Patches and updates
Portal for ArcGIS Security 2026 Update 3 Patch
Summary
Esri announces the Portal for ArcGIS Security 2026 Update 3 Patch. Esri recommends that all customers using Portal for ArcGIS 12.1, 12.0, 11.5, 11.3 and 11.1 apply this patch. This patch deals specifically with the issues listed below under Issues Addressed with this Patch.
As part of the patch installation, the Portal for ArcGIS service is stopped and restarted. The restart may take several minutes depending on the number of items on the enterprise deployment.
As a best practice, clear the browser cache and re-launch the browser after installing the patch.
This patch can be uninstalled as outlined in the Uninstalling this patch on Windows and Uninstalling this patch on Linux sections below.
Esri recommends developing a rollback plan before installing patches. This may be taking a snapshot of machines and related file servers or using the WebGIS DR tool as a software backup. See Back up and restore best practices for more information. For those utilizing a highly available environment, refer to the help topic on how to apply patches in a highly available environment for guidance.
For more information on the security vulnerabilities addressed, please see the ArcGIS Trust Center announcements.
Issues addressed with this patch
- BUG-000185638 - Portal for ArcGIS has a security vulnerability. (12.0, 11.5)
- BUG-000185529 - Creating an ArcGIS Enterprise backup with the WebGIDR tool fails when ArcGIS Velocity is a federated server. (12.1)
- BUG-000185513 - After patching Portal for ArcGIS 11.5, adding an external WFS service fails and returns the error messages "Service does not exist or is inaccessible" in the user interface and "unsupported-spatial-reference" in the browser console. (11.5)
- BUG-000185212 - In ArcGIS Experience Builder, thumbnails of ArcGIS Online templates are not displayed in ArcGIS Enterprise. (12.1)
- BUG-000184948 - Portal for ArcGIS has a security vulnerability. (12.0, 11.5, 11.3, 11.1)
- BUG-000184947 - Portal for ArcGIS has a security vulnerability. (12.0 ,11.5, 11.3, 11.1)
- BUG-000184946 - Portal for ArcGIS has a security vulnerability. (11.5, 11.3)
- BUG-000184944 - Portal for ArcGIS has a security vulnerability. (11.5, 11.3, 11.1)
- BUG-000184943 - Portal for ArcGIS has a security vulnerability. (11.5, 11.3, 11.1)
- BUG-000184486 - Unable to add Active Directory users to ArcGIS Enterprise via the portal home interface, returning the error message “The user 'name' was not found". (12.1, 12.0)
- BUG-000183429 - Portal for ArcGIS has a security vulnerability. (12.0, 11.5, 11.3, 11.1)
- BUG-000183187 - Cannot update a member's email more than 80 hours after account creation. (11.5)
- BUG-000183679 - ArcGIS Experience Builder does not reflect latest changes made to custom widgets. (11.3)
- BUG-000182337 - ArcGIS Enterprise returns the "Invalid password" error message while importing a Secure Socket Layer (SSL) certificate if the certificate password includes the ^ character. (12.0, 11.5, 11.3, 11.1)
- BUG-000182186 - Portal for ArcGIS has a security vulnerability. (12.0, 11.5, 11.3, 11.1)
- BUG-000180933 - Portal for ArcGIS has a security vulnerability. (12.1, 12.0, 11.5, 11.3, 11.1)
- BUG-000180761 - Portal for ArcGIS has a security vulnerability. (11.5, 11.3,1 1.1)
- BUG-000179225 - Portal for ArcGIS has a security vulnerability. (11.5, 11.3, 11.1)
- BUG-000176591 Portal for ArcGIS has a security vulnerability. (11.5, 11.3, 11.1)
- BUG-000174118 - Portal for ArcGIS has a security vulnerability. (11.3, 11.1)
- BUG-000178493 - ArcGIS Experience Builder experiences embedded in an external website using an HTML iframe return the error message, "Item does not exist or is inaccessible," even after specifying user credentials. (11.5)
- BUG-000177797 - When attempting to update a member's email address, it reverts back to the previous one. (11.5)
- BUG-000177756 - In Experience Builder 1.17, exporting the results of a network trace to CSV format from the Table widget generates empty records on the first attempt, but it works correctly the second time. (11.5)
- BUG-000175889 - Edit widget does not display "Update" and "Delete" buttons when accessed through a Window in ArcGIS Experience Builder. (11.5)
To avoid conflicts the 12.1 version also addresses:
- BUG-000185376 - Portal for ArcGIS has a security vulnerability.
