New Features and Enhancements
FortiSOAR release 7.5.3 focuses on usability, administrative, and security fixes. It does not introduce new features or significant enhancements. Users running releases 7.5.0, 7.5.1, or 7.5.2 are strongly encouraged to upgrade to release 7.5.3 to benefit from these fixes.
FortiSOAR Administrative Enhancements
- iFrame Configuration Settings: Release 7.5.3 (for 7.5.x series and 7.6.5 for 7.6.x and later series) introduces iFrame configuration options that allow you to control how external content is embedded within the application. Sandbox restrictions are enabled by default for enhanced security, and you can specify which domains are allowed to load inside iFrames.
For details, see the iFrame Settings topic in the System Configuration chapter of the "Administration Guide."
Security Enhancements
- New:Unique Encryption key for Data Protection: Release 7.5.3 now automatically generates a unique encryption key, per instance, during the Configuration Wizard process. This change significantly strengthens data protection by securing stored credentials, database entries, and inter-service communication with 256-bit encryption — all while maintaining full backward compatibility. All passwords saved after deployment are encrypted using this new key.
For more information, see the Deploying FortiSOAR chapter in the "Deployment Guide." - New: Advanced Development Features Tab in System Configuration: Added a new Advanced Development Features tab in the
System Configurationpage! This tab empowers administrators to review security risks and usage guidelines for creating or updating custom connectors and widgets. With this update, administrators now need to provide explicit consent—based on their organization's requirements—before users can create new connectors, widgets, or update existing ones.
For details, see the Advanced Development Features topic in the System Configuration chapter of the "Administration Guide." - Enhanced iFrame Widget Security: The iFrame widget now runs in a sandboxed environment by default, fully restricting the loading of external content. This update enhances the security by preventing Stored Cross-Site Scripting (XSS) attacks.
For details on the iFrame widget, see the Dashboards, Templates, and Widgets chapter in the "User Guide." - Enhanced Security Validation for Connector Configuration Updates: Beginning with release 7.5.3 (for the 7.5.x series) and 7.6.5 (for the 7.6.x series), any change to connector configuration fields, such as Server URL, Hostname, Address, Server IP, etc., requires users to re-enter all password-type fields before the configuration can be saved or applied. This update strengthens security by ensuring that when a server or endpoint detail is modified, the associated credentials are explicitly validated, reducing the risk of misconfiguration or unintended access.