Araxis Merge 2026.1
Araxis Merge 2026.0
Araxis Merge 2025
Pre-2025: Windows, macOS
This release features full support for macOS 27 Golden Gate. Merge for Windows now offers the same discoverable, fluid navigation through every change in every file of a folder comparison as Merge for macOS. The release also provides important security improvements, as well as many other enhancements and fixes. Please read the release notes below for a complete list of changes.
This is the current production-quality release that Araxis recommends for all users. In view of the security fixes present in this release, all users of older versions of Merge are encouraged to upgrade.
This release is available at no extra cost to all customers with upgrade/support entitlement covering the build date indicated in the download box below. This includes everyone who purchased Merge within the year prior to that date.
This release is tested and supported on the following platforms:
The following platforms are supported and expected to work, though they are not routinely tested:
macOS Merge for macOS is fully supported, optimized, and tested on macOS 27 Golden Gate. Support for macOS Golden Gate replaces that for macOS 14 Sonoma, so Merge 2026.1 for macOS requires macOS 15 Sequoia or later. #7238 #7265
Windows Stepping backwards and forwards fluidly through all the changes within all the files of a Two-way with file comparison
or Three-way with file comparison
split-view folder comparison is now discoverable, thoroughly integrated, and comprehensive. For general documentation, please see the Navigation sections of the revised Comparing Text Files (or Typed/Pasted Text), Three-Way File Comparison and Merging, and Comparing Folders topics. #7248
Earlier versions of Merge for Windows offered a subset of this capability only through the CtrlPage Up and CtrlPage Down file comparison keyboard shortcuts. Merge for Windows now provides the complete and refined implementation introduced in Merge 2024.6000 for macOS.
This feature involved many coordinated changes:
For all comparison types, the ribbon Previous change in comparison
and Next change in comparison
buttons have been renamed from Previous change and Next change. They now always operate on the entire comparison, as do their keyboard shortcuts. Previously, they operated only on the comparison pane that had focus. Their tooltips have been updated to Move to the previous change in the entire comparison (Ctrl+Alt+Up) and Move to the next change in the entire comparison (Ctrl+Alt+Down), indicating their new behaviour and showing their new keyboard shortcuts.
For three-way text and binary comparisons, this means that the ribbon buttons reliably step through every change in the comparison, regardless of which pane has focus when they are clicked. The new behaviour gives the middle pane focus and steps through every change in it, thus ensuring that every change between both the left/middle and middle/right files is encountered.
For split-view folder comparisons (where a file comparison for the selected folder comparison row is displayed in the lower portion of the window), the ribbon buttons operate in a unified way on the combined folder/file comparison. Consequently, repeatedly clicking either button – regardless of whether the upper folder comparison or the lower file comparison has focus – steps through every individual change in every file of the folder comparison.
Stepping forwards past the last change in the lower file comparison moves to the first change in the files of the next changed row of the folder comparison. Stepping backwards past the first change moves to the last change in the files of the previous changed row. If the selected row has not yet been loaded into the lower file comparison, the first click loads it and moves to its first or last change.
The image comparison ribbon gains a Changes group. In a split-view folder comparison whose lower portion shows an image comparison, its buttons step between the changed rows of the folder comparison. They are disabled in a standalone image comparison, because there is no notion of navigating between changes within an image.
The ribbon buttons are enabled only while there is a further change to which they can navigate. In a split-view folder comparison, this takes into account both the changes remaining in the current file and the changed rows remaining in the folder comparison.
The new keyboard shortcuts CtrlAlt↑ and CtrlAlt↓ are equivalent to the ribbon buttons in all types of file and folder comparison. The existing CtrlPage Up and CtrlPage Down shortcuts, which previously worked only within a text or binary pane, now perform exactly the same action as the ribbon buttons in every comparison type.
The new CtrlShiftAlt↑ and CtrlShiftAlt↓ shortcuts jump between the changed rows of a split-view folder comparison even when the lower file comparison has focus, skipping any remaining changes in the current files. They are the equivalent of the Previous Change in Folder Comparison and Next Change in Folder Comparison commands of Merge for macOS.
The small scrollbar Previous change in pane
and Next change in pane
buttons in text and binary comparison panes continue to operate only on the pane to which they belong. They have new tooltips, Previous change in this pane (F7 or Ctrl+Shift+Up) and Next change in this pane (F8 or Ctrl+Shift+Down). The new CtrlShift↑ and CtrlShift↓ shortcuts are equivalent to the existing F7 and F8 shortcuts. The old Alt← and Alt→ shortcuts continue to work as before, but are now deprecated.
