🚀 Acunetix is now Invicti Web + API. Read the announcement.
Release Notes

Acunetix 360 On-Premises

RSS Feed

v26.9.1 - 24 Sep 2026

The latest release adds secrets support in custom authentication scripts, extends scan data retention, and fixes a CyberArk NTLM authentication issue.

New features

  • Secrets in custom authentication scripts: Added support for secrets in custom authentication scripts, allowing you to securely manage and test sensitive credentials during automated scans.

Improvements

  • Extended scan data retention: Improved scan data retention settings to allow you to store scan results for longer periods.
  • API endpoint accuracy for HTTPS websites: Fixed an issue where API requests for HTTPS websites incorrectly returned HTTP records, ensuring the correct website data is retrieved based on the requested protocol.

Bug fixes

  • CyberArk NTLM authentication: Fixed an issue where CyberArk secret resolution failed for NTLM authentication, allowing credentials and vault connections to be verified successfully.

Verify the hash value for package integrity

The hash value for the 26.9.1.zip file is D784D7F115F82329DF97084DB54DBE24D760EC184183A90C4001D655AC17577C.

You can verify the integrity of the file by checking its hash value using one of the outlined methods:

  • PowerShell (Windows): Get-FileHash -Path "26.9.1.zip" -Algorithm SHA256
  • Command Prompt (Windows): certutil -hashfile "26.9.1.zip" SHA256
  • Linux or macOS: sha256sum "26.9.1.zip"

v26.9.0 - 10 Sep 2026

The latest release resolves authentication, stability, and recording issues.

Improvements

  • Login Screen Recorder content and interactions: Updated the Login Screen Recorder content and fixed an issue where button clicks weren’t correctly captured during recording sessions.
  • Chromium engine update: Updated the internal Chromium engine to version 149 to provide improved security, stability, and performance.

Resolved issues

  • Platform stability during target configuration: Fixed an issue where editing a target caused the platform to become unresponsive, ensuring the service remains available and stable during configuration updates.
  • Business Logic Recorder authentication with CyberArk: Fixed an issue where the Business Logic Recorder failed to authenticate with CyberArk credentials, ensuring recordings now correctly start from the authenticated session.
  • SSO and Okta authentication after upgrade: Fixed an issue where SSO and Okta logins failed after an upgrade, allowing users to successfully authenticate and access the application again.

Verify the hash value for package integrity

  • The hash value for the 26.9.0.zip file is B183A9DA96684E62175BB35E1B7EF04C5AA71C59C959C2D770D7BD1EE5C86CB4.

You can verify the integrity of the file by checking its hash value using one of the outlined methods:

  • PowerShell (Windows): Get-FileHash -Path "26.9.0.zip" -Algorithm SHA256
  • Command Prompt (Windows): certutil -hashfile "26.9.0.zip" SHA256
  • Linux or macOS: sha256sum "26.9.0.zip"

v26.8.1 - 27 Aug 2026

The latest release adds opt-in HAR file generation for auth verification, fixes DB transactions, login paste, and scan agent failover.

Improvements

  • Generate HAR files option for authentication verification: Added an opt-in Generate HAR files option for authentication verification. The option is turned off by default to avoid unnecessary HAR file generation.
  • Background tasks no longer generate excessive database transactions: Fixed excessive database transactions generated by background tasks to prevent rapid audit log growth and ensure stable performance on Azure SQL Managed Instances.

Resolved issues

  • Text pasting in the Interactive Login window now works as expected: Fixed an issue preventing text from being pasted into the Interactive Login window, so you can now use keyboard shortcuts to enter credentials.
  • Scheduled scans now use available agents when the preferred agent is unavailable: Fixed an issue where scheduled scans failed if a specific agent became unavailable. Scans now correctly use other available agents within the assigned agent group.

Verify the Hash value for package integrity in Acunetix 360 on-premises

The hash value for the “26.8.1.zip” file is 10CF093A86B4656A64480CB2BF9A08F4723BFDF2D74C6F978ABAFDF52946CEE17.

You can verify the integrity of the file by checking its hash value using one of the outlined methods:

PowerShell (Windows):

Get-FileHash -Path "26.8.1.zip" -Algorithm SHA256
Command Prompt (Windows):

certutil -hashfile "26.8.1.zip" SHA256
Linux or macOS:

sha256sum "26.8.1.zip"

v26.8.0 - 13 Aug 2026

The latest release includes .NET 10 upgrades, 730-day data retention, PATCH API support, and authentication fixes

New features

  • Partial API updates (PATCH semantics) for scan profile and policy endpoints: You can now modify specific settings through the API without resubmitting the entire configuration object, so existing values are preserved when you update only part of a profile or policy.

Improvements

  • 730-day scan data retention: You can now configure scan data retention for up to 730 days (two years), giving you longer access to historical scan results.
  • Auth Verifier Service upgraded to .NET 10: The Auth Verifier Service now runs on .NET 10, ensuring long-term support, improved security, and access to the latest platform features.
  • Scan agent upgraded to .NET 10: The scan agent now runs on .NET 10, delivering improved performance and enhanced stability.