To avoid conflicts the 12.0 version also addresses:
- BUG-000184350 - After installing the Portal for ArcGIS Security 2026 Update 1 Patch, access to the ArcGIS Enterprise portal deployment fails on systems configured with web-tier authentication.
- BUG-000185376 - Portal for ArcGIS has a security vulnerability.
- BUG-000183756 - Lead promotion causes user interface issue in Mission Analyst.
- BUG-000183038 - Portal for ArcGIS has a security vulnerability.
- BUG-000182453 - Using the Search widget in ArcGIS Experience Builder to query a large number of features with 'Enable filtering for layer source search' enabled returns multiple query requests (200+) being made.
- BUG-000182430 - The metadata editor is missing translations for some strings.
- BUG-000182294 - In a list of existing task types, when a type is deleted, the type persists even though a message shows that the deletion was successful.
- BUG-000182293 - In the ArcGIS Mission analyst experience, when a user selects the tracks view on the map in the form of a 'heat map,' the tracks do not draw correctly.
- BUG-000182292 - The presence data in ArcGIS Mission must be consistently refreshed.
- BUG-000182291 - The text character limits for reports, related to default and maximum values, are not consistent.
- BUG-000181636 - The ArcGIS Experience Builder Business Analyst widget in ArcGIS Enterprise fails to load and returns the error message "This report can't be loaded" after upgrading to Google Chrome 142 or Microsoft Edge 143.
- BUG-000181346 - In ArcGIS Experience Builder, an Embed widget containing a Survey123 form from ArcGIS Enterprise fails to load and returns the error message "The survey is not accessible or does not exist." in Google Chrome 142 and Microsoft Edge 143.
- BUG-000180846 - In ArcGIS Dashboards, an embedded content element containing an ArcGIS Survey123 form from ArcGIS Enterprise fails to load with the error message "The survey is not accessible or does not exist" in Google Chrome 142 and Microsoft Edge 143.
- BUG-000180627 - Updating a task, then sending a broadcast, followed by clicking on Create Task, opens the Update Task panel instead of opening the Create Task panel.
- BUG-000180091 - The 'Enable attachments' setting for reports is not retained in missions created from templates, resulting in missing attachment functionality in the new mission.
- BUG-000179864 - Creating a new mission report from the Mission Report template does not honor the saved field lengths in the template.
- BUG-000179860 - ArcGIS Survey123 forms are not added to a new ArcGIS Mission when using a mission template with surveys.
To avoid conflicts the 11.5 version also addresses:
- BUG-000185376 - Portal for ArcGIS has a security vulnerability.
- BUG-000185267 - Upgrade from ArcGIS Enterprise 11.5 to versions 12.0 or 12.1 fails when the Portal for ArcGIS 11.5 Security 2026 Update 1 Patch is installed on Windows.
- BUG-000184442 - 'Edit privileges' window of an application created by Developer Credentials is blank after installing Portal for ArcGIS 11.5 Security 2026 Update 1 Patch B.
- BUG-000184381 - Receiving a 498 Invalid Token error when leveraging secure services in a Portal HA environment with the portal content directory configured on a separate file server or cloud storage.
- BUG-000184350 - After installing the Portal for ArcGIS Security 2026 Update 1 Patch, access to the ArcGIS Enterprise portal deployment fails on systems configured with web-tier authentication.
- BUG-000183227 - Web Editor on ArcGIS Enterprise checks for the Advanced Editing User Type Extension (AE UTE) for branch version management or editing simple features.
- BUG-000183038 - Portal for ArcGIS has a security vulnerability.
- BUG-000182873 - A spatial query in the ArcGIS Experience Builder Query widget returns an incorrect total record count when using the 'Add to table' option on the 'Data action' tab under 'All data' in the Table widget.
- BUG-000182353 - Portal for ArcGIS has a security vulnerability.
- BUG-000182125 - Selecting a classification from the item classification when saving a web map results in two classifications being selected.
- BUG-000181636 - The ArcGIS Experience Builder Business Analyst widget in ArcGIS Enterprise fails to load and returns the error message "This report can't be loaded" after upgrading to Google Chrome 142 or Microsoft Edge 143.
- BUG-000181403 - The survey form item details page 'Open in Survey123 app' option fails to launch the Survey123 app in disconnected environments.
