🚀 Acunetix is now Invicti Web + API. Read the announcement.
Release Notes

Acunetix Standard & Premium

RSS Feed

v.Security - 03 Feb 2026

Enhanced API security testing with JWT bypass detection, authorization checks, and new CVE coverage for Java, MySQL, Oracle, osTicket, and more.

Security checks

– Updated the vulnerability database (VDB) to version 20260203

– Added comprehensive JWT authentication bypass detection
   – High: JWT Signature Bypass via None Algorithm
   – High: JWT Signature is not Verified
   – High: JWT Signature Bypass via kid SQL injection
   – High: JWT Signature Bypass via kid Path Traversal
   – High: JWT Signature Bypass via unvalidated jwk parameter
   – High: Unvalidated JWT jku parameter
   – High: Unvalidated JWT x5u parameter
   – High: JWT Signature Bypass via unvalidated jku parameter
   – High: JWT Signature Bypass via unvalidated x5u parameter
   – High: JWT Signature Bypass via unvalidated x5c parameter
– Added authorization vulnerability detection
   – High: Horizontal Broken Function Level Authorization (BFLA)
   – High: Unauthenticated Access to Sensitive Functions
   – High: Horizontal IDOR/BOLA (Broken Object Level Authorization)
   – High: Vertical Broken Function Level Authorization (BFLA)
   – High: Vertical IDOR/BOLA (Broken Object Level Authorization)
– Added sensitive information exposure detection
   – High: API Sensitive Info(PII) accessible without authentication
   – Medium: Resource Accessible Without Required Authentication
– Added API inventory management checks
   – Medium: API Authentication Bypass Using a Test/Staging Host Header
– Added microservice security checks
   – High: Microservice Directory Traversal
– Added vulnerability detection for Java:
   – Medium: CVE-2026-21925
   – High: CVE-2026-21932
   – Medium: CVE-2026-21933
   – High: CVE-2026-21945
– Added vulnerability detection for Jetty:
   – High: CVE-2025-5115
– Added vulnerability detection for Joomla:
   – Medium: CVE-2025-63082
   – Medium: CVE-2025-63083
– Removed vulnerability detection for LiferayPortal:
– Added vulnerability detection for LimeSurvey:
   – Medium: CVE-2020-36993
   – High: CVE-2024-39063
   – Critical: CVE-2025-41375
   – Medium: CVE-2025-41376
– Added vulnerability detection for MySQL:
   – Medium: CVE-2026-21964
– Added vulnerability detection for Oracle:
   – High: CVE-2026-21939
– Added vulnerability detection for Oracle HTTP Server:
   – Critical: CVE-2026-21962
– Added vulnerability detection for osTicket:
   – High: CVE-2026-22200
– Added vulnerability detection for phpMyFAQ:
   – Medium: CVE-2026-24420
   – Medium: CVE-2026-24421
   – High: CVE-2026-24422
– Updated severity for Oracle 23.8 from Medium to High
– Updated severity for osTicket 1.17, 1.17.1, 1.17.3, 1.17.4, 1.17.5, 1.17.6, 1.18 from Medium to High
– Added Zimbra Collaboration Suite (ZCS) Local File Inclusion check CVE-2025-68645

v.Security - 29 Jan 2026

Updates to the vulnerability database, improved XSS detection, and detection of new vulnerabilities for e107.

Security checks

  • Updated the vulnerability database (VDB) to version 20260127
  • Improved XSS detection
  • Added vulnerability detection for e107:

Resolved issue

  • Fixed notifications

v.Security - 20 Jan 2026

Security checks Updated the vulnerability database (VDB) to version 20260120 Updated severity rating for Craft CMS version 3.9.15 from Medium to Critical Updated severity ratings for Craft CMS versions 4.4.16, 4.4.16.1, 4.4.17, 4.5.0, 4.14.9, 4.14.10, 4.14.11, 4.14.11.1, 4.14.12, 4.14.13, 4.14.14, 4.14.15, 4.15.0, 4.15.0.1, 4.15.0.2, 4.15.1,...