Windows macOS When navigating in a text or binary comparison, the Windows ribbon Previous change in comparison
and Next change in comparison
buttons, the macOS toolbar Previous Change in Comparison
and Next Change in Comparison
buttons, and the scrollbar Previous change in pane
and Next change in pane
buttons, now move the editing cursor to the destination change as well as scrolling to it, as their keyboard shortcuts already did. Previously, the buttons scrolled to the change without moving the cursor. This enhancement maintains synchronization of the visual position with the cursor, making switching between keyboard and button navigation seamless. Additional logic ensures the expected cursor navigation between changes when a file is already scrolled as far as it can go in either direction. #7248
Windows In binary comparisons, the keyboard shortcuts for navigation between changes in a pane now use the centre of the pane as their starting point, matching the existing behaviour of the scrollbar Previous change in pane
and Next change in pane
buttons. This improves navigation consistency and better matches navigation in text comparisons. #7248
Windows The Previous conflict
and Next conflict
ribbon buttons now navigate between the conflicts of a three-way text comparison in the same way as their Merge for macOS equivalents. Conflict navigation always takes place in the middle pane, which is where merge conflicts are resolved. Invoking either command gives the middle pane focus, moves the editing cursor to the previous or next conflict in it, and vertically centres that conflict. Previously, the commands navigated through the conflict markers of whichever pane had focus and, on reaching the last conflict in that pane, wrapped around to the first conflict in the next pane. The sequence of conflicts thus appeared to be continuous when it was not. Navigation no longer wraps between panes, and the buttons are enabled only while another conflict exists in the relevant direction. The equivalent keyboard shortcuts and menu commands behave in the same way. #7220
macOS The Previous Conflict
command now moves the insertion point to the first line of a conflict that spans several lines, matching the behaviour of the Previous Change in Comparison
command. The menu commands equivalent to the Previous Conflict
and Next Conflict
toolbar buttons now behave identically to the buttons, and both are enabled according to the conflicts in the middle pane, regardless of which pane has focus. #7220
Windows In a split-view folder comparison, the lower file comparison is now unloaded when the folder comparison row that it displays is deselected or becomes hidden. For example, if copying a file makes the two sides of its row identical while Keep unchanged rows hidden is checked, the file comparison no longer continues to show the previous state of that file. The file comparison is also now refreshed after every command that changes the selection, including the Select… dialog and selection changes made through the Automation API. It also retains its content while the folder comparison is re-compared. #6034
macOS We revised the application icon to match the subtly revised macOS Golden Gate style. The light source in the icon also now comes from the top, rather than the bottom, matching the general macOS style. #7238
macOS The toolbar icons have been carefully redrawn to harmonize with macOS Golden Gate. #7242
macOS macOS Golden Gate reduces the corner radius of windows compared with macOS Tahoe. Merge now positions the status bar text and the binary and image comparison controls at the bottom of the window according to the corner radius of the platform on which it is running, so that they sit closer to the corners on macOS 27 Golden Gate and macOS 15 Sequoia. #7237
macOS The macOS screenshots on the Merge overview page have been updated. #7237 #7242
Windows The Windows Instant Overview of Folder Comparison and Synchronization has been updated. #7248
macOS The Save Filename column of the Save Modified Files sheet can now be widened as far as the sheet allows, and the columns fill the width of the sheet when it opens and when it is resized. Previously, the column could not be widened beyond a fixed maximum width. #7254
macOS All embedded icon artwork is now SVG rather than PDF. This slightly reduces the size of the Merge for macOS disk image. Icons that previously relied on fonts are now drawn with strokes. #7242
macOS The widths of the text-comparison toolbar groups have been normalized so that toolbar items no longer shift horizontally on macOS Sequoia when switching between comparisons of different types. #7242
Windows macOS The subset of the OpenJDK Java Runtime Environment that is bundled with Merge for use by some of the supplied file filters is now the Azul Zulu build of OpenJDK 25.0.4. This replaces the Adoptium Eclipse Temurin build used by earlier versions of Merge. The Zulu build is licensed on the same terms as OpenJDK itself: the GNU General Public License, version 2, with the Classpath Exception. The legal notices have been updated accordingly: Windows, macOS. #7239
Windows macOS We undertook various chores to improve the build system and to provide compatibility with Microsoft Visual Studio 2026, Apple Xcode 27, and the latest versions of third-party dependencies. #7137 #7238 #7239 #7256 #7275 #7278 #7281 #7283
Windows macOS As explained in the security advisories section below, the FTP, Perforce, and Subversion file-system plugins have been removed. The Perforce plugin had previously been deprecated in Merge 2024.6000 for macOS and Merge 2024.6001 for Windows, and the Windows-only FTP plugin in Merge 2024.6001, with a warning that they might be removed in a future release. The Subversion plugin was not deprecated. Users of these plugins should obtain remote content with their normal client and compare the local result. For FTP, prefer SFTP or FTPS where the server supports them, because FTP transmits credentials and data without encryption. #7259
These removals do not affect the use of Merge as an external comparison and merge tool for Perforce and Subversion clients, which remains fully supported. The Git and Mercurial file-system plugins, and the third-party AllChange plugin, are unaffected.