- BUG-000181346 - In ArcGIS Experience Builder, an Embed widget containing a Survey123 form from ArcGIS Enterprise fails to load and returns the error message "The survey is not accessible or does not exist." in Google Chrome 142 and Microsoft Edge 143.
- BUG-000181192 - The item details page for the web map cannot be accessed when a classification scheme is enabled in ArcGIS Enterprise 11.5.
- BUG-000180912 - In ArcGIS Enterprise, the login page displays in English instead of the default language when 'Allow anonymous access to your portal' is disabled.
- BUG-000180846 - In ArcGIS Dashboards, an embedded content element containing an ArcGIS Survey123 form from ArcGIS Enterprise fails to load with the error message "The survey is not accessible or does not exist" in Google Chrome 142 and Microsoft Edge 143.
- BUG-000180830 - When publishing a hosted feature layer from a CSV or Excel file in ArcGIS Enterprise portal, the user-selected time zone is not honored.
- BUG-000180629 - When the Update Task is opened followed by opening the Create Task, status input is missing between the assignees input and the reports input.
- BUG-000180628 - After assigning a task without a report, the task is unable to be marked as Complete and provides the message "report required" even though the dropdown for the report in the task is set to None.
- BUG-000180627 - Updating a task, then sending a broadcast, followed by clicking on Create Task, opens the Update Task panel instead of opening the Create Task panel.
- BUG-000180091 - The 'Enable attachments' setting for reports is not retained in missions created from templates, resulting in missing attachment functionality in the new mission.
- BUG-000179864 - Creating a new mission report from the Mission Report template does not honor the saved field lengths in the template.
- BUG-000179860 - ArcGIS Survey123 forms are not added to a new ArcGIS Mission when using a mission template with surveys.
- BUG-000179857 - Mission report layers are not added to the map when a new mission is created from a mission template with reports.
- BUG-000179782 - When using the Statistics option in the Table widget of ArcGIS Experience Builder to query statistics for a field, the request fails if the underlying service is referenced from an SQL Server database.
- BUG-000179287 - "Failed to edit portal directory 'content'. JsonObject Code: 500" when editing the ArcGIS Enterprise content directory from the file system to the Amazon S3 bucket.
- BUG-000179160 - ArcGIS Experience Builder is missing the option in the Print widget to 'Use layout from layout item' that is documented and was available previously.
- BUG-000179095 - In ArcGIS Mission Manager, last known location pins are disappearing from the map.
- BUG-000179037 - The Thai translation is incorrect for the Quote button when editing in ArcGIS StoryMaps in ArcGIS Enterprise.
- BUG-000178714 - In ArcGIS Dashboards, the serial chart element data visually shifts when data queries update, such as map filtering or live data refresh.
- BUG-000178713 - Gauge widget value elements in ArcGIS Dashboards visually shift when data queries update, such as during map filtering or live data refreshes.
- BUG-000178512 - Selecting a classification from the picklist can result in two classifications being selected.
- BUG-000178457 - Administrators and those with the necessary administrative privileges cannot change the owner of data store items in the ArcGIS Enterprise portal.
- BUG-000178204 - The extentService set with 'URL to local map service' in a disconnected environment is ignored when using Metadata Editor and instead makes a request to an ArcGIS Online service.
- BUG-000177917 - Using 'Save As' in ArcGIS Knowledge Studio projects can corrupt unopened maps and link charts if the content item in the original project is deleted.
- BUG-000177915 - When multiple users edit the same project and one user deletes an unopened link chart, the project can become corrupted.
- BUG-000177808 - Web applications installed with Portal for ArcGIS 11.5 may intermittently fail to fully load all content, and the browser console returns the "ChunkLoadError: Loading chunk xxxx failed." error message.
- BUG-000177378 - In ArcGIS Experience Builder, non-administrative users cannot export map image layers published to ArcGIS Enterprise 11.5.
- BUG-000177330 - The home page editor does not display the View option, preventing the preview of the home page layout on desktop, tablet, and mobile devices.
- BUG-000177260 - Updating the federated server URL incorrectly updates portal content URLs, resulting in inaccessible content and negatively affecting federation.
- BUG-000176037 - ArcGIS Survey123 tokens time out after 30 minutes when the survey is embedded in ArcGIS Workflow Manager.
- BUG-000175748 - ArcGIS Mission Responder is not using enterprise basemaps.
- BUG-000175746 - ArcGIS Mission Manager tasks are positioned with the wrong location caused by the basemap.