Security checks

v.Security - 13 Jan 2026

Security update adds CVE-2025-66516 coverage and improved XXE detection accuracy. VDB updated to 20260113 with new vulnerability checks for OpenCart, PHP, WordPress, and phpMyFAQ including multiple high-severity CVEs.

Security checks

v.Security - 07 Jan 2026

VDB 20260106: added 15 versions across 18 technologies and 7 CVEs.

Security checks

  • Updated the Vulnerability Database (VDB) to version 20260106
  • Added 15 new versions for 18 technologies and 7 new CVEs
  • Updated severity ratings for MongoDB versions 4.2.18, 4.3.0-4.3.3, 4.4.29, 5.0.30-5.0.31, 6.0.23-6.0.26, 8.0.13-8.0.15, 8.2.0-8.2.1 from Medium to High
  • Updated severity rating for Podcast Generator version 3.2.9 from Medium to Critical
  • Updated severity ratings for Python versions 3.10.10-3.10.19, 3.11-3.11.14, 3.12-3.12.5 from High to Critical
  • Updated severity rating for Python version 3.12.6 from Medium to Critical
  • Added vulnerability detection for CrushFTP:
  • Added vulnerability detection for MongoDB:
  • Added vulnerability detection for Podcast Generator:
  • Added vulnerability detection for Python:
  • Added vulnerability detection for Roundcube:
  • Added vulnerability detection for phpMyFAQ:

v.Security - 30 Dec 2025

VDB 20251230: added 84 versions across 50 technologies and 133 CVEs. Updated vulnerabilities and OWASP Top 10 scan profile to align with OWASP Top 10 2025.

Security checks

  • Updated the Vulnerability Database (VDB) to version 20251230
  • Added 84 new versions for 50 technologies and 133 new CVEs
  • Improved severity ratings for Dotclear version 2.29 from Medium to High
  • Improved severity ratings for Jenkins versions 2.426.3, 2.452.4, 2.462.1-2.462.3, 2.471-2.492, 2.492.1-2.492.3, 2.493-2.501, 2.504 from Medium to High
  • Improved severity ratings for Liferay DXP versions 2024.q1.14-2024.q1.18 from High to Critical
  • Improved severity ratings for Liferay DXP versions 2024.q3.0, 2024.q4.7, 2025.q1.0-2025.q1.14, 2025.q2.0 from Medium to Critical
  • Improved severity ratings for Liferay Portal version 7.4.3.132 from Medium to Critical
  • Improved severity ratings for Next.js React Framework versions 15.2.6-15.2.7, 15.3.6-15.3.7, 15.4.8-15.4.9 from Critical to High
  • Improved severity ratings for Next.js React Framework version 15.6.0 from High to Critical
  • Improved severity ratings for React versions 19.0.1-19.0.2, 19.1.2-19.1.3 from Critical to High
  • Improved severity ratings for Roundcube versions 1.5.6, 1.6.5-1.6.6 from Medium to High
  • Improved severity ratings for Ruby version 1.9.0 from Critical to High

Improvements

  • Updated vulnerability classifications to align with OWASP Top 10 2025 categories
  • Updated OWASP Top 10 scan profile to align with OWASP Top 10 2025 categories

v25.12.3 - Security - 15 Dec 2025

VDB 20251215: Added 179 versions across 37 technologies and 118 CVEs. Critical updates for Liferay and SharePoint. Enhanced DOM XSS and Open Redirect detection.

Security checks

Improvements

  • Improved detection of DOM XSS vulnerabilities
  • Updated the alert text of the most detected vulnerabilities

Resolved issues

  • Improved detection of “Sensitive pages could be cached” vulnerabilities
  • Improved detection of “Open Redirect” vulnerabilities

v25.12.2 - Security - 09 Dec 2025

Version 25.12.2 enhances security with an updated Vulnerability Database (VDB) version 20251209, ensuring the latest checks and improved detection coverage.

Security check

  • Updated the Vulnerability Database (VDB) to version 20251209

v25.12.1 - Security - 08 Dec 2025

Added security checks for critical RCE vulnerabilities CVE-2025-55182 and CVE-2025-66478 in React Server Components/Next.js.

Security checks

1 2 3 … 30