What's New In 26R2.3

This topic provides information about the Veeva CRM 26R2.3 release, including important dates and release announcements.

All dates listed are subject to change.

Dates to Remember

  • October 1, 2026 – Maintenance Notes available
  • October 8, 2026 – Sandbox Release
  • October 15, 2026 – Production Release

Release Notes

The 26R2.3 release does not include new features. Maintenance Notes include a list of fixes available in this release.

Announcements

iOS 27 and Updated Device Support

Veeva CRM supports the iPadOS and iOS 27 releases on iPad and iPhone. See CRM for iOS for more information about supported devices.

Veeva CRM supports standard aspect ratios for iPad and iPhone devices. iPhone Duo is not supported.

Multi-Factor Authentication (MFA) – Now Mandatory for All Users, Including Admins, in Sandbox & Production Orgs

Multi-Factor Authentication (MFA) is required for all users in Sandbox & Production orgs, including admins. Ensure MFA is fully configured for your users. While phishing-resistant MFA is not required for standard (non-privileged) users, it is strongly recommended. For details, see Salesforce Security Updates and MFA Requirements.

Changes to Salesforce Security Control Requirements

Salesforce plans to require the implementation of additional security controls and settings. Take the following actions to ensure your settings meet Salesforce’s security requirements:

  • Require Multifactor Authentication (MFA): MFA is mandatory for all Production Orgs as of June 2026. Customers must ensure that MFA is fully set up. While in the past Veeva was able to request a 90-day rollback for customers, Salesforce will no longer approve these requests.
  • Ensure all System Administrator users adopt phishing-resistant MFA for login: While not mandatory, all System Administrator users are strongly encouraged to adopt phishing-resistant MFA for login. This is considered a security best practice to protect your most privileged accounts.
  • Restrict login IP addresses in profiles: Beginning with the Winter '26 release, Salesforce will enforce limits on login IP ranges for specific profiles. If your organization uses profile-level IP restrictions, we recommend reviewing your current configurations now to ensure they will remain within the new limits.

The following items are standard security best practices that all customers should continue to follow:

  • Enable a Transaction Security Policy (TSP) that restricts large data exports
  • Avoid connecting from anonymizing proxies or high-risk IP addresses

For more details on these updates, refer to Salesforce’s New Security Control Requirements page. This page is updated regularly — we encourage you to monitor the Change Log table there for the latest information.

If you have any questions or concerns, please reach out to Veeva Support.

Changes to Public Key Infrastructure in Salesforce

Salesforce has announced upcoming mandatory changes to Public Key Infrastructure. Veeva standard integrations with Salesforce are not impacted. However, Veeva recommends customers review any custom-built integrations within their environments to ensure compliance with these upcoming changes.

End of Support

See End of Support for a list of deprecated features, devices, and OS versions.