- BUG-000175721 - Issues long queries for large datasets when searching for a feature from 'Recent search' or clearing the searches in the ArcGIS Experience Builder Search widget.
- BUG-000175706 - A pop-up configured with a feature service sometimes returns away from the searched-for point upon automatic zoom when using the Search widget in ArcGIS Web AppBuilder.
- BUG-000175398 - When the password for a member in an ArcGIS Online or ArcGIS Enterprise account is changed, any API key previously created by the member stops working.
- BUG-000173561 - The "Error: Create Service exception 'java.lang.Exception: Exception: Read timed out" error message is returned when publishing a hosted feature service via Portal for ArcGIS.
- BUG-000173253 - A map service with a different projection from the basemap results in an additional selection in ArcGIS Experience Builder.
- BUG-000162583 - Creating an offline map area fails when using a cached image service in the web map.
To avoid conflicts the 11.3 version also addresses:
- BUG-000185376 - Portal for ArcGIS has a security vulnerability.
- BUG-000181636 - The ArcGIS Experience Builder Business Analyst widget in ArcGIS Enterprise fails to load and returns the error message "This report can't be loaded" after upgrading to Google Chrome 142 or Microsoft Edge 143.
- BUG-000181346 - In ArcGIS Experience Builder, an Embed widget containing a Survey123 form from ArcGIS Enterprise fails to load and returns the error message "The survey is not accessible or does not exist." in Google Chrome 142 and Microsoft Edge 143.
- BUG-000180846 - In ArcGIS Dashboards, an embedded content element containing an ArcGIS Survey123 form from ArcGIS Enterprise fails to load with the error message "The survey is not accessible or does not exist" in Google Chrome 142 and Microsoft Edge 143.
- BUG-000180614 - 'Delete item' from the ArcGIS Enterprise Settings page keeps loading indefinitely.
- BUG-000179287 - "Failed to edit portal directory 'content'. JsonObject Code: 500" when editing the ArcGIS Enterprise content directory from the file system to the S3 bucket.
- BUG-000179114 - Map Viewer fails to evaluate contingent values when creating new valid features in ArcGIS Enterprise 11.3 and returns the error message "Value is incompatible with other selected values".
- BUG-000178599 - Unable to uninstall Portal for ArcGIS 11.3 Security 2025 Update 2 Patch B.
- BUG-000178089 - Portal for ArcGIS Security Patch 2 removes the builddate.txt and buildsources.txt from the installation framework.
- BUG-000177447 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000176589 - Installing Portal for ArcGIS patches erases custom edits to the \apps\workflowmanager\conf\appconfig.json file.
- BUG-000176348 - Portal for ArcGIS 11.3 Security 2025 Update 1 Patch B causes ArcGIS Web Editor to display a blank page.
- BUG-000176212 - Server-Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS.
- BUG-000176174 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000176172 - Portal for ArcGIS has a security vulnerability.
- BUG-000176170 - Stored Cross Site scripting in Portal for ArcGIS.
- BUG-000176169 - Stored Cross Site scripting in Portal for ArcGIS.
- BUG-000176168 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000175706 - The pop up configured with a feature service sometimes returns away from the searched for point upon automatic zoom when using the Search widget in ArcGIS Web AppBuilder.)
- BUG-000175245 - The Portal for ArcGIS Security 2025 Update 1 patch for Portal for ArcGIS 11.3 causes some ArcGIS Instant Apps to return a 404 error message and not load successfully.
- BUG-000175222 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174537 - A missing match attribute in the group filter leads to incorrect zooming/panning to the filtered features.
- BUG-000174336 - Improper authentication issue in Portal for ArcGIS.
- BUG-000174160 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174158 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174157 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174155 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174154 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174153 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174152 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174150 - Unvalidated redirect in Portal for ArcGIS.
- BUG-000174149 - The Portal for ArcGIS has an unvalidated redirect.
- BUG-000174022 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174020 - Reflected XSS vulnerability identified in Portal for ArcGIS.
- BUG-000173957 - Using a custom geoprocessing tool in the Analysis widget to extract and download data or files from ArcGIS Enterprise fails, and the error message, "e.fetcFolders is not a function" is returned in a public ArcGIS Experience Builder app.
- BUG-000173740 - A file handle leak in Portal for ArcGIS returns the "Too many open files" error and requires frequent restarts in an Amazon Web Services (AWS) deployment.
