Azul Payara Server and Micro 7.2.0 are now available. Alongside a security fix that runs through every supported branch, this cycle brings Jakarta EE 11 certification, MicroProfile 6.1 support, and a handful of upgrades worth knowing about before your next deployment window.
What’s New in Azul Payara 7.2.0?
Payara Server 7.2.0 is Jakarta EE 11 certified across Full Platform, Web Profile, and Core Profile.
Payara Micro 7.2.0 implements the Web Profile and Core Profile APIs. Both ship MicroProfile 6.1 in full – Config, Metrics, Health, Fault Tolerance, JWT, OpenAPI, REST Client and Telemetry Tracing – and both pick up Grizzly 5.0.2, the transport built for the Jakarta EE 11 era.
Two changes carry over to both Server and Micro this month: backwards compatibility for defining implicit CDI via glassfish-application.xml, which eases migrations that relied on the legacy descriptor; and Payara major-versioned deployment descriptors, which let an application pin itself to a specific Payara major version.
Bug fixes this month include the IBM MQ resource adapter failing to deploy with a custom metrics.xml, restart-deployment-group not showing progress while running, and stale attributes lingering in httpAttr.inc. Beyond Grizzly, component upgrades touch Woodstox, the Jakarta MVC API, JNA, Reactor Core, SmallRye Common and Config, JLine, and the Jackson BOM – for the full list, see the release notes https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html
Backported by Design: The Brute Force Fix Across 4, 5, 6, and 7
Brute force attack prevention for authentication has been backported across Azul Payara Server and Micro 7.2.0, 6.40.0, 5.89.0, and 4.1.2.191.57. The fix originated in Eclipse GlassFish and was ported back into the Payara codebase, reflecting the shared ancestry between the two projects.
Shipping a patch across the full supported lifecycle, not just the newest major release, is the practice long-running Azul customers rely on. Azul is a registered CVE Numbering Authority under CISA and DHS oversight, with backports delivered to every supported version on a published monthly schedule; there’s no reason to delay upgrading based on the major-version line you’re running.
6.40.0 also closes two Jackson CVEs (CVE-2026-54512 and CVE-2026-54513) affecting the PolymorphicTypeValidator, alongside a Jackson BOM upgrade. The 7 line is not affected by these two.
What About Azul Payara Community?
For teams on the open-source distribution, Azul Payara Community 7.2026.7 tracks the same Payara 7 development line and carries the same security fix, bug fixes and component upgrades as Server and Micro 7.2.0. You can download Payara Community here: https://payara.fish/downloads/payara-platform-community-edition/
Ready to Upgrade?
The jakarta.* namespace is stable between EE 10 and EE 11, so teams on the 5 or 6 line can move existing applications to Payara 7 by upgrading the runtime rather than rewriting code. Migration assessments are available through your Azul account team.
See the full release notes for Azul Payara 7.2.0 here: https://docs.azul.com/payara/release-notes/release-notes-7.2.0.html
Request your free trial of Azul Payara https://www.azul.com/azul-payara-trial/