Resolved issues

  • Scheduled scans now authenticate correctly with OAuth 2: Fixed an issue where scheduled scans failed to authenticate using OAuth 2, ensuring automated scans complete as expected.
  • Scan control API endpoint no longer returns unauthorized errors: The scan control API endpoint now correctly accepts requests using valid API credentials, so you can manage scan settings without unexpected authentication failures.
  • Scans no longer fail when encountering null values during concurrent scanning: Fixed an issue that caused scans to fail when encountering null values, ensuring more reliable performance during high-volume concurrent scanning.
  • Interactive Login and OAuth2 Test Connection now complete reliably: Fixed issues where Interactive Login hung during session saving and the OAuth2 Test Connection button remained unresponsive, ensuring authentication configurations and tests complete successfully.
  • GraphQL vulnerability reports now show correct request and response data: Security reports for GraphQL checks now display the accurate request and response details for the detected vulnerability.

Verify the Hash value for package integrity in Acunetix 360 on-premises

The hash value for the “26.8.0.zip” file is 10488B82C4E4D773670B17309072C2B5ABEFC8B2B2BCC0324DD980C1A91F8DFA.

You can verify the integrity of the file by checking its hash value using one of the outlined methods:

PowerShell (Windows):

Get-FileHash -Path "26.8.0.zip" -Algorithm SHA256
Command Prompt (Windows):

certutil -hashfile "26.8.0.zip" SHA256
Linux or macOS:

sha256sum "26.8.0.zip"

v26.7.1 - 28 Jul 2026

The latest release includes OAuth2 and security fixes, PDF report improvements, and better scheduled scan profile handling.

Improvements

  • Agents page now alerts you when vulnerability database updates can’t be completed: Added a notification to the agents page that alerts you when vulnerability database updates fail due to connection issues, with guidance on how to resolve the issue.
  • AWS Load Balancer configuration no longer hides dropdown menus and agent options: Fixed an issue where AWS Load Balancer settings could cause dropdown menus and agent selection options to disappear.

Resolved issues

  • OAuth2 Test Connection and Interactive Login now complete reliably: Fixed issues where Interactive Login hung during session saving and the OAuth2 Test Connection UI remained unresponsive, ensuring authentication configurations and tests complete successfully.
  • Docker agents updated with security improvements: Updated Docker agents to address reported security findings and improve overall system security.
  • PDF reports now correctly handle special characters in vulnerability titles: Fixed an issue where vulnerability titles containing special characters weren’t properly escaped during PDF report generation, which could allow unintended access to system files.
  • Scheduled scans now apply the most recent primary scan profile: Fixed an issue where scheduled scans used outdated profile information, ensuring that updates to primary scan profiles are correctly applied to all future scans.
  • Agents and verifiers now download the correct runtime payload versions: Fixed an issue where the license download path could deliver incorrect agent and verifier runtime payloads, resulting in mixed component versions being installed.

Verify the Hash value for package integrity in Acunetix 360 on-premises

The hash value for the “26.7.1.zip” file is 72CAB75C7DE323CE66CCDEE4E5C129AB0FEDFD5A15433E4B382305164C5C79B9.

You can verify the integrity of the file by checking its hash value using one of the outlined methods:

PowerShell (Windows):

Get-FileHash -Path "26.7.1.zip" -Algorithm SHA256
Command Prompt (Windows):

certutil -hashfile "26.7.1.zip" SHA256
Linux or macOS:

sha256sum "26.7.1.zip"

v26.7.0 - 16 Jul 2026

This update includes TLS proof data, API secret retention, OTP masking, CWE-829 classification, and fixes for scan stability and agent assignment.

Improvements

  • Legacy TLS protocol findings now include supporting proof: When legacy TLS protocols are detected, findings now include proof data to help you validate and communicate the issue.
  • Scan profile updates via API now preserve existing secrets: You can now modify scan profile settings through the API without re-entering sensitive credentials – existing secrets are retained automatically.
  • OTP secret key is now masked: The OTP secret key is now masked in the UI to prevent exposure.
  • Polyfill.io supply chain attack check now includes CWE-829 classification: The Polyfill.io supply chain attack security check now includes CWE-829 classification, improving vulnerability categorization and reporting accuracy.

Resolved issues

  • Simultaneous scheduled scans no longer cause service instability: Scheduling a large number of individual scans at the same time could cause service disruptions. Concurrent scan starts per account are now limited to ensure system stability.
  • Issue details now correctly distinguish attacked parameters: The Parameters table in issue details previously showed misleading labels for 500 Internal Server Error findings. Labels now clearly distinguish general request parameters from the specific parameter that was attacked.
  • “Any available Agent” selection now saves correctly for scheduled scans: Fixed an issue preventing users from saving the “Any available Agent” selection for scheduled scans, ensuring scans are correctly assigned to active agents and complete successfully.