- BUG-000172179 - When adding a point event using the Add Point Event widget in ArcGIS Experience Builder, route names and measure values are not automatically populated.
- BUG-000172165 - ArcGIS Enterprise 11.3 returns the "Too many exchange refresh token" error message even though the threshold is not reached.
- BUG-000172153 - Content categories are not properly assigned when items are categorized on the item page, which results in no items returned when filtering using content categories on the ArcGIS Enterprise portal content page.
- BUG-000171000 - Remove hard-coded URLs that reference arcgis.com from ArcGIS Instant Apps so they can work in fully disconnected ArcGIS Enterprise deployments (especially with the Category Gallery and Countdown templates).
- BUG-000170421 - The legend does not display for map image layers in Map Viewer.
- BUG-000170223 - In ArcGIS Enterprise 11.3, the import of a portal webgisdr backup fails with the error "The incoming site bundle is invalid" if a federated ArcGIS Server 10.9.1 is included.
- BUG-000169460 - Unable to open and access the URL address of a PDF item in ArcGIS Enterprise 11.3.
- BUG-000168729 - Unable to edit ArcGIS Experience Builder owned by another user, despite having sufficient privileges.
- BUG-000168562 - When using Map Viewer with HTTP/2 enabled on Internet Information Services (IIS) and in a Chrome or Edge browser, a burst of concurrent requests, such as rapid panning and zooming of the map, can lead to disappearing features and ERR_CONNECTION_RESET errors in the developer tools' console tab.
- BUG-000168418 - The error message "Essential Apps Required" is returned when loading ArcGIS Enterprise Sites directly for the first time when using web-tier authentication such Integrated Windows Authentication (IWA) or public key infrastructure (PKI).
- BUG-000167766 - Collaboration workspace sync fails when the ArcGIS Online organization is hosted in the Asia-Pacific region and the group joined to the workspace contains more than 20 items.
- BUG-000167652 - The Last Modified timestamp of a hosted feature layer is updated during a collaboration workspace sync, even when the service has not changed.
- BUG-000167622 - The index service Portal for ArcGIS (Linux) crashes when certain environmental conditions are in place.
- BUG-000167085 - When adding a Web Map Tile Service (WMTS) with multiple layers as an item to the portal, only the first layer is displayed in ArcGIS Online Map Viewer.
- BUG-000165350 - Distributed collaboration does not sync item description changes from ArcGIS Online to ArcGIS Enterprise.
- BUG-000165233 - The View Data Source option for ArcGIS Hub ends on a loop when the data is referenced from Portal for ArcGIS.
- BUG-000164122 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000163121 - The ArcGIS Enterprise Sites Gallery layout does not display items correctly.
- BUG-000161627 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000155605 - In a distributed collaboration, an ArcGIS Web AppBuilder app with the Search and Attribute Table widgets and custom configurations shared as copies still points back to the original data in Portal for ArcGIS, not the ArcGIS Online data where it is copied, which results in a login prompt in both ArcGIS Online and ArcGIS Enterprise.
- BUG-000153500 - Two-way distributed collaboration failing to 'sync' updates from ArcGIS Online to ArcGIS Enterprise 10.9.1.
- BUG-000146151 - When Window Authentication is enabled, viewing a KML layer in Map Viewer returns the error message, "The KML, is not available or cannot be added to the map."
- BUG-000143028 - A hosted feature layer exceeding 2 GB is not shared in a distributed collaboration from ArcGIS Online to Portal for ArcGIS despite successful sync.
To avoid conflicts the 11.1 version also addresses:
- BUG-000185376 - Portal for ArcGIS has a security vulnerability.
- BUG-000181346 - In ArcGIS Experience Builder, an Embed widget containing a Survey123 form from ArcGIS Enterprise fails to load and returns the error message "The survey is not accessible or does not exist." in Google Chrome 142 and Microsoft Edge 143.
- BUG-000180846 - In ArcGIS Dashboards, an embedded content element containing an ArcGIS Survey123 form from ArcGIS Enterprise fails to load with the error message "The survey is not accessible or does not exist" in Google Chrome 142 and Microsoft Edge 143.
- BUG-000178089 - Portal for ArcGIS Security Patch 2 removes the builddate.txt and buildsources.txt from the installation framework.
- BUG-000177447 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000176212 - Server-Side Request Forgery (SSRF) vulnerability in Portal for ArcGIS.
- BUG-000176174 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000176172 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000176170 - Stored Cross Site scripting in Portal for ArcGIS.
