoft Store, visit the store to perform the update.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://newdocs.keeper.io/en/release-notes/desktop/web-vault-+-desktop-app/vault-release-18.6.0.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