macOS The Merge extension for Finder has been removed. It was previously deprecated in favour of the Merge services for macOS, which should be used instead. macOS 26 Tahoe has a bug that causes Finder to show the icon of an application that provides a Finder Sync extension in place of the icons of unrelated sidebar items, such as network volumes and mounted disk images. Removing the extension resolves that problem for Merge. No action is needed after upgrading, because macOS stops offering the extension as soon as the new version of Merge replaces the old one. However, Finder caches sidebar icons, so incorrect icons may persist until Finder is relaunched or you log out and in again. Any older copy of Merge that remains reachable (for example, in another folder or on a mounted disk image) keeps the extension available to Finder until that copy is removed. Merge-SA-26-06 below describes a further reason for the removal. #7193
macOS A local file or folder path that contains :// can no longer be compared, because Merge now treats such text as a URI with an unrecognized scheme. #7259 #7264
Windows macOS The Git file-system plugin now requires Git 2.24.0 or later, and the Mercurial file-system plugin requires Mercurial 4.4.2 or later. This is because Merge now invokes Git with the --end-of-options marker introduced in Git 2.24.0, and runs Mercurial in plain mode with the strict flag parsing introduced in Mercurial 4.4.2. See Merge-SA-26-05 below for the motivation for this change. #7259 #7264
Windows macOS When the Show file versions from SCM systems (Windows) or Include versions from SCM systems (macOS) setting is on, Merge now looks up the available versions of the path in a file or folder entry field only when the path is committed: when you press Enter, choose an item from the history or versions list, or move the keyboard focus out of the field. Earlier versions of Merge queried the SCM system on every change to the text. This change avoids passing incomplete URIs to file-system plugins. See Merge-SA-26-05 below for the reason for this change. #7264
Windows macOS Credential-notification settings and some file-system plugin settings have been retired from the Automation API and AppleScript. On Windows, the ConfigString members csP4Path (215) and csSVNPath (216), and the ConfigLong members clBadCredentialsWarningTrayIconEnabled (292) and clNeedCredentialsWarningTrayIconEnabled (293), no longer exist. Each keeps its numeric value as a reserved slot. Access to a retired setting by number, by its old symbolic name, or by its old preference key, in any letter case, returns E_INVALIDARG. Such access cannot disclose a stale value or recreate a key. Merge deletes any stored values of these settings on every launch. On macOS, AppleScript access to the same preferences by name fails in the same way. #7259
Windows macOS The unused internal firewall settings have been retired. On Windows, the Automation API settings csFirewallPassword, csFirewallUsername, csFirewallHost, clSaveFirewallPassword, and clFirewallPort no longer exist. On macOS, the equivalent AppleScript preferences (FirewallPassword, etc.) are also removed. Merge deletes any stored values of these settings on every launch. We do not believe these settings have been used in a released version of Merge, and no sensitive information should therefore have been stored in them. Anyone who nevertheless stored a password in csFirewallPassword or FirewallPassword through the Automation API or AppleScript should change that password. #7259 #7264
Windows The Automation API ConfigString members csFileComparisonHistory and csFolderComparisonHistory have been retired. They have not worked since Merge 2019.5174 reorganized the comparison histories, and the histories are per-user data that no longer appear in saved comparisons, workspaces, or options files. Access to either member by number or by name now returns E_INVALIDARG. #7259 #7260 #7264
Windows The IHostCredentials interface has been removed from the VFS plugin API used to support file-system plugins. The VFS API was previously deprecated for third-party use in Merge 2024.6001. The vfsplugin.idl file is no longer shipped with the Automation samples. The .NET interop assembly Interop.Merge70VFS.dll is no longer installed. #7259
Windows The now obsolete FolderComparisonPerforceChangeListReport Automation API examples have been removed. #7259
macOS Regular-expression character classes give correct results again. Since the upgrade of the Boost C++ Libraries in Merge 2026.0, several character classes and escapes, including \w, \W, \b, \B, [[:upper:]], [[:lower:]], [[:space:]], [[:punct:]], [[:print:]], [[:word:]], and [[:xdigit:]], matched the wrong characters in line expressions, line-pairing rules, and block expressions. Literals, ranges, quantifiers, anchors, case-insensitive matching, \d, and \s were unaffected. Merge for Windows was not affected. #7274
macOS Hexadecimal escapes in regular expressions now match the intended character. Previously, an escape whose digits included a letter, such as \xE9 or \x263A, matched the wrong character or no character at all. An escape with a letter beyond f, such as \xg1, was accepted instead of being reported as an error. Merge for Windows was not affected. #7314
Windows macOS We fixed a race condition that could occasionally lead a binary comparison to hang without ever completing. On macOS, the problem could sometimes cause Merge to become unresponsive when a binary comparison was started via AppleScript or the compare command-line utility. #7294
macOS The Git file-system plugin can now list and open earlier versions of a file that is located within a Git worktree. #7280
macOS Merge no longer hangs consuming a full CPU core when a Git URI has a relative path, such as git://host/repo. Such a URI is now rejected at once. #7259 #7264
Windows macOS In a three-way text comparison, a block of lines excluded by a block expression in the left or right file can no longer become a spurious next/previous-change navigation target in the middle pane. This problem occurred only in very specific circumstances. #7292
