IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.
Release Notes Tanium Client (Version 7.9.3.5139)
This Release Notes document lists changes to the Tanium Client v7.9.3.5139. The release notes for the previous Tanium Client version can be found here: Release Notes Tanium Client (Version 7.8.4.1333).
Tanium Client 7.9.3.5139
- Tanium Cloud availability: 2026-09-08.
- On-premises availability: 2026-09-08.
Special Notes
- This release of the Windows Tanium Client is now a 64-bit binary on 64-bit Windows machines. 32-bit Windows installs will continue to install the 32-bit Tanium Client.
- This release of the Tanium Client requires a change to host-based security exclusions on Windows machines.
- For additional details on the 7.9.3 Tanium Client, see this page.
- Updated the End User License Agreement (EULA) presented by the Tanium Server, Client, Module Server, and Zone Server installers to the August 2026 version.
Security Updates
- None.
New Features
- The Tanium Client logs on startup the architecture of its compiled binary and the underlying operating system, like: "
Client compiled for x86 running on x86_64". - The Tanium Client now uses a highest random weight hashing algorithm to decide which downloaded chunks to cache, distributing chunks across peers in a neighborhood so each chunk is cached by a single peer to reduce duplicate storage and bandwidth usage.
- Adds the
Onlinesensor as a built-in sensor in the Tanium Client, which always returnsTruefor extended entities. - A 64-bit Tanium Client now routes package action commands through a 32-bit process by default, so package content does not need to be rewritten for 64-bit compatibility.
- The new 64-bit Tanium Client for Windows executes internal runscript packages in the 32-bit helper process for consistent behavior with legacy content.
- Adds Crashpad crash reporting support to the Tanium Client.
- Adds 32-bit OpenSSL and a 32-bit script runner to the 64-bit Tanium Client installer for Windows, enabling legacy 32-bit sensor and package content to execute.
- The Tanium Client now enforces that entity computer ID namespaces are non-zero, as zero is reserved for the Tanium Client itself.
- Adds a specific error message to
cx-socketcommunications so the Tanium Client can signal a failed management rights evaluation without waiting for the connection to time out. - Adds a
test computer-namediagnostic command to the Tanium Client that explains how the value returned for theComputer Namesensor is resolved on an endpoint, including the configuredHostFQDNandHostDomainNameoverrides and each platform resolution step. - Adds the
MacComputerNameModesetting to the Tanium Client which controls how theComputer Namesensor is resolved on macOS endpoints, acceptinghostname,SCComputerName, orSCLocalHostNameto avoid the frequently changing network-derived names. - The Tanium Client on non-Windows platforms now provides the
FirstInstallandLastInstallconfiguration values, matching the behavior already present on Windows.
Improvements
- Tanium Platform components now ship with OpenSSL v3.5.8.
- Tanium Platform components now ship with Python 3.12.14.
- The
libpqPostgreSQL client library bundled with Tanium Platform components no longer initializes OpenSSL itself, avoiding a duplicate initialization that could crash the hosting process. - Tanium Platform components now ship with SQLite v3.53.2.
- The Tanium Client now implements the download RPCs (
CreateDownload,GetDownload,ListDownloads,DeleteDownload) of its gRPC API, letting callers manage API downloads over gRPC instead of SOAP to reduce concurrent connections. - Tanium Platform components now ship with v8.20 of
libcurl. - Tanium Platform components now ship with libexpat v2.8.0.
- Tanium Platform components now ship with xz library v5.8.3 and had removed unnecessary dependencies on it.
- Tanium Platform components now ship with
protobufv3.25.5. - Removes unused module components from the Python builds distributed with Platform software components.
- Updated the version of
python-sixshipped with Platform to v1.17.0. - Platform components now ship with
pyasn1v0.6.3. - Provides a single Tanium Client installer for Windows that installs the 32-bit or 64-bit client to match the architecture of the target system.
- Increases the Tanium Client sensor child process send timeout from 10 seconds to 1 minute, reducing the frequency of "
Failed to send to sensor child process" errors. - Adds a 32-bit helper process to the 64-bit Tanium Client for Windows to execute legacy sensor and package content that requires a 32-bit runtime.
- The Tanium Client now deletes outbound module messages from disk that it cannot parse, decrypt, or verify when loading them from its local database, rather than failing to deliver subsequent messages.
- The Tanium Client now includes extension isolation configuration in CX start messages, allowing CX extensions to start without performing their own configuration lookup.
- The Tanium Client no longer duplicates sensor execution log entries in
log0.txt; executions are now logged only tosensor-history0.txtwhen theLogSensorExecutionsetting is active. - Adds optional SHA-256 hash support to the Tanium Client download API.
- Adds a persistent store of inbound module messages to the Tanium Client where messages are saved before being acknowledged to the Tanium Server.
