# CiviCRM 6.16.5 Released Tue Aug 04 2026 21:00:00 GMT-0700 (GMT-07:00) - **[Synopsis](#synopsis)** - **[Security advisories](#security)** - **[Credits](#credits)** - **[Feedback](#feedback)** ## <a name="synopsis"></a>Synopsis | *Does this version...?* | | | --------------------------------------------------------------- | -------- | | Change the database schema? | no | | Alter the API? | no | | Require attention to configuration options? | no | | Fix problems installing or upgrading to a previous version? | no | | Introduce features? | no | | Fix bugs? | no | | **Fix security vulnerabilities?** | **yes** | ## <a name="security"></a>Security advisories * **[CIVI-SA-2026-37](https://civicrm.org/advisory/civi-sa-2026-37-additional-permission-bypass-apiv4): _APIv4_: Additional Permission Bypass in APIv4 (security/core#293)** ## <a name="credits"></a>Credits This release was developed by the following authors and reviewers: Wikimedia Foundation - Eileen McNaughton; Tadpole Collective - Kevin Cristiano; John Kingsnorth; JMA Consulting - Seamus Lee; Fuzion - Luke Stewart; Coop SymbioTIC - Mathieu Lutfy; CiviCRM - Coleman Watts, Tim Otten; AGH Strategies - Chris Garaffa ## <a name="feedback"></a>Feedback These security release-notes are edited by Tim Otten. If you'd like to provide feedback on them, please report an issue at https://lab.civicrm.org/dev/release/.