macOS A saved text or binary comparison now always shows the rulers, vertical scroll bars, and Previous change in pane
and Next change in pane
scrollbar buttons of its panes when it is reopened. Previously, these controls were sometimes missing from one or more panes of a reopened comparison. Newly created comparisons were not affected. #7284
macOS When a line of a UTF-8 text file contains an invalid byte sequence that cannot be decoded, Merge now replaces only that sequence with the Unicode replacement character � and keeps the rest of the line intact, as Merge for Windows already did. Previously, the entire line was converted byte by byte such that valid multi-byte characters elsewhere on the line, such as é, became pairs of unrelated characters, and each undecodable byte became an unrelated character rather than a recognizable marker. The most common trigger was a file in a legacy encoding such as ISO-8859-1 or Windows-1252, with no byte-order mark or charset declaration, opened while the default character encoding was UTF-8. For a line that cannot be decoded by any encoding other than UTF-8, each byte is now shown as the Latin-1 character with the same value. #7302
Windows macOS When a file that begins with a byte-order mark is loaded without automatic character-encoding detection – because the Try to auto-detect character encoding from file content setting is unchecked, or because the file is reopened with an expressly specified character encoding or from a history list – and the encoding in effect is the Unicode encoding to which that mark belongs, the mark is now consumed rather than treated as text. Previously, the mark became an invisible character at the start of the first line, so that the file appeared to differ from an otherwise identical file without a mark, and a second mark was written when the file was saved with an encoding that includes a byte-order mark. If such a file is subsequently saved with an encoding that does not include a byte-order mark, the mark is now dropped, as appropriate for the chosen encoding. A mark that does not belong to the encoding in effect, for example under a legacy encoding such as Windows-1252, continues to be decoded as text. On macOS, only UTF-16 and UTF-32 files were affected; on Windows, UTF-8 files were also affected. #7302
macOS We fixed a problem that could, in rare circumstances, cause Merge to crash or behave unpredictably when stepping backwards from the first change of the lower file comparison into the previous changed row of a split-view folder comparison. This could occur when the text comparison of the newly selected row contained no changes, for example when the folder comparison compares files by timestamp and size and the files of the row differed only in their timestamps. #7287
Windows Merge no longer crashes when its main window is closed while a ribbon drop-down menu is open, for example by the taskbar, by another application, or at log-off. The menu is now dismissed, and Merge then closes normally. #7303
Windows The Delete button on the OptionsText comparisonsLine expressions, OptionsText comparisonsBlock expressions, and OptionsText comparisonsLine pairing settings pages is now able to remove the first item. #7295
Windows In a binary comparison, the previous change commands no longer report that there are no earlier changes when the editing caret is on a row that contains several changes before it. #7301
Windows When a text comparison pane shows an information panel, such as a warning that a file has been reformatted, navigating to a change now positions that change level with the centre marker of the linking-lines strip, as it already did when no information panel was shown. Previously, the change was positioned below the marker. #7293
macOS Several controls in the Settings window are now correctly aligned on macOS Golden Gate and Tahoe, and text labels that were clipped in the Japanese Settings, Registration, and Synchronization Links windows are now shown in full. #7225
macOS Text in the cells of the tables in the Settings window no longer extends beyond the row background. #7223
Windows We have corrected an issue with the Japanese Print dialog. #7255
Windows The error message shown when Merge cannot initialize Direct2D, DirectWrite, or the Windows image converters now refers to Direct2D rather than DirectDraw, which Merge does not use. #7256
Windows Numeric indexes into the Automation API LongPreferences object now reach the correct preferences. Since Merge 2019.5137, the use of a ConfigLong constant greater than clPrinterAspect (172) with the Item property or the Set method reached the preference of the preceding slot, so that, for example, Longs.Item(clShowLineDetailPanel) read or wrote BackupVolumeMountWarningTrayIconEnabled. Index 173 failed, and the out-of-range index 328 was accepted. Access by name, which all the provided Automation examples use, was never affected. Any script that has compensated for the offset by adding one to the index will now reach the following preference and must be corrected. #7262
Windows The Item property of the Automation API StringPreferences, LongPreferences, and DoublePreferences objects now returns E_INVALIDARG, as documented, when given an unknown preference name, a reserved slot, or the numeric index of a preference that cannot be accessed by number, such as a colour. Previously, such calls failed with RPC_E_SERVERFAULT (0x80010105, ‘The server threw an exception’). #7263
Windows The C++ (ATL) examples in the Introduction to the Automation API documentation have been corrected so that they compile successfully. #6853
Security researcher Kelvin Winborne (grepStrength) responsibly disclosed a credential-storage weakness present in Merge for Windows 2026.0 and earlier versions, described in full below. Our subsequent thorough audit of how Merge stores and uses credentials uncovered several other problems, also described below. We thank grepStrength for his report, which prompted the wider audit.