- Adds the protocol buffer definitions needed for module messaging between Tanium Servers and Tanium Clients.
- Ensures that certificate serial numbers are non-zero and fit within a 20-byte field, in keeping with RFC 3280.
- Tanium Platform components now ship with the boost v1.87 libraries.
- Improves data protection on Linux systems so that the data protection key resides in the Tanium application directory rather than a user home directory, making decryption less dependent on which user account runs Tanium commands.
Bug Fixes
- Fixed an omission in the Tanium Windows installers where the
OriginalFilenameversion field was missing, which prevented building an AppLocker Publisher rule against them. - Fixed an issue in Tanium Windows binaries where the version resource did not include an
OriginalFilenameentry, causing AppLocker publisher rules to fail to build for signed binaries such asTaniumClient.exeandTaniumCX.exe. - Prevented a crash in the Tanium Client logging path when evaluating a sensor with no definition for the endpoint's platform, which previously caused group evaluation to fail and report ECF manifest errors.
- Fixes a crash in the Tanium Client on Windows endpoints with .NET Framework 1.1 installed, where the sensor sub-process would fail to start and every sensor would return
Failed to send to sensor child process: broken pipe. - Fixed a race condition in the Tanium Client download chunk cache where a cached file entry could be released without holding the cache lock, corrupting the internal age-list and crashing during cleanup.
- Fixes an issue in the Tanium Client where an inter-process communication socket file might be created outside the client's installation directory.
- Fixed an inaccuracy in the Tanium software bill of materials where the
llhttppackage was listed as a runtime dependency; it is now correctly marked as a build-time-only dependency and no longer flagged as vulnerable in dependency scans. - Fixed an issue in the Tanium Client where enqueued CDN config request messages did not trigger transmission of the queue.
- Fixes an issue in the Tanium Client where a download database that could not be loaded would produce a repeating
no such columnSQL error and prevent the client from starting; the client now resets the download database when it cannot be loaded. - Fixes a busy loop in the Tanium Client caused by an invalid module message batch not being cleared between processing runs.
- Fixes an omission in the Tanium Client where unicast and broadcast message sequences were not trimmed during registration.
- Prevents Tanium Clients from publishing unicast messages to other clients or sending broadcast messages; such messages are now blocked at the client and dropped at the Tanium Server.
- Fixes an issue where unzipping a file with malformed timestamp metadata would throw an
InvalidDateerror; out-of-range timestamp fields are now clamped to the expected range. - Fixes an issue in the Tanium Client where an invalid
GetNumericcall for a mismatched integer size would throw an assertion instead of logging a non-fatal error. - Fixes an issue on Solaris x86 where Tanium Client mailbox messages using Protobuf
bytesfields were processed incorrectly due to incorrect endianness handling. - Fixes an issue in the Tanium Client where connections used to retrieve bandwidth throttle information always closed after 5 seconds because the idle timer was not reset when throttle messages were received.
- Fixes an issue in the Tanium Client test registration command where the
ServerPortsetting from the local client configuration was not respected, causing the command to connect using the default port. - Fixes an issue in the Tanium Client installer for Windows where the
TaniumClient.exeinbound Windows Firewall rule was not removed during uninstallation. - Fixed an issue on AIX where the Tanium Client's IP Address sensor failed with an EADDRNOTAVAIL error caused by a defect in the
getifaddrscompatibility shim, which queried the network interface mask using a zero address instead of the interface's own address. - Fixes an issue in the Tanium Client
cx-socketconnection handler where a reused event could cause the error "Callback is already connected to another source" to be reported. - Fixes an issue where a Tanium Client did not regenerate its computer ID after a Tanium Server database was reverted to an earlier snapshot, leaving the client able to register but unable to report question results and causing encrypted messages for the unknown computer ID to be dropped.
- Fixes a busy loop in the Tanium Client where it would continuously resend entity ID requests, triggering a failed
m_availableComputerIds.count == 0assertion, when interpreting server-provided computer IDs. - Corrects the CPE identifier for the
xzlibrary in Tanium platform SBOMs so that the vendor readstukaanirather than a wildcard. - Fixes an issue in the Tanium Client where the
tanium_cx_channel_responses_bytes_sent_totalmetric always reported zero instead of the number of bytes sent. - Fixes an omission in the Tanium Client where the
TANIUM_SUPPORTS_DISKLESS_MAILBOXenvironment variable was not set, leaving the Python diskless mailbox interface unavailable to Python sensors. - Fixes an issue in the Tanium Client uninstaller for Windows where
uninst.exeand other files left in the application directory could be removed after a subsequent reboot. - Fixes an issue in the Tanium Client download API where two requests with the same path but different URLs could overwrite the same downloaded file; the API now allows only a single URL per download path.
Known Issues and Workarounds
- None.
Workaround: Not needed.