MONTHLY PLATFORM PATCH AND MONTHLY SOFTWARE PATCH FOR THE API GATEWAY – JANUARY 2026
36893
30 January 2026
30 January 2026
January 2026
To: Layer7 API Gateway Customers
From: The Broadcom API Gateway Product Team
Subject: Monthly Platform Patch and Monthly Software Patch for the API Gateway – January 2026
Platform patches upgrade the underlying OS packages and other (non- Layer7 API) hardware/virtual appliance components where Common Vulnerabilities and Exposures (CVE) have been raised.
The Monthly Software Patch (MSP) is a cumulative update introduced to maintain system integrity and address Common Vulnerabilities and Exposures (CVEs) in Gateway software between minor and major release cycles. Unlike the Monthly Platform Patch (MPP), which targets only OS-level fixes, the MSP's scope varies by deployment:
- Appliance Gateways: Gateway software CVEs and minor JDK updates.
- Software Gateways: Gateway software CVEs.
- Container Gateways: OS and Gateway software CVEs and minor JDK updates.
These patches are delivered on a monthly basis unless a CVE has been discovered that requires immediate attention. Currently, none of the CVEs raised has caused issues with the Layer7 API Gateway or API Developer Portal, but they are being addressed as a preventative measure.
To bring the platform and Gateway up to the most recent level, apply the most recent monthly patch.
We recommend that all Gateway container and appliance customers (both hardware or virtual) of our Layer7 API Gateway/Developer Portal remain current with the platform patch level and the core application level.
You can download the latest monthly platform patch from the Layer7 API Management Solutions & Patches page or pull the latest image from Docker Hub.
- January 2026 MPP release addresses the CVEs related to Operating Systems.
- MySQL version is upgraded to 8.4.8 for Gateway v11.2.0 and MySQL version is upgraded to 8.0.45 for Gateway v11.1.x.
- The January 2026 MSP release addresses specific CVEs for Gateway 11.1.3. This patch is exclusively compatible with version 11.1.3 for both Appliance and Software Gateways.
Please be noted that Gateway 11.0 will reach End of Life in January 2026. Consequently, this is the final MPP release for Gateway 11.0
Note: Before you patch an appliance gateway, please ensure that you have sufficient disk space in the appliance to avoid space issues. If you encounter any space issues, please follow these instructions to add additional disk space. Increase Disk Space in Virtual Appliance
You can also call Broadcom Customer Care at +1 800 225 5224 in North America or visit https://www.broadcom.com/support/software/contact for the local number in your country.
Should you need any assistance, our Broadcom Services experts can help. For more information on Broadcom Services and how you can leverage our experience, please visit https://www.broadcom.com/support/services-support.