Merge stored credentials to support the Perforce, Subversion, and Windows-only FTP file-system plugins. Taken together, the reported weakness and the further issues that our audit uncovered showed the credential store itself to be a risk. Few customers use the features that depend on it: the consultation on the removal of the Perforce and FTP plugins, run in the release notes from May 2023 until the plugins were deprecated in 2024, drew very few responses, and we receive almost no support requests about file-system plugins. Weighing the risk of retaining the credential store against the loss of these features, we decided to remove it entirely from Merge 2026.1, together with the three plugins that used it. We have also mitigated the risk to credentials stored by earlier versions. We apologize for the inconvenience caused to users of the removed plugins.
These removals do not affect the use of Merge as an external comparison and merge tool for Perforce and Subversion clients, which remains fully supported. The Git and Mercurial file-system plugins operate only on local repositories and use no stored credentials. They are therefore retained, and Merge-SA-26-05 describes the hardening that they received.
Rotate credentials and upgrade Araxis Merge:
Merge 2026.1 removes stored credentials only in the user accounts in which it runs. It cannot reach backups, system images, or profiles that never run it. Rotation of the credentials is therefore the only certain remedy.
Review the access logs of the servers concerned if you suspect that credentials used with Merge have been compromised. Stored credentials could have been used through Merge, as well as recovered from it.
Users unable or not wishing to upgrade should:
| Affects | Windows Merge 2011.4074–2026.0 |
| Corrected in | Merge 2026.1 |
| Reported by | Kelvin Winborne (grepStrength) |
| CVE ID | CVE-2026-92680 |
| Description | Merge for Windows was able to store server credentials for use by some of its file-system plugins. Merge wrote these credentials as a binary object (blob) to the Windows registry. By design, the blob was protected by the user-scope Windows Data Protection API (DPAPI) using a As a consequence of its use of the DPAPI to protect its credential store without employing additional security measures, Merge relied upon the standard Windows user-scope security boundary. This boundary does not prevent other unsandboxed processes running with the same user permissions as Merge from accessing the stored credentials. |
| Impact | Users who have never stored credentials in Merge for Windows and who have never used the FTP, Perforce, Subversion, or Visual SourceSafe file-system plugins are unaffected. Ordinary unsandboxed code running as the Windows user who stored the credentials could recover any FTP, Perforce, Subversion, or (in versions before 2014.4531) Visual SourceSafe credentials stored by affected versions of Merge, without administrator rights, user interaction, or any Merge-specific secret material. Every non-deprecated use of the user-scope Windows DPAPI or of a generic Windows Credential Manager entry to store a reusable secret without additional protection has the same fundamental limitation: neither mechanism provides application-to-application isolation between unsandboxed processes running as the same user. That is the standard security boundary that these Windows generic-secret APIs provide to ordinary unsandboxed desktop software. For example, Git Credential Manager documents that its default Windows store uses Windows Credential Manager entries and that an alternative Windows store uses DPAPI. Its source shows that the default store writes generic ( |
| Solution | |
| Workaround | |
| Correction details | The credential store existed on the two platforms, and the changes below apply to both. This vulnerability affected Windows only: on macOS, the keychain protected the stored credentials from other applications. The store was removed on macOS for the reasons given in the Background and in Merge-SA-26-04.
