# FileMaker Server 22.0.5 and 21.1.7 Updates Available

**URL:** <https://the.fmsoup.org/t/filemaker-server-22-0-5-and-21-1-7-updates-available/5285>\
**Category:** Floating Topics\
**Tags:** security, filemaker-server\
**Created:** [February 17, 2026, 5:55pm UTC](https://the.fmsoup.org/t/filemaker-server-22-0-5-and-21-1-7-updates-available/5285 "2026-02-17T17:55:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![xochi](https://avatars.discourse-cdn.com/v4/letter/x/0ea827/32.png) [@xochi](https://the.fmsoup.org/u/xochi)\
**Post date:** [February 17, 2026, 5:55pm UTC](https://the.fmsoup.org/t/filemaker-server-22-0-5-and-21-1-7-updates-available/5285/1 "2026-02-17T17:55:43Z")

</div>

Includes some bug fixes as well as some important security updates.

See [Claris FileMaker Server Release Notes](https://help.claris.com/en/server-release-notes/content/index.html)

---

<div class="post-metadata">

**Author:** ![xochi](https://avatars.discourse-cdn.com/v4/letter/x/0ea827/32.png) [@xochi](https://the.fmsoup.org/u/xochi)\
**Post date:** [February 17, 2026, 6:01pm UTC](https://the.fmsoup.org/t/filemaker-server-22-0-5-and-21-1-7-updates-available/5285/2 "2026-02-17T18:01:07Z")

</div>

Here are the Apache Tomcat vulnerabilities fixed in 22.0.5:

CVE-2025-31650 - **Important: Denial of Service via invalid HTTP priority header**

CVE-2025-55752 - **Important: Directory traversal via Rewrite Valve with possible remote code execution if PUT is enabled**

CVE-2025-55754 - **Low: Console manipulation via escape sequences in log messages**

CVE-2025-61795 - **Low: Delayed cleaning of multipart upload temporary files may lead to DoS**

See [Apache Tomcat® - Apache Tomcat 10 vulnerabilities](https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.47)

---

<div class="post-metadata">

**Author:** ![xochi](https://avatars.discourse-cdn.com/v4/letter/x/0ea827/32.png) [@xochi](https://the.fmsoup.org/u/xochi)\
**Post date:** [February 18, 2026, 3:13pm UTC](https://the.fmsoup.org/t/filemaker-server-22-0-5-and-21-1-7-updates-available/5285/3 "2026-02-18T15:13:19Z")

</div>

There appear to be some questions being raised as to whether all the vulnerabilities were fixed or not:

> Following recent communications with Apple, it has been confirmed that, despite previous statements, only some of the issues were actually fixed, while others remain open.
> 
> While your OFFICIAL release notes publicly stated that these vulnerabilities were fixed, in reality, only some issues were addressed, and others remain open. This discrepancy is concerning, as it creates a false sense of security for users. Your release indicates that vulnerabilities were addressed, yet CRITICAL components remain exposed, posing a serious risk.
> 
> I encourage to clarify the current status of these issues. If no clear clarification is provided, I will consider publishing the full technical details in the interest of transparency and responsible disclosure.

[Link](https://community.claris.com/en/s/question/0D5Vy00001ipqYvKAI/january-8-2026-community-live-protect-your-filemaker-environment-with-the-latest-update)

---

<div class="post-metadata">

**Author:** ![DanShockley](https://avatars.discourse-cdn.com/v4/letter/d/9f8e36/32.png) [@DanShockley](https://the.fmsoup.org/u/DanShockley)\
**Post date:** [February 18, 2026, 4:35pm UTC](https://the.fmsoup.org/t/filemaker-server-22-0-5-and-21-1-7-updates-available/5285/4 "2026-02-18T16:35:48Z")

</div>

I’m also concerned by the ongoing issue where Apple appears to be reluctant to give credit and bounties to researchers. I don’t do that kind of work, but, like all of us, I rely on the results they provide: stronger products. If Apple keeps giving security researchers the impression that they will be cheated, they might decline to help improve Apple products. Or, it could encourage those with less scruples to shop the vulnerabilities around. That’s all bad for those of us who rely on Apple product security.

---

<div class="post-metadata">

**Author:** ![Malcolm](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/malcolm/32/196_2.png) [@Malcolm](https://the.fmsoup.org/u/Malcolm)\
**Post date:** [February 19, 2026, 4:00am UTC](https://the.fmsoup.org/t/filemaker-server-22-0-5-and-21-1-7-updates-available/5285/5 "2026-02-19T04:00:08Z")

</div>

Thanks for bringing that thread to our attention.

---

<div class="post-metadata">

**Author:** ![OliverBarrett](https://avatars.discourse-cdn.com/v4/letter/o/f19dbf/32.png) [@OliverBarrett](https://the.fmsoup.org/u/OliverBarrett)\
**Post date:** [February 19, 2026, 12:15pm UTC](https://the.fmsoup.org/t/filemaker-server-22-0-5-and-21-1-7-updates-available/5285/6 "2026-02-19T12:15:08Z")

</div>

Go ahead and publish the details (!) …. unless you’re under some kind of NDA or otherwise prohibited.

---

<div class="post-metadata">

**Author:** ![xochi](https://avatars.discourse-cdn.com/v4/letter/x/0ea827/32.png) [@xochi](https://the.fmsoup.org/u/xochi)\
**Post date:** [February 19, 2026, 2:46pm UTC](https://the.fmsoup.org/t/filemaker-server-22-0-5-and-21-1-7-updates-available/5285/7 "2026-02-19T14:46:24Z")

</div>

> [@OliverBarrett](#):
>
> Go ahead and publish the details

This warning comes from someone else, see the link above.
