eyeSight v9.1.7 Release Notes

These release notes provide high-level descriptions of enhancements, new features, and fixed and known issues for Forescout eyeSight version 9.1.7 and its base module components. For the latest upgrade recommendations and validation steps, refer to the Forescout eyeSight v9.1.x Upgrade Guide. For installation prerequisites and procedures, refer to the Forescout eyeSight v9.1.x Installation Guide.

Important Considerations

Consideration Details
TLS and certificate validation

eyeSight 9.1.x upgrades from OpenSSL 1.0.2 to OpenSSL 3 and applies stricter TLS and certificate validation requirements. TLS 1.2 and TLS 1.3 are used by default. Earlier TLS versions are not recommended, although some components provide an option to use them for legacy interoperability.

After upgrading, devices that use outdated TLS versions, weak cryptographic settings, or certificates that do not meet current security requirements might experience authentication or connectivity issues. Environments that use certificate-based authentication, legacy IoT/OT devices, medical devices, embedded devices, or older infrastructure are more likely to be affected.

Forescout recommends reviewing certificate-based authentication deployments, validating certificate health and certificate chains, and confirming endpoint support for TLS 1.2 or TLS 1.3 before upgrading.

Important: Authentication or connectivity issues identified after upgrading might indicate existing certificate or TLS configuration issues that were previously accepted, rather than issues introduced by eyeSight.

For detailed guidance and pre-upgrade recommendations, see Certificate and TLS validation in the Upgrade Guide.

eyeExtend Product Compatibility

The following eyeExtend plugins are currently not compatible with eyeSight v9.1.7:

  • ArcSight Enterprise Security Manager

If these products are installed, you will not be able to upgrade to eyeSight v9.1.7.

 

The Upgrade Verifier (UV) plugin for v9.1.7 will see this reflected.

 

Update (July 2026): The previously reported compatibility issue for recently released eyeExtend plugins is resolved. See module and plugin updates for the latest compatibility details.

Plugin updates and compatibility: As of July 2026, the previously reported compatibility issue is resolved, and this release-note update includes the following eyeExtend plugin updates:
  • BigFix v1.5.8

  • Check Point Threat Prevention v1.3.2

  • McAfee ePO v3.4.3

  • Operational Technology v3.2.1

  • Passive Sensor v7.0.1

  • Trellix EX (previously FireEye EX) v1.3.0

  • Trellix HX (previously FireEye HX) v1.3.3

  • Trellix NX (previously FireEye NX) v2.2.0

You can access the eyeExtend product guides in the Doc Portal here.

Features/Enhancements

Security enhancement to FIPS configuration.

Input validation in the FIPS configuration process now strengthens eyeSight appliance security.

Improved SSO login service security.

Deserialization handling in the SSO login service has been enhanced to help prevent unauthorized code execution on eyeSight appliances, improving overall system security.

Fixed Issues

This release includes the following fixes below:

Issue # Description
EYST-36310, EYST-36314, EYST-36358 During startup, the service did not respond while starting RabbitMQ, which caused the Forescout appliance to become unresponsive and prevented the boot sequence from completing. This has been fixed.
EYST-36349 When an IP moved to a new device, the system created a new ID but did not notify the Enterprise Manager, leading to duplicate hosts and incorrect policy enforcement. This has been fixed. The system now notifies the Enterprise Manager immediately after an ID change, preventing duplicates and ensuring accurate tracking.

Solution Bundle Orders

Forescout Solution Bundles are composed of a packaged combination of entitlements for Forescout Software, Cloud Services, Integrations, and Premium Support Services designed to deliver comprehensive capabilities for defined use cases.

In the event that a customer has placed an order that includes an Entitlement Credit applied towards a Replacement Entitlement, the customer will continue to have access to their Current Entitlement for thirty (30) days from the date Forescout accepts the applicable order to facilitate the customer’s transition from the Current Entitlement to the Replacement Entitlement.