Release Notes for Cisco XDR 2.71
Release Date: August 5, 2026
New Features and Updates
Note: Only sections with new customer-facing features or updates in this release are listed below.
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Activity source updates on the Activities page |
Cisco Meraki and Oracle Cloud Infrastructure are now supported as activity sources on the Activities page. You can also filter the list of activities by these new sources using the Activity source drop-down list in the Filters drawer. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Merged device ID tracking |
Updated device lookup so that when duplicate devices are merged, Cisco XDR resolves previous device IDs to the current merged device details. If a device captured in an incident is later merged into another device, users can pivot from the incident to the merged device details without seeing a “device not found” error. |
— |
|
Meraki Network Clients source details |
On the Device Details page, the Meraki Network Clients Seen in Sources card and drawer now separate Reporting Appliance attributes from Client attributes to help distinguish the Meraki MX appliance reporting the activity from the client associated with it. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Endpoint Visibility Module version update |
Endpoint Visibility Module version 1.8.0 has been released for Windows amd64 deployments. This release provides broader Windows endpoint visibility by reporting non-system DLL loads, kernel driver loads, expanded registry monitoring, executable file version details, and MITRE ATT&CK framework version information in events. This release also fixes an EVM Windows kernel driver issue that could cause a system crash (BSOD), and improves event reliability, categorization, readability, and performance while reducing background activity noise. |
|
Feature |
Description |
Help Topic |
|---|---|---|
|
Retry failed task assignments |
You can now retry eligible failed task assignments from task and asset workflows without recreating the original task. This helps analysts rerun failed collection or analysis work while preserving operational context. |
|
|
Advanced auto asset tagging conditions |
Auto asset tagging rules now support additional negative and pattern-based conditions, including does not contain, does not start with, and regex-style matching. This helps security teams classify assets more accurately in complex environments. |
Previous Release Notes
To view the Release Notes for previous releases, see Previous Release Notes for Cisco XDR.