This GA release addresses security vulnerabilities and bug fixes that enhance stability and performance. It includes two CVE fixes: CVE-2026-4410 (denial of service, CVSS 4.8, affecting sipServlet-1.1) and CVE-2026-5516 (denial of service, CVSS 4.4, affecting appSecurity features). Notable bug fixes cover featureUtility exit codes, EJB remote runtime exceptions, AES encryption, Windows JAVA_HOME configuration, HTTP/2 race conditions, and Windows service stop timeout handling, plus four new guides on observability with OpenTelemetry, Jakarta Faces, and Gradle multi-module applications.