STARFACE 10, 9 and 8.1 get patched on the same day — which version belongs on your PBX

On 8 July 2026 STARFACE released three security patches at once: 10.0.1.7, 9.0.3.8 and 8.1.3.7. Three version numbers, three product lines, one day — and all three release notes carry the same sentence: this patch closes a critical security hole in the STARFACE system. Which line your PBX runs does not decide whether you get the fix. It decides what number the fix arrives under.

What the four digits mean

STARFACE numbers its server releases with four parts. The download overview in the STARFACE wiki puts a type next to every one of them — MAJOR VERSION, SERVICE RELEASE, SECURITY PATCH or HOTFIX — and that column is what makes the scheme readable:

VersionType per vendorReleased
10.0.0.26MAJOR VERSION10 Feb 2026
10.0.1.6SERVICE RELEASE8 June 2026
10.0.1.7SECURITY PATCH8 July 2026
10.0.2.5SERVICE RELEASE6 Aug 2026

So the first two digits name the line, the third counts service releases inside that line, and the fourth counts builds inside that service release. 10.0.1.7 is not a new feature release; it is 10.0.1 with a patch on top.

The practical consequence matters more than the scheme itself: comparing numbers across lines tells you nothing. 9.0.3.8 has higher third and fourth digits than 10.0.1.7 and is nevertheless the older product. “We are on 3.8” is not an answer. The line is the answer.

Three lines, one release date

STARFACE maintains several lines side by side and serves them on the same day. That habit is not new — what changes over the years is how many lines are on the list:

DayVersions released that day
8 July 202610.0.1.7 · 9.0.3.8 · 8.1.3.7
22 June 20269.0.3.7 · 8.1.3.6
9 July 20259.0.3.4 · 8.1.3.4 · 8.0.0.16
28 Nov 20249.0.0.10 · 8.1.3.3 · 8.0.0.15 · 7.3.1.6
14 Nov 20238.1.0.11 · 8.0.0.14 · 7.3.1.5 · 7.2.1.5 · 7.1.1.11

All but one of these versions carry the type SECURITY PATCH in the download overview, right down to lines that are long gone from the current download page and only survive in the archive. The one exception shows how little the label weighs: the download overview files 9.0.3.4 as a SERVICE RELEASE, while the release notes for that very version report the fix of a critical vulnerability in a system component. The release notes for 8.1.3.7 and 9.0.3.8 add a sentence the 10 line does not get: install this security patch or move up to STARFACE 10.0.1.7. The vendor offers both routes and forces neither.

From 8.0 upwards there is no reinstall

The migration section of the release notes is unusually clear for once: an update from STARFACE 8.0 and higher to STARFACE 10 installs as an ordinary update through the web interface and requires no reinstallation. The cut runs below that, and the reason is the backup format:

  • STARFACE 8.0 reworked backup and recovery. STARFACE 10 imports backups from 8.0 and above only.
  • Systems on 7.3 or older cannot go to 10 directly — appliances, VMs and clouds alike. They go to 8.0 or 8.1 first, produce a backup in the new format there, and only then move on.
  • Free disk space for the update to 10: at least 6 GB, plus twice the size of the backup being imported.
  • Modules may need adjusting. Check with the module vendors for a compatible version before you start, not after.
  • After the update the STARFACE apps have to be brought up to date as well, and the version 10 desktop apps additionally need port 9092.

One more list is worth reading before you plan anything: the appliance models STARFACE 10 still supports are Compact SIP V2 and V2.1, Compact V3, V4 and V4.1, Advanced V6 and V7, Enterprise V6 and V7, Platinum V6 and V7. Hardware that is not on it does not get there by planning better.

The check itself takes five minutes

  • Admin → System status → overview. A warning triangle appears here when the update option has expired or the installed version is higher than the licensed one — two conditions that quietly decide whether the next patch is even offered to you.
  • Admin → Server → Licences tab. Shows whether an update option exists, for how many users, and the date it runs out.
  • Admin → Server → Status tab. Triggers the search for new versions and shows the release notes for what it finds. Whether an offered version can actually be installed depends on the licences on the box and on an update contract. The same screen shows under module updates whether the installed modules are compatible with the new version — the line worth reading twice.
  • Tick separate download and installation. The download then runs in the background and only the installation takes the system down — no inbound or outbound calls while it runs.
  • A backup is taken automatically before the installation, and a failed install is rolled back to the previous state without data loss.

Which version it should be

On the 10 line: 10.0.1.7 at the very least, since that is where the July fix lives. The newest state of the line as of 19 August 2026 is 10.0.2.5.

On 9.0 or 8.1: 9.0.3.8 and 8.1.3.7 close the same hole on those lines, and both lines are still listed as supported. Staying put is a defensible decision — staying two patches back is not the same decision.

On 8.0 or older: those lines have moved to the archive for discontinued versions, where STARFACE itself names the consequences: security holes, missing features, no support. The route out is 8.0 or 8.1 first, then 10.

The honest limitation

STARFACE marks every version with a product status — supported or discontinued — but publishes no date at which a line will flip from one to the other. There is no lifecycle table to plan against. You can look up today’s status; you cannot look up next year’s.

The security notes are equally sparse by design. STARFACE states it plainly in the older patch notes: to protect customers who have not yet applied the update, it cannot disclose further detail about the specific content of the vulnerability. The July patch accordingly carries neither a CVE id nor a severity — only a second line in the fix notes hinting at the area: access protection for the PBX communication interfaces was improved to prevent unauthorised requests. STARFACE does name a CVE where a third-party component is involved — CVE-2023-46604 in the ActiveMQ library back in 2023, for one. For holes in its own code the release note is the whole signal.

Even the release dates are not entirely firm. 10.0.2.5 is dated 30 July 2026 in the release notes and 6 Aug 2026 in the wiki download overview; 10.0.1.6 appears as 1 June 2026 and 8 June 2026 in the same two places, while the vendor’s own press release says service release 1 was cleared on 8 June. Where the two pages disagree, the tables above carry the download overview’s dates — those match the press release.

Watching a vendor that announces nothing

When there is no published end-of-support date, the release itself is the only signal there is — and it arrives on a page you have to remember to open. That is a poor fit for a PBX, which is precisely the box nobody looks at while it works. The STARFACE page on patchletter tracks the released versions, and you can have an email when a new one appears. Free, no account, one-click unsubscribe.

Version numbers, release types and product status from the STARFACE release notes and the download overview plus its archive of discontinued versions; administration paths from the wiki pages on performing an update, on system status and on reading licence information; the service release 1 date from the vendor press release. All retrieved 19 August 2026. Dates as published on that day and deliberately left as they were.