|
| Affects | Windows Merge v6.5.1661–2026.0 |
| Corrected in | Merge 2026.1 |
| Reported by | Araxis engineering staff |
| Description | When the Perforce file-system plugin invoked the Perforce |
| Impact | Users who have never used the Perforce or Subversion file-system plugins are unaffected. A process permitted by the operating system to read the |
| Solution | |
| Workaround | |
| Correction details | The Perforce and Subversion file-system plugins have been removed. |
| Affects | macOS Merge 2014.4581–2026.0 |
| Corrected in | Merge 2026.1 |
| Reported by | Araxis engineering staff |
| Description | The macOS Perforce file-system plugin logged all its arguments to the macOS system log using |
| Impact | Users who have never used the Perforce file-system plugin are unaffected. On macOS releases before macOS 26, an administrator, a privileged management agent, or a recipient of a diagnostic log archive could recover the password or ticket from the system logs without keychain approval. From macOS 26 onwards, the system log replaces the variable content of such messages, which includes the password or ticket, with |
| Solution | |
| Workaround | |
| Correction details | The Perforce file-system plugin has been removed. |
| Affects | Windows Merge v6.5.1491–2026.0 |
| Corrected in | Merge 2026.1 |
| Reported by | Araxis engineering staff |
| Description | Merge accepted passwords embedded in file and folder URIs used by its file-system plugins. For example, the Perforce file-system plugin accepted URIs such as File, folder, binary, and image comparison histories stored such URIs verbatim. The same URIs could enter saved comparisons or diagnostic material on both platforms, and, on Windows, saved workspaces and options files. All of these stores recorded the unredacted URIs in plain form. On macOS, if execution failed, the |
| Impact | Users who have never used a credential-bearing URI with Merge are unaffected. Many potential uses of such URIs were better served by the use of stored credentials or the placeholder A password or access token provided to Merge in a file or folder On macOS releases before macOS 26, an administrator, a privileged management agent, or a recipient of a diagnostic log archive could recover a password or token from the entries that the |
| Solution | |
| Workaround | |
| Correction details |
|
| Affects | Windows Merge 2011.4074–2026.0 |
| Corrected in | Merge 2026.1 |
| Reported by | Araxis engineering staff |
| Description | Merge was able to store server credentials for use by some of its file-system plugins. Those credentials were protected by the Windows DPAPI on Windows and by the keychain on macOS. However, any application able to control Merge (through the command line, the Windows Automation API, AppleScript, or accessibility features that simulate user input) could use Merge as a proxy to access files on remote servers using those stored credentials. On macOS, each of these paths needs a permission that the user grants once. On Windows, no such permission is needed. |
| Impact | Users who have never stored credentials in Merge are unaffected. An attacker able to run code as the user could gain read access to whatever the stored credentials could read, and, on Windows, write access through FTP saves. This did not require recovering the credentials themselves, which is why it applied on macOS as well. |
| Solution | |
| Workaround | |
| Correction details |
|
| Affects | Windows macOS Potentially all versions before Merge 2026.1. No exploit has been demonstrated. |
| Corrected in | Merge 2026.1 |
| Reported by | Araxis engineering staff |
| Description | On Windows, the Perforce, Subversion, Git, and Mercurial file-system plugins built a single command-line string to invoke the native On both Windows and macOS, the Perforce, Subversion, Git, and Mercurial commands invoked by their respective file-system plugins were passed path arguments without specifically marking the end of native options to those commands. For Perforce and Subversion this had little practical consequence, because every path argument began with |
| Impact | Users who have never used the Perforce, Subversion, Git, or Mercurial file-system plugins are unaffected. On Windows, it is conceivable that a specially crafted path might terminate a quoted argument and add options to the invocation of the native tools used by the file-system plugins. On either platform, a path or revision beginning with These are unconfirmed, potential vulnerabilities, and we have not proven the feasibility of an exploit. |
| Solution | Upgrade to Merge 2026.1 or later. |
| Workaround | Turn off Show file versions from SCM systems (Windows) or Include versions from SCM systems (macOS), and do not open a Git or Mercurial URI or revision from an untrusted source. |
| Correction details |
|
| Affects | macOS Potentially all versions before Merge 2026.1. No exploit has been demonstrated. |
| Corrected in | Merge 2026.1 |
| Reported by | Araxis engineering staff |
| Description | The |
| Impact | A crafted file or folder path or URI in, for example, a checkout, an archive, or a shared folder, could cause the The command-line tool is unsandboxed. The Merge extension for Finder runs in the macOS App Sandbox, which constrains what an injected script could do from there. A successful injection attack remains unconfirmed. |
| Solution | Upgrade to Merge 2026.1 or later. |
| Workaround |
|
| Correction details |
|
This release includes the following dependencies, with updates indicated: #7239 #7278
| Platform | Dependency | Version (Previous → 2026.1) |
|---|---|---|
| Windows macOS | Azul Zulu build of OpenJDK JRE (subset; new dependency) | 25.0.4 |
| Windows macOS | Adoptium Eclipse Temurin OpenJDK JRE (subset) | 25.0.2+10 → removed |
| Windows macOS | Apache Commons Collections library | 4.5.0 |
| Windows macOS | Apache Commons Compress library | 1.28.0 |
| Windows macOS | Apache Commons IO library | 2.21.0 |
| Windows macOS | Apache Commons Lang library | 3.18.0 |
| Windows macOS | Apache Commons Logging library | 1.3.5 |
| Windows macOS | Apache Log4j API library | 2.24.3 |
| Windows macOS | Apache PDFBox, FontBox, and PDFBox IO libraries | 3.0.7 |
| Windows macOS | Apache POI libraries | 5.5.1 |
| Windows macOS | Apache XMLBeans library | 5.3.0 |
| Windows macOS | Boost C++ Libraries (subset) | 1.90.0 |
| Windows macOS | Compile time regular expressions library | 3.10.0 → 3.11.0 |
| Windows macOS | Crypto++ library (subset) | Source fork of 5.2.1 |
| Windows macOS | JDOM library | 2.0.6.1 |
| Windows macOS | jsoup library | 1.22.1 |
| Windows | libarchive library | 3.8.7 → 3.8.9 |
| Windows | libbzip2 library | 1.0.8 |
| Windows | liblzma library from XZ Utils | 5.8.3 |
| Windows | libpng library | 1.6.57 → 1.6.58 |
| Windows | Microsoft.Windows.CppWinRT package | 2.0.250303.1 |
| Windows macOS | RTF Parser Kit library | 1.16.0 |
| Windows macOS | Scintilla text editing component (subset) | Source fork |
| Windows macOS | SparseBitSet library | 1.3 |
| Windows | Universal Ctags | Source fork |
| Windows macOS | zlib library | 1.3.2 |
We updated the following release-significant tool versions: #7137 #7238
| Platform | Dependency | Version (Previous → 2026.1) |
|---|---|---|
| macOS | Apple Xcode | 26.5 → 27.0 |
| Windows | Microsoft.Trusted.Signing.Client package | 1.0.95 |
| Windows | Microsoft Visual Studio | 17.14.33 → 18.10.1 |
| Version | Build date |
|---|---|
| 2026.1 | 22 September 2026 |
This release features a beautiful UI redesign for macOS and first-class support for macOS 26 Tahoe. The macOS 27 Golden Gate Developer Beta 1 also receives preliminary support. The presentation of comparison results on macOS is significantly enhanced, making it easier than ever to see and understand changes in their full context. Various other improvements and fixes for Windows and macOS are also included. Please read the release notes below for a complete list of changes.
