Acunetix DAST powers runtime capabilities for Invicti’s complete AppSec platform. Visit Invicti for more.

Acunetix 360 On-Demand - v25.12.0

New features

  • Enhanced REST API compliance by implementing proper PUT verb endpoints for 13 update operations (AgentGroups, AuthenticationProfiles, Discovery, Issues, Members, Notifications, Roles, ScanPolicies, ScanProfiles, Team, WebsiteGroups, Websites). Legacy POST endpoints remain fully supported for backward compatibility.
  • Added support for retrieving OAuth2 credentials from secrets storage

Improvements

 
  • Added agent type information to Queue Reason for improved clarity
  • Added the `InterceptDocumentOnly` setting to the Scan policy section under the Browser tab for easier access
  • Limited all discovery settings entries to 100 lines to address performance issues and improve data retrieval efficiency
  • Upgraded the underlying engine to `Chromium 137.0.7151.68`, delivering critical security patches, improved stability, and better performance
  • Unified the Splunk Enterprise and Splunk Cloud add-ons into a single package for simplified deployment and maintenance. The legacy on-premises app is now deprecated, with full support for both platforms available in the consolidated add-on.
Resolved issues  
  • Proxy credentials are now properly masked in `InvictiProxy` logs
  • Resolved API request errors that occurred when `UrlRewriteExcludedLinks` was added to a profile
  • Fixed a permissions issue where users without Edit Members permissions were unable to perform API Token Reset operations
  • Resolved an issue where manually disabling an agent assigned to queued or active scans would cause those scans to become stuck indefinitely. The system now prevents disabling agents with assigned scans and displays clear error messages
  • Fixed the `/api/1.0/agentgroups/list` endpoint returning null for the Teams field when TeamAgentGroupAssignmentEnabled was enabled, ensuring team assignments for agent groups are properly retrieved
  • Corrected an issue where excluded cookies were incorrectly appearing in scan reports
  • Fixed missing `Known issues` and `CVE details` on the Scan Summary page