🚀 Acunetix is now Invicti Web + API. Read the announcement.
Release Notes

Acunetix 360 On-Demand

RSS Feed

v26.1.0 - 13 Jan 2026

Latest update adds 1-year Sitemap retention, Browser logs in verification, and Jira Fix Versions support. Includes OAuth2 fixes, libtiff6 security update, and improvements to chatbot persistence, URL rewriting, and scan scheduling.

New features

  • Added a 1-year retention policy for Sitemap records
  • Added Browser Network and Console logs to the verification log area

Improvements

  • Added support for Fix Versions when creating Jira issues via integration. Multiple fix versions can now be assigned to a single issue. Supports mixed usage of name and id attributes such as [{"name":"v1.2"},{"id":"10001"},{"name":"v1.0"}]
  • Chatbot pop-up now displays after redirection and persists until manually closed by the user

Resolved issues

  • Fixed OAuth2 update issue regarding the use of ‘secret’
  • Updated the vulnerable libtiff6 package
  • Fixed TempPath-dependent errors when the path contains whitespace
  • Fixed next execution time recalculation for on-premises environments after scan is triggered
  • Fixed InvictiProxy usage on Auth Verifiers
  • Fixed incorrect redirect for More Information link on URL Rewrite Custom Mode
  • Fixed OAuth2 3-legged Authorization code issue
  • Fixed sitemap issue causing URLs with /#/ to be missing
  • Fixed gRPC attack engine to use form values
  • Fixed retest scan launch failure
  • Fixed scan data archiving error

v25.12.0 - 10 Dec 2025

Enhanced API compliance with 13 new PUT endpoints, OAuth2 secrets support, and Chromium 137 upgrade. Unified Splunk add-on, improved agent management, and fixes for proxy logging, scan queue issues, and API permissions.

New features

  • Enhanced REST API compliance by implementing proper PUT verb endpoints for 13 update operations (AgentGroups, AuthenticationProfiles, Discovery, Issues, Members, Notifications, Roles, ScanPolicies, ScanProfiles, Team, WebsiteGroups, Websites). Legacy POST endpoints remain fully supported for backward compatibility.
  • Added support for retrieving OAuth2 credentials from secrets storage

Improvements

 

  • Added agent type information to Queue Reason for improved clarity
  • Added the `InterceptDocumentOnly` setting to the Scan policy section under the Browser tab for easier access
  • Limited all discovery settings entries to 100 lines to address performance issues and improve data retrieval efficiency
  • Upgraded the underlying engine to `Chromium 137.0.7151.68`, delivering critical security patches, improved stability, and better performance
  • Unified the Splunk Enterprise and Splunk Cloud add-ons into a single package for simplified deployment and maintenance. The legacy on-premises app is now deprecated, with full support for both platforms available in the consolidated add-on.

Resolved issues

 

  • Proxy credentials are now properly masked in `InvictiProxy` logs
  • Resolved API request errors that occurred when `UrlRewriteExcludedLinks` was added to a profile
  • Fixed a permissions issue where users without Edit Members permissions were unable to perform API Token Reset operations
  • Resolved an issue where manually disabling an agent assigned to queued or active scans would cause those scans to become stuck indefinitely. The system now prevents disabling agents with assigned scans and displays clear error messages
  • Fixed the `/api/1.0/agentgroups/list` endpoint returning null for the Teams field when TeamAgentGroupAssignmentEnabled was enabled, ensuring team assignments for agent groups are properly retrieved
  • Corrected an issue where excluded cookies were incorrectly appearing in scan reports
  • Fixed missing `Known issues` and `CVE details` on the Scan Summary page

 

v25.11.2-HF - 05 Dec 2025

This release includes security checks for Next.js/React Server Components RCE (React2Shell) vulnerability.