We plan to bring many of the macOS UI refinements from this release to Merge for Windows in future versions.
This is no longer the current release. All users are encouraged to upgrade to the most recent release for the latest enhancements, bug fixes, and security improvements.
This release is available at no extra cost to all customers with upgrade/support entitlement covering the build date indicated in the download box below. This includes everyone who purchased Merge within the year prior to that date.
Merge 2026.0 appears to be fully functional on macOS 27 Golden Gate Developer Beta 1, though macOS Golden Gate is not yet a fully supported platform. We are working to provide complete support for macOS Golden Gate following its general availability.
This release is tested and supported on the following platforms:
The following platforms are supported and expected to work, though they are not routinely tested:
macOS Merge for macOS is fully supported, optimized, and tested on macOS 26 Tahoe. Support for macOS Tahoe replaces that for macOS 13 Ventura. #7097
macOS Merge for macOS now provides preliminary support for macOS 27 Golden Gate Developer Beta 1. Please note that macOS Golden Gate is still undergoing development and is not yet of production quality. #7236
macOS Merge for macOS has a beautiful new design that harmonizes perfectly with macOS Golden Gate, Tahoe, Sequoia, and Sonoma. #7097
macOS The presentation of comparison results is significantly clearer and less cluttered. #7097 #7151 #7152 #7156 #7160 #7161 #7209
macOS Configuration of comparison colours is much easier. #7097 #7160
macOS The unchanged text background colour is no longer configurable in dark mode. This is necessary to support macOS window tinting because the comparison panel background needs to be drawn with specific macOS materials rather than a fixed, solid colour. #7097
macOS In split-view folder comparisons, most of the area between the folder comparison and the file comparison is now draggable to change the relative sizes of the two comparison areas. This makes resizing much easier than before. #7097
macOS The linking-lines colour is now configured as a hue, rather than an absolute colour. This is because it is programmatically adjusted so that linking lines can participate in window tinting and translucency. (This constraint arises from macOS limitations in how colours can be composited against certain display materials.) #7097
macOS We have improved the operation of the Previous Conflict
and Next Conflict
commands in three-way text comparisons. Conflict navigation now occurs solely in the middle pane, stepping through each conflict in turn. This eliminates the need to step through conflicts in each pane separately. Each conflict is also vertically centred when targeted. #7165
macOS Merge now centres the first conflict and gives the middle panel focus when using the Merge to Common Ancestor
command. #7164
macOS Split-view folder comparisons give more initial space to the file comparison. This default better aligns with Merge for Windows, matching the common workflow of selecting a folder-comparison row and then inspecting the corresponding file changes in detail. #7149
Windows macOS The binary-comparison Search size control is renamed Effort to better reflect its purpose. It now accepts values from 1 to 9999 on both platforms. The new default of 5 drastically improves the baseline performance of large binary comparisons with many changes on Windows. For more information, please read the updated documentation: Windows, macOS. #7123
Windows Merge for Windows now remembers the value of the Effort setting across binary comparisons, aligning its behaviour with Merge for macOS. #7123
macOS The algorithm used for binary comparisons has been updated to that used by Merge for Windows. This should improve performance with very large files. #7123
macOS In binary comparisons, the status line has been combined with the control strip. This increases the amount of space available for comparison content. #7097 #7222
Windows macOS After a fresh installation or a settings reset, Merge now defaults to comparing XML files using a normal text comparison, rather than a Text XML/XHTML comparison as before. For more information about comparing XML files, please read the documentation: Windows, macOS. #7233
macOS The pointer adopts a move up/down shape when over a synchronization-link arrowhead. This clearly indicates that the synchronization link can be repositioned by dragging. #7154
