Unifyed Announces General Availability of Engage v12.36

Thursday – June 25, 2026

Unifyed Engage 12.36

Summary

The following have been updated with new enhancements and/or resolved defects: 

  • Expired Notifications remaining in Notifications Applet 
  • Broken links for Images and Documents submitted in Forms 
  • Non-Administrator activities displaying in Audit Logs  

Enhancements Form Data Reset Functionality

Implemented the Reset Form Data feature in Engage v12 Studio → Content → Forms, allowing authorized administrators to clear historical form submissions without affecting form configurations, permissions, or live widgets. Added confirmation prompts, backend permission validation, activity logging, export response reset logic, and submission status reset to allow fresh submissions after data clearance. 

Security Vulnerability

Implemented multiple security enhancements to strengthen portal security posture and       address infrastructure-level vulnerabilities identified during external security assessments. Anti-clickjacking protection has been enforced by configuring X-Frame-Options and frame control policies to prevent unauthorized embedding of application pages. TLS configurations were hardened by enabling OCSP Stapling for improved certificate revocation validation, reducing the risk of certificate misuse. 

Additionally, several critical HTTP security headers were introduced to improve browser-side protections. Cross-Origin-Opener-Policy (COOP) and Cross-Origin-Resource-Policy (CORP) were implemented to strengthen cross-origin isolation and resource access control. Referrer-Policy was configured to limit sensitive referrer information leakage, and Permissions-Policy was added to restrict access to privileged browser APIs. These improvements collectively enhance protection against clickjacking, certificate abuse, data leakage, and cross-origin security risks while aligning the application with modern security best practices. 

Security Vulnerability – NGINX CVE-2026-42945

Resolved the reported CVE-2026-42945 vulnerability impacting NGINX by upgrading the server from version 1.29.5 to the secure patched version 1.30.1. A detailed configuration review was completed to identify potential rewrite-rule exploit conditions, and necessary hardening updates were applied to mitigate the vulnerability. This upgrade ensures the environment is aligned with the latest security advisory and protected against known exploit paths. 

Supported Browser & Devices

This release is supported on the following devices and browsers:

Supported Devices  
Device Operating System
Android Version 10
iPad Version 13.1
iOS Version 12 and Above
 
Supported Browsers  
Browser Version
Chrome 84.0.4147.89 & above
Edge 84.0.522.48 & above
Firefox 79.0 & above
Safari 12.0 & above

About Unifyed

Unifyed is a pioneer in higher education software and serves over 150 colleges and universities around the world. Unifyed partners with colleges and universities to deliver affordable solutions that help recruit, engage, educate, retain and graduate 21st century students.

For the detailed release note please visit : my.unifyed.com