Red Hat Satellite 6.19 moves Red Hat Enterprise Linux (RHEL) management forward and continues to deliver the value of Red Hat Lightspeed to disconnected, air-gapped, and data-sovereign environments. This latest release shifts the focus from merely finding vulnerabilities to proactively managing risk, and refines the advisor experience so administrators can cut through the noise and focus on what truly matters.Vulnerability service for RHEL reaches general availabilityThe big news: Red Hat Lightspeed’s vulnerability service is now generally available (GA) for disconnected RHEL environments in Satellite 6.19, thanks to Red Hat Lightspeed on premise. Red Hat Lightspeed on premise is more than just another dashboard; it brings the full power of a SaaS-based vulnerability monitoring service directly into your air-gapped data center, giving you the ability to identify, triage, and remediate Common Vulnerabilities and Exposures (CVEs) without ever sending data outside your environment.With vulnerability service now GA, administrators can define business risk and perform bulk CVE triage locally, enabling a "trust, but verify" posture without requiring external connectivity or compromising data sovereignty.Here's what's new:Granular host-level control: Satellite 6.19 introduces the ability to enable or disable vulnerability analysis on individual hosts. This improves the signal-to-noise ratio: you analyze only the systems that matter, reducing irrelevant alerts and allowing your team to focus on genuine threats.Business risk and status triage: Administrators can now define both the business risk and the status of CVEs, individually or in bulk. This transforms vulnerability management from a flat list of findings into a prioritized workflow that reflects how your organization actually assesses and responds to risk.Enhanced reporting: Need to brief leadership on your security posture? Satellite 6.19 adds the ability to download reports in JSON and CSV formats from any screen that lists systems or CVEs. RHEL administrators can generate executive-ready reports directly from the vulnerability service, saving time that would otherwise be spent manually compiling data. Additionally, a new filter allows you to sort CVEs by OS version on the CVE list view, making it easier to focus remediation efforts where they are needed most.Advisor quality-of-life enhancementsThe advisor service in Satellite helps administrators maintain stable, optimized RHEL environments by surfacing system health recommendations based on Red Hat's deep knowledge base. In Satellite 6.19, the advisor service gets several quality-of-life improvements designed to reduce alert fatigue and give administrators more control over their experience.Administrators can now disable or suppress specific advisor recommendations at the organization level. Not every recommendation applies to every environment, and with this feature, teams can configure alerts so they aren't distracted by issues that they have already evaluated and deemed irrelevant to their specific configuration. Satellite preserves auditability, so your security team can trace why a recommendation was suppressed.Changes to insights-client deliveryThe release of RHEL 10.2/9.8 standardizes how insights-client, the package responsible for sending data from the hosts to Satellite, is delivered to managed hosts. Previously, the insights client used a Python egg as an update mechanism, which updated automatically outside the management channels of Satellite. Starting with this release, the insights client will be delivered as an RPM Package Manager (RPM) file through the standard RHEL repository that can be managed via Satellite, just like any other RPM file.For disconnected and air-gapped customers, this is a meaningful improvement. Rather than relying on an update mechanism that could not function without external connectivity, administrators can now manage the insights-client lifecycle atomically. Updates arrive consistently with the RHEL z-stream cadence, so disconnected environments stay current without requiring a separate update workflow.This change also gives all customers greater control over collected data across managed systems, aligning the delivery of insights software with how Red Hat delivers all other enterprise software.Extended Update Support: A bridge to the futureTo help customers maintain stability through this period of product evolution, Satellite 6.19 includes an optional Extended Update Support Add-On. As the final RPM-based release of Satellite, 6.19 marks a significant milestone, and Satellite Extended Update Support Add-On provides a 30-month total maintenance window (12 months beyond the standard 18-month lifecycle) to give organizations additional time to plan their transition to the container-based Satellite 7. During this period, Red Hat will continue to deliver what Red Hat Product Security rates as Critical and Important security errata and selected Urgent priority bug fixes, establishing a predictable and secure maintenance cadence.Looking aheadSatellite 6.19 reflects a clear direction for Red Hat Lightspeed on premise: giving disconnected and data-sovereign environments security intelligence and operational insight that connected customers already rely on, all without compromising the strict data boundaries that define these environments. Whether you're operating in a classified data center, a regulated financial institution, or a remote industrial site, the tools to proactively manage risk and maintain system health are now available right where you need them.Satellite 6.19 is available now. For more information, explore the documentation.