Security checks

v25.11.1-HF - 20 Nov 2025

Hotfix for an issue that was causing login failures during authenticated scans

Resolved issue

  • Fixed an issue that was causing login failures during authenticated scans

v25.11.1 - 19 Nov 2025

Aligned Acunetix security checks with report policy and improved scan stability when using custom scripts

New feature

  • Implemented Acunetix security checks into the report policy, aligning it with the existing functionality in Invicti Standard

Resolved issue

  • Prevented scan fails due to syntax errors on custom security scripts

v25.11.0 - 11 Nov 2025

New features Added support for referencing secrets from SEM integrations when configuring Basic, Digest, NTLM/Kerberos, or Negotiate authentication Improvements Added “Fix versions” field to the JIRA integration Added “Queue reason” to the Scan summary page Improved IP Restriction Logic Improved the “SameSite Cookie Not Implemented”...

New features

  • Added support for referencing secrets from SEM integrations when configuring Basic, Digest, NTLM/Kerberos, or Negotiate authentication

Improvements

  • Added “Fix versions” field to the JIRA integration
  • Added “Queue reason” to the Scan summary page
  • Improved IP Restriction Logic
  • Improved the “SameSite Cookie Not Implemented” security check
  • Improved the “JWT Signature is not Verified” security check

Resolved issues

  • Fixed a layout problem when adding a new certificate
  • Fixed an issue showing wrong Vulnerability Database (VDB) version
  • Fixed a cache cleaning issue
  • Fixed an issue where users without an API Discovery license saw the error “ApiHub Service URL cannot be empty” when updating items on the Settings > General page
  • Fixed “The deletion of the website continues” issue when adding a target
  • Fixed an empty list issue in the Mend integration
  • Fixed an issue where Linux/cloud agents couldn’t parse secrets pre-request query parameters for a customer environment
  • Updated Java sensor
  • Fixed an issue with confirmation SMS messages

v25.10.1 - 27 Oct 2025

Improvements Updated .NET 8 runtime to fix a security issue (CVE-2025-55315)

Improvements

v25.10.0 - 15 Oct 2025

New update: WebLogic support, SEM secret integration, API improvements, and fixes for scan errors, auto-updates, and security reports

New feature

  • Added WebLogic support for JAVA Shark sensor
  • The Secrets screen now supports selecting and referencing secrets from SEM integrations in addition to manually entered name–value pairs. This allows more secure and centralized secret management

Improvements

  • Replaced old POST deletion methods with standard DELETE endpoints for a more consistent API. The POST endpoints are now deprecated – please update your integrations.

Resolved issues

  • Corrected a typo in the Ivanti RCE CVE-2024-21887 report template
  • Improved detection of CSP directives
  • Resolved containerized Agents being stuck during auto-updates
  • Fixed “Unable to Load Scan Session” and “Unable to Find Scan Files” errors
  • Corrected discrepancies in Roles permission counts
  • Enabled Agent auto-updater to use encrypted proxy credentials from appsettings.json
  • Added RegEx validation to prevent invalid patterns causing scan failures
  • Fixed Intel instance assignment issue for On-Prem Cloud Provider

v25.9.1 - 23 Sep 2025

New feature Improvements Resolved issues

New feature

  • Introduced Global Client Certificates: Admins can now add client certificates to the Global Certificate section and apply them directly to Scan Profiles

Improvements

  • Added “Export to CSV” functionality to several pages, including Scan Policies, Report Policies, Scan Profiles, Scheduled Scans, and Website Groups
  • Updated GitHub Actions to their latest stable versions to take advantage of new features and performance improvements

Resolved issues

  • Resolved an issue where clicking “Toggle Content” did not display the list of Imported Links on scan profiles
  • Resolved an issue with parsing JIRA Custom Complex Fields in JSON
  • Addressed SSL errors in certificate-based environments by adding support for the IgnoreSslCertificateErrors parameter
  • Corrected an issue where NTLM “Test Credentials” incorrectly passed using default credentials; invalid credentials now fail as expected
  • Resolved issues with previously problematic Report Policies
1 2 3 4 … 18