- BUG-000176169 - Stored Cross Site Scripting in Portal for ArcGIS.
- BUG-000176168 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000175222 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174336 - Improper authentication issue in Portal for ArcGIS.
- BUG-000174160 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174159 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174158 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174157 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174155 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174154 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174153 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174152 - Stored XSS vulnerability in Portal for ArcGIS.
- BUG-000174151 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174150 - Unvalidated redirect in Portal for ArcGIS.
- BUG-000174022 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000174020 - Reflected XSS vulnerability identified in Portal for ArcGIS.
- BUG-000174019 - Reflected XSS vulnerability identified in Portal for ArcGIS.
- BUG-000174018 - Reflected XSS vulnerability identified in Portal for ArcGIS.
- BUG-000173253 - A map image service with a different projection from the basemap results in an additional selection in ArcGIS Experience Builder.
- BUG-000171009 - URL manipulation vulnerability in Portal for ArcGIS.
- BUG-000168637 - Reflected cross-site-scripting (XSS) attacks in Portal for ArcGIS.
- BUG-000168624 - Unvalidated redirect in Portal for ArcGIS.
- BUG-000167984 - Portal for ArcGIS has a Local file inclusion (LFI) vulnerability.
- BUG-000167983 - Unvalidated redirect in Portal for ArcGIS.
- BUG-000167837 - When using the Calcite theme in ArcGIS Experience Builder 11.1, the error message, "Cannot read properties of undefined (reading 'underline')" is returned when clicking the Layers or Measure button in the Map widget.
- BUG-000167622 - The index service Portal for ArcGIS (Linux) crashes when certain environmental conditions are in place.
- BUG-000167597 - The navigation bars in the ArcGIS Instant Apps gallery and configuration pages in the ArcGIS Enterprise portal do not display correctly after updating the browser to Google Chrome 127 or Microsoft Edge 127.
- BUG-000167596 - The ArcGIS Solutions navigation bar in the ArcGIS Enterprise portal does not display correctly after updating the browser to Google Chrome 127 or Microsoft Edge 127.
- BUG-000167545 - The Map Viewer navigation bar in Portal for ArcGIS does not display correctly after updating the browser to Google Chrome 127 or Microsoft Edge 127.
- BUG-000167544 - The home page navigation bar in Portal for ArcGIS does not display correctly after updating the browser to Chrome 127 or Edge 127.
- BUG-000167432 - Vector Tile Style Editor displays unexpected characters in the 'Save As' dialog when the home application is configured to display in a non-English language.
- BUG-000166350 - Installing Portal for ArcGIS 11.1 Sharing Patch removes the directory and files used by 3D Object style items, resulting in advanced 3D symbols not displaying properly in Scene Viewer.
- BUG-000165805 - ArcGIS Experience Builder in ArcGIS Enterprise becomes unresponsive after adding an 'Extent changes' trigger when a map layer is also part of a Table widget.
- BUG-000165732 - Reflected cross-site scripting (XSS) vulnerability in Portal for ArcGIS.
- BUG-000165473 - The Portal for ArcGIS 11.1 Sharing patch adds sample widgets to ArcGIS Experience Builder.
- BUG-000165286 - Reflected XSS in Portal for ArcGIS.
- BUG-000164335 - Feature service edits are not synchronized when the guest in a distributed collaboration has a multi-machine deployment architecture.
- BUG-000164122 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000164118 - Members are not able to share with groups through Portal for ArcGIS Map Viewer when they own or manage more than 30 groups configured to only allow owners and managers to contribute content.
- BUG-000163309 - Reflected XSS in Portal for ArcGIS.
- BUG-000162883 - Unable to log in to some endpoints in Portal for ArcGIS through Security Assertion Markup Language (SAML) or OpenID Connect when using an external identity provider.
- BUG-000162733 - Portal for ArcGIS has an invalid authentication vulnerability.
- BUG-000162671 - Unable to view the legacy home page until users are authenticated within Portal for ArcGIS.
- BUG-000162623 - Portal for ArcGIS has a directory traversal vulnerability.
- BUG-000162544 - Unable to open the KML layer added to Portal for ArcGIS from a file in Map Viewer.
- BUG-000161781 - Unable to open a hosted tile layer's item details page 10 days after creation.
- BUG-000161683 - HTML injection vulnerability in Portal for ArcGIS.
