RELEASE 6.1.2.42921
6.1.2.42921 – Video Management System
Published: 20 May 2026
Release Notes
IMPORTANT: These release notes cover changes implemented since the latest major release (6.1.1.42471).
Breaking Changes
- Support for MacOS 12 will be discontinued in the next major release (6.2).
- The Paxton plugin will be removed from the distribution package. The latest release for Paxton Net2 Pro v5 / v6 (6.1.1.42624) will be available on the “Previous Releases” page on Cloud Portal.
- Security hardening:
Access-Control-Allow-Credentialsis now false. Browser integrations using cookie-based authentication on cross-origin requests (includingfetchwithcredentials: 'include',XHR.withCredentials = true, and Axios requests withwithCredentials: true) will stop working and must migrate toAuthorization: Bearer <token>.
New Devices / Operating Systems Support
- Raspberry Pi OS 13 (Trixie)
Security Updates
- Security hardening:
Access-Control-Allow-Credentialsis now false. Browser integrations using cookie-based authentication on cross-origin requests must migrate toAuthorization: Bearer <token>. - Server now sends HSTS headers during HTTP → HTTPS redirections. As a result, the initial connection is no longer vulnerable to SSL stripping and MITM attacks.
General Improvements
- Server Monitoring graph colors improved.
- VCA edge build size is optimized — debug symbols are removed.
- Localization has been improved.
- Timeline date format is consistent with the OS date format.
- It is now possible to download a full health report from the “Advanced > Logs Management” page.
Enterprise Functionality Improvements / Fixes
- Fixed the issue with reporting Live Streaming service usage.
Analytics Improvements / Fixes
- Added Intrusion Detection events support on Milesight cameras.
- Metadata parsing (object attributes) is added for the Vivotek analytics plugin.
- After upgrading to 6.1, selecting a Vehicle type in the Milesight plugin search box could search for bikes. Fixed.
- On Hikvision cameras, incorrect previews of analytic objects (Vehicle or LPR) were shown on the right panel in the Desktop Client. Fixed.
- The Vivotek analytics plugin could initiate a large number of false-positive error notifications. Fixed.
- The analytic event/object from the Vivotek SD9384-EHL could stop appearing in the Desktop Client after some time. Fixed.
- Dahua analytics plugin did not load for autodiscovered devices such as DH-SD22204UE-GN. Fixed.
- The built-in Milesight analytics could show unexpected “Unknown” objects. Fixed.
- The analytics database could completely fill the storage after upgrading to v6.1. Fixed.
Device Support and Fixes
Hanwha Devices
- On Hanwha Profile G cameras such as XND-9083RV, imported archives could have missing periods after network disconnection. Fixed.
Device-Specific Fixes
- I/O monitoring was enabled on Axis devices after initialization even if it was not enabled in the Desktop Client. Fixed.
- The secondary stream was not available on Dahua DH-IPC-HDBW2441* camera models after upgrading to 6.1. Fixed.
- Dahua DH-IPC-HFW366* camera models now support 2-way audio.
- Fixed PTZ on Hikvision DS-2DP3236ZIXS-D/440.
- If Hikvision cameras were not connected to the Internet, timestamps of thermal events could differ. The system time is now used.
- After upgrading to v6.1, some Hikvision cameras such as DS-2CD2* could become unauthorized. Fixed.
- After upgrading to 6.1, Server could unexpectedly change stream configuration on HikVision DS-2TD2617* camera models after Server reboot. Fixed.
- Incorrect camera firmware version was displayed for the Hikvision DS-2CD2743G2* model line with firmware 5.7.19+. Fixed.
- On Milesight devices, audio alarm can be enabled even if audio input is disabled in the camera settings.
- Files exported from some Arecont Vision panoramic cameras could not be played back. Fixed.
- Fixed PTZ on Hikmicro HM-TX3840-10*.
Newly Supported Devices
- Advantech ADAM-6250
Encoders Added to the Analog List
- Hikvision DS-7632* series, DS-9032HUHI-K8
- Avycon AVR-NSV64E2N, AVR-NSV32P16
Multisensor Cameras
- Hikvision DS-2SE4C425MWG* and DS-2CD2346G3D* series
- Hikmicro HM-TD1228*, HM-TX3840-10* and HM-TD2628* series
- Axis Q6300
- IVSEC NC542ADX
- Dahua DH-IPC-HDBW2449F
- Pelco SMLE1-24V5* and SMLE1-32V5* series
- Panasonic wv-s8530
- Invid VIS-P4DUALDRIR28NH* series
- Digital Watchdog DWC-XMDS20Mi, DWC-XMDF32H, DWC-XDBJ10Mi, DWC-XTBG05DiT
- Safire Smart SF-IPTB640A*, SF-IPTB384A*, SF-IPTB256A* series
Advanced PTZ
- Sparsh SS-IND212* series
- Pelco ESCE1-2X40* series
Bug Fixes
General UI Fixes
- The “Floor/table” mount option in the dewarping settings was not visible by default. Fixed.