macOS We have slightly increased the font size used for image and binary comparison controls. #7222
macOS In light mode, a darker green colour is used to improve the readability of valid serial numbers in the Araxis Merge Registration dialog. #7097
macOS All the macOS screenshots have been retaken. #6167
Windows macOS We undertook various chores to improve the build system and to provide compatibility with the latest versions of Microsoft Visual Studio, Apple Xcode, and third-party dependencies. #7122 #7174 #7179
macOS We updated the Araxis Merge application bundle CFBundleDevelopmentRegion metadata to use an ISO 639-1 language code. #7195
Windows macOS We updated the major product version number and copyright notices for 2026. #7142
Windows macOS Linking-line brackets in text comparisons are no longer missing when both Intelligently split blocks of changed text based on matched line pairs and Consecutively (working downwards from the top of the block) are enabled. #7216
macOS Three-way text and binary comparisons now render linking lines correctly for change blocks that begin right at the bottom of the left or right pane. #7244
macOS On macOS Tahoe, the confirmation dialog that appears when deleting files from a folder comparison context menu no longer becomes unresponsive to mouse or trackpad input. #7145
macOS AppleScript/OSA API folder comparisons can no longer crash when a script closes the comparison immediately after it completes. #7196
macOS In a three-way text comparison with line-wrapping enabled, text is no longer unexpectedly selected when using the Previous Change in Comparison
or Next Change in Comparison
toolbar buttons, or the Previous change in pane
or Next change in pane
scrollbar buttons. #7200
macOS We have properly aligned the Configure… button on the HTML and XML pages of the folder comparison report dialog. #7203
macOS We have addressed several folder-comparison rendering issues specific to macOS Tahoe. In addition, we fixed a problem where folder comparisons could be scrolled a small horizontal distance on macOS Tahoe. #7178
macOS The mouse pointer now properly assumes its arrow shape when it is over the vertical scrollbar in the centre pane of a text or binary comparison. #7131
macOS We fixed a CGContextSetFillColorWithColor: invalid context diagnostic that appeared in Xcode when opening certain text files. #7092
This release includes the following dependencies, with updates indicated: #7111 #7143
| Platform | Dependency | Version (Previous → 2026.0) |
|---|---|---|
| Windows macOS | Adoptium Eclipse Temurin OpenJDK JRE (subset) | 21.0.7+6 → 25.0.2+10 |
| Windows macOS | Apache Commons Collections library | 4.4 → 4.5.0 |
| Windows macOS | Apache Commons Compress library | 1.27.1 → 1.28.0 |
| Windows macOS | Apache Commons IO library | 2.18.0 → 2.21.0 |
| Windows macOS | Apache Commons Lang library (new dependency) | 3.18.0 |
| Windows macOS | Apache Commons Logging library | 1.3.5 |
| Windows macOS | Apache Log4j API library | 2.24.3 |
| Windows macOS | Apache PDFBox, FontBox, and PDFBox IO libraries | 3.0.5 → 3.0.7 |
| Windows macOS | Apache POI libraries | 5.4.1 → 5.5.1 |
| Windows macOS | Apache XMLBeans library | 5.3.0 |
| Windows macOS | Boost C++ Libraries (subset) | 1.77.0 → 1.90.0 |
| Windows macOS | Compile time regular expressions library | 3.10.0 |
| Windows macOS | Crypto++ library (subset) | Source fork of 5.2.1 |
| Windows macOS | JDOM library | 2.0.6.1 |
| Windows macOS | jsoup library | 1.21.1 → 1.22.1 |
| Windows | libarchive library | 3.7.7 → 3.8.7 |
| Windows | libbzip2 library | 1.0.8 |
| Windows | liblzma library from XZ Utils | 5.8.1 → 5.8.3 |
| Windows | libpng library | 1.6.47 → 1.6.57 |
| Windows | Microsoft.Windows.CppWinRT package | 2.0.250303.1 |
| Windows macOS | RTF Parser Kit library | 1.16.0 |
| Windows macOS | Scintilla text editing component (subset) | Source fork |
| Windows macOS | SparseBitSet library | 1.3 |
| Windows | Universal Ctags | Source fork |
| Windows macOS | zlib library | 1.3.1 → 1.3.2 |
We updated the following release-significant tool versions: #7143 #7179
| Platform | Dependency | Version (Previous → 2026.0) |
|---|---|---|
| macOS | Apple Xcode | 16.4 → 26.5 |
| Windows | Microsoft.Trusted.Signing.Client package | 1.0.86 → 1.0.95 |
| Windows | Microsoft Visual Studio | 17.14.9 → 17.14.33 |
| Version | Build date |
|---|---|
| 2026.0 | 19 June 2026 |