- BUG-000161627 - Reflected XSS vulnerability in Portal for ArcGIS.
- BUG-000160803 - Unable to access secured services with saved credentials when using a forward proxy that requires authentication.
- BUG-000160765 - Stored cross-site scripting (XSS) vulnerability in ArcGIS Experience Builder.
- BUG-000160633 - When selecting features from the map using the Query widget with a buffer, ArcGIS Experience Builder fails to include the query results from the buffered area in a linked Table widget.
- BUG-000160599 - Stored cross-site scripting (XSS) vulnerability in Portal for ArcGIS Web AppBuilder.
- BUG-000160241 - Reflected cross-site scripting (XSS) vulnerability in Portal for ArcGIS.
- BUG-000159271 - Warnings are erroneously logged for ArcGIS Notebooks and ArcGIS Mission while trying to refresh a webhooks configuration.
- BUG-000158984 - Stored Cross Site Scripting (XSS) in Portal for ArcGIS.
- BUG-000158980 - Trying to add a service to the Map Viewer or as an item is resulting in an infinite loop of checkURL-requests when the allowedProxyHosts-parameter does not contain the domain of the service.
- BUG-000158910 - The Web GIS Disaster Recovery (WebGISDR) tool fails to create a backup if the backup of Portal for ArcGIS indicates items are missing.
- BUG-000158688 - There is a cross-site scripting vulnerability in ArcGIS Experience Builder.
- BUG-000158430 - In ArcGIS Web AppBuilder, the Geoprocessing widget returns an incorrect output for the selected feature if the 'Set as input for Geoprocessing' option is not selected in the Select widget.
- BUG-000158232 - Members are not able to share items with groups through the ArcGIS Enterprise portal when owning or managing more than 29 groups configured to only allow owners and managers to contribute content.
- BUG-000158210 - HTML injection in ArcGIS Web AppBuilder.
- BUG-000158161 - Include the embed configurable app in Portal for ArcGIS 11.2.
- BUG-000157727 - On the Organization > Overview page, the 'Administrative contacts' section fails to load.
- BUG-000157485 - Unable to create an offline area for a large data size in Portal for ArcGIS due to a size limit.
- BUG-000153928 - The measure tools do not work if a cursor is moved to find a second point and the map is double-clicked to complete the area measured.
- BUG-000153884 - Reflected Cross-Site Scripting (XSS) in Portal for ArcGIS Map Viewer.
- BUG-000146151 - When Window Authentication is enabled, viewing a KML layer in Map Viewer returns the error message, "The KML, is not available or cannot be added to the map."
Installing this patch on Windows
On Windows, the release date order of the patches does not matter when installing multiple patches. If an older patch is installed after a newer patch, the newer patch takes precedence and the fixes from the newer patch will remain. The ArcGIS Enterprise Patch Notification tool, when the option to install all available patches is activated, installs multiple patches in order of release date starting with oldest to newest.
The ArcGIS product listed in the table must be installed on your system before you can install a patch. Each patch setup is specific to the ArcGIS product in the list. To determine which products are installed on your system, please see the How to identify which ArcGIS products are installed section. Esri recommends that you install the patch for each product that is on your system.
Step 1: Download the appropriate file to a location other than your ArcGIS installation location.
| ArcGIS Enterprise | |
| Portal for ArcGIS 12.1 | ArcGIS-121-PFA-SEC2026U3-Patch.msp |
| Checksum (SHA256) |
3ABDA83B6A97259C7B3AAD3FBC66A198D2459745A81955F2A9A200847D922252 |
| Portal for ArcGIS 12.0 | ArcGIS-120-PFA-SEC2026U3-Patch.msp |
| Checksum (SHA256) |
A0FB3A81FE2896CC745B69BB9E2DF8CECA2CBB3123145AC4AF0619F3CD128A44 |
| Portal for ArcGIS 11.5 | ArcGIS-115-PFA-SEC2026U3-Patch.msp |
| Checksum (SHA256) |
CFB86ED19EAD81BAEEECFC7A07DFC348AD290A63996A1590F508B1E6D98EC8C4 |
| Portal for ArcGIS 11.3 | ArcGIS-113-PFA-SEC2026U3-Patch.msp |
| Checksum (SHA256) |
9295542812B4452A7D0ED22392F5ED0A3EAA30F6486999894CE1BBDA6AAB21C0 |
| Portal for ArcGIS 11.1 | ArcGIS-111-PFA-SEC2026U3-Patch.msp |
| Checksum (SHA256) |
43D06603EE9F8E92AAED2267529055B5FF4AC4D253FF994824625E3A7CFEBC02 |
Step 2: Make sure you have write access to your ArcGIS installation location.