- Some entries could appear in the Audit Log as actions with no user account specified. Fixed.
- Playback speed behavior has been reverted: when video is paused, playback speed will reset. An option to change this behavior will be provided.
- “Do HTTP(s) Request” rules with whitespace in the URL did not work in 6.1+. Fixed.
- Fixed scrolling issues with events in the Notification Panel.
- In multi-Server environments, multiple “Unsuccessful login” entries appeared in Audit Trail when opening bookmarks from a device where the archive was spread across different Servers. Fixed.
- In large systems, recording and device statuses could be displayed incorrectly after upgrading to v6.1. Fixed.
- Fixed a Desktop Client crash that could occur when browsing the Timeline with 4x4 or 5x5 layouts open.
- On some Sites, users failed to authenticate via temporary links and were prompted to authenticate through Cloud instead. Fixed.
- Fixed scaling issues when many Server Monitoring items were opened on the layout.
- In multi-monitor environments, configurations were not restored after restart when multiple instances were opened on specific monitors. Fixed.
- Default user groups (Administrators and Power Users) were also selected as recipients in the Send Mail action even when only one email address was specified. Fixed.
- The Desktop Client did not restore the state of the “Bookmarks” and “Events” tabs after restart. Fixed.
- In certain environments, the Desktop Client could show an empty Timeline portion past a certain date. Fixed.
- The role description in Group Details was not fully visible without scrolling. Fixed.
- In User Management > Resources, group-level selection in search did not work consistently. Fixed.
- Bookmarks could sometimes begin playing a few seconds earlier than their start time. Fixed.
- Fixed a Desktop Client crash when dragging a Cloud layout onto a Video Wall.
- Multi Video export to .nov format could freeze when exporting several hours of video. Fixed.
- The “Available by Permissions” setting in the Resources tab for a new group/user could be reset. Fixed.
- The Desktop Client could lose its Cloud connection and require authentication again when connecting to a different Server version. Fixed.
- Fixed a visual rendering bug that caused the system tray icon context menu to display unreadable characters on Windows 10 Enterprise 2016 LTSB (build 1607).
Server Fixes
- Media2 requests were sent to devices even if the “Use Media2 to fetch profiles” advanced option was set to “Never.” Fixed.
- Devices could be shown as unauthorized after a password reset even when the password was correct. Fixed.
- Motion & Events Panels could scroll down on their own after idling for a while. Fixed.
- In some cases, it was not possible to merge a Server with a Site that had a custom certificate installed. Fixed.
- Emails initiated by a Server were missing the URL to recordings in the plain-text body. Fixed.
- Server could crash after a WebRTC camera was created, began streaming live, and then stopped its live stream. Fixed.
- If a user’s OU was changed in the LDAP server, Server treated the user as new and created a duplicate user entry after LDAP synchronization. Fixed.
- When adding RTSP streams, Server did not check all supported authentication algorithms. Fixed.
API / SDK Fixes
- Fixed streaming issues via
vmsproxyusing FFplay. - When performing an export using the
/rest/v3/devices/method with thecontinuousTimestampsparameter specified,utcTimestampswere ignored. Fixed. - REST API:
rest/v4/events/logchanged itseventsOnlyparameter behavior. - API responses containing GUIDs are changed in V4 so there will be no
{}symbols. - In v3 or earlier:
{%guid_string%} - In v4:
%guid_string% - Fixed an incorrect response from
rest/v4/servers/this/storageswith ETag. - Timezone ID and offset information is added to exported media file metadata when export is performed via the
/rest/v3/devices/method. - The readonly field
prolongedis added torest/v4-/events/rulesto evaluate triggers by rules only. - WebRTC metadata packets are now dropped when channel capacity is insufficient.
- WebRTC WebSocket connection failed after a live stream was restarted. Fixed.
- Plugin Analytics SDK:
utilitiProvider()->cloudToken()did not return the token. Fixed. - Added advanced PTZ functions that were missing in the v4 REST API compared with the legacy
/api/ptz, including ContinuousFocusPtzCommand, AbsoluteLogicalMovePtzCommand, relative pan/tilt/zoom/focus/rotation capability bits, ViewportPtzCapability, FlipPtzCapability, HomePtzCapability, and AuxiliaryPtzCapability. - Server responded with “Not found” to unauthorized JSONRPC requests instead of “Unauthorized.” Fixed.
GET /rest/v4/devicesrequired{}when using the_filteroption. They are now optional.
In-Client Upgrade
Build Number: 42921
Password: 9ce7bm