Step 3: Double-click ArcGIS-<Version>-PFA-SEC2026U3-Patch.msp to start the setup process.
NOTE: If double clicking on the msp file does not start the setup installation, you can start the setup installation manually by using the following command:
msiexec.exe /p [location of Patch]\ArcGIS-<Version>-PFA-SEC2026U3-Patch.msp
Step 4: As a best practice, clear the browser cache and re-launch the browser after installing the patch.
Installing this patch on Linux
On Linux, the release date order of the patches matters when installing multiple patches. If an older patch is installed after a newer patch, the older patch will replace the newer patch and the fixes in the newer patch will be removed. The ArcGIS Enterprise Patch Notification tool, when the option to install all available patches is activated, installs multiple patches in order of release date starting with oldest to newest.
Complete the following install steps as the ArcGIS Install owner. The Install owner is the owner of the arcgis folder.
The ArcGIS product listed in the table must be installed on your system before you can install a patch. Each patch setup is specific to the ArcGIS product in the list. To determine which products are installed on your system, please see the How to identify which ArcGIS products are installed section. Esri recommends that you install the patch for each product that is on your system.
Step 1: Download the appropriate file to a location other than your ArcGIS installation location.
| ArcGIS Enterprise | |
| Portal for ArcGIS 12.1 | ArcGIS-121-PFA-SEC2026U3-Patch-linux.tar |
| Checksum (SHA256) |
391C999BCF436E62BFC41D27ECB565B69E7B6E516EA368ACB0FDE9BB34C1EAB2 |
| Portal for ArcGIS 12.0 | ArcGIS-120-PFA-SEC2026U3-Patch-linux.tar |
| Checksum (SHA256) |
B1300AA29DCDAC940B181A7D4DE727390FAD70C9F3E8DE0022053D5E0CFCA11C |
| Portal for ArcGIS 11.5 | ArcGIS-115-PFA-SEC2026U3-Patch-linux.tar |
| Checksum (SHA256) |
9D1B3A358A0C42A623F68A0BAAB921B5C589612255AAB60A63D8BA46AC050513 |
| Portal for ArcGIS 11.3 | ArcGIS-113-PFA-SEC2026U3-Patch-linux.tar |
| Checksum (SHA256) |
D195682865A2B47ABC1B7EC278FC7FFFF326134E1DB1CCFB8D6CFAD71FF674CD |
| Portal for ArcGIS 11.1 | ArcGIS-111-PFA-SEC2026U3-Patch-linux.tar |
| Checksum (SHA256) |
3BE47A1B9D2E7D2A21C32FDEB8BAA808F403AB89234FD8BDC1D52050E127D974 |
Step 2: Make sure have write access to your ArcGIS installation location, and that no one is using ArcGIS.
Step 3: Extract the specified tar file by typing:
% tar -xvf ArcGIS-<Version>-PFA-SEC2026U3-Patch-linux.tar
Step 4: Start the installation by typing:
% ./applypatch
This will start the dialog for the menu-driven installation procedure. Default selections are noted in parentheses ( ). To quit the installation procedure, type 'q' at any time.
Step 5: As a best practice, clear the browser cache and re-launch the browser after installing the patch.
Uninstalling this patch on Windows
To uninstall this patch on Windows, open the Windows Control Panel and navigate to installed programs. Make sure that "View installed updates" (upper left side of the Programs and Features dialog) is active. Select the patch name from the programs list and click Uninstall to remove the patch.
Uninstalling this patch on Linux
Navigate to the <Product Installation Directory>/.Setup/qfe directory and run the following script as the ArcGIS Install owner:
./removepatch.sh
The removepatch.sh script allows you to uninstall previously installed patches or hot fixes. Use the -s status flag to get the list of installed patches or hot fixes ordered by date. Use the -q flag to remove patches or hot fixes in reverse chronological order by date they were installed. Type removepatch -h for usage help.
Restart your ArcGIS services.
How to identify which ArcGIS products are installed
To determine which ArcGIS products are installed, choose the appropriate version of the PatchFinder utility for your environment and run it from your local machine. PatchFinder will list all products, hot fixes, and patches installed on your local machine.
Get help from ArcGIS experts
Download the Esri Support App