Verify the Hash value for package integrity in Acunetix 360 on-premises

The hash value for the “26.7.0.zip” file is F748222ED48219339370E05E77B327B614B7E58AF5D54C83BCE7A533A63ECBC2.

You can verify the integrity of the file by checking its hash value using one of the outlined methods:

PowerShell (Windows):

Get-FileHash -Path "26.7.0.zip" -Algorithm SHA256
Command Prompt (Windows):

certutil -hashfile "26.7.0.zip" SHA256
Linux or macOS:

sha256sum "26.7.0.zip"

    v26.6.2 - 24 Jun 2026

    The latest release introduces enhanced secret management, standardizes API update operations with PUT endpoints, and addresses scan stability issues.
    Due to a Windows single EXE file size limitation, the WebApp installer package has been split into multiple files; simply extract zip file and run WebAppSetup.exe from the WebApp folder as usual.

    New features

    • Pre-scan authentication validation for NTLM, Basic, and Kerberos: Scans can now be configured to fail immediately if credentials are invalid, preventing unauthenticated scans from running silently.
    • Sitemap data retention policy now available in General Settings: Root users can now enable automatic cleanup of sitemap data older than one year, helping manage storage and keep scan data relevant.
    • Interactive Login now supported on the Form Authentication page: Users can now handle MFA, CAPTCHA, and other interactive authentication steps directly within the UI during scan setup. Captured sessions are stored encrypted and reused automatically across future scans.

    Improvements

    • Docker agent updated with latest security patches: The Docker agent base image has been updated to address a critical OpenSSL vulnerability.
    • Scans now fail immediately when the target returns HTTP 502-503-504: If the first response is 502-503-504, the scan stops right away rather than continuing against an unreachable target.

    Resolved issues

    • Custom policy severity settings no longer reset after a product update: User-configured severity levels in custom report policies are now preserved across upgrades.
    • Multiple scan notifications can now be created for the same target with different scan groups: Creating more than one “New Scan Notification” for the same target was incorrectly blocked when scan groups differed. The duplicate check now accounts for scan group selection.
    • Login/Logout Verification dialog no longer shows stale errors on quick reopen: Closing and immediately reopening the verification modal no longer causes outdated error messages or incorrect UI state to appear.
    • Targets can no longer be re-imported before the deletion grace period has elapsed: A target deleted within the last week could cause “already exists” errors when re-adding the same URL. This is now handled correctly.
    • Remediation scans now correctly use the target’s assigned agent group: On-Prem remediation scans triggered via “Mark as Fixed (Unconfirmed)” were getting stuck in queue because the wrong agent was selected instead of the target’s configured internal agent group. Remediation scans now use the same agent selection logic as full and retest scans.
    • Report generation no longer fails for findings with expired request/response data: Generating reports that included older findings where HTTP request/response data had been purged per the retention policy could cause the report to fail entirely. The report engine now handles missing evidence gracefully.
    • Sensitive information masking logic improved: The “Prevent any sensitive information showing within the product” option now works more reliably across relevant areas of the UI.
    • FIDO2 security key (YubiKey) registration no longer fails with “Incorrect U2F security key” error: A dependency version mismatch was causing YubiKey registration to fail. This has been resolved and FIDO2 keys can now be registered successfully.

    Security checks

    • JavaScript Source Map detection now available Added Javascript Source Map detected vulnerability into security checks.

    Verify the Hash value for package integrity in Acunetix 360 on-premises

    The hash value for the “26.6.2.zip” file is D25551814278DA7BE384A2991AF3D6A715AAAA3236479EB5A36DB8543798E971.

    You can verify the integrity of the file by checking its hash value using one of the outlined methods:

    PowerShell (Windows):
    
    Get-FileHash -Path "26.6.2.zip" -Algorithm SHA256
    Command Prompt (Windows):
    
    certutil -hashfile "26.6.2.zip" SHA256
    Linux or macOS:
    
    sha256sum "26.6.2.zip"

    v26.6.1 - 11 Jun 2026

    Security & reliability updates Enhanced Security: Dependency Vulnerability Fixes We have resolved security vulnerabilities in third-party libraries used within the platform. These fixes eliminate potential attack vectors and ensure your environment remains protected against known exploits. Platform Security Patches (.NET 8.0.28) We have updated the core runtime...

    Security & reliability updates

    • Enhanced Security: Dependency Vulnerability Fixes We have resolved security vulnerabilities in third-party libraries used within the platform. These fixes eliminate potential attack vectors and ensure your environment remains protected against known exploits.
    • Platform Security Patches (.NET 8.0.28) We have updated the core runtime powering our Scanner/AV Agent and Auth Verifier Service Hub to incorporate the latest Microsoft security patches. This ensures your environment benefits from the most recent protections against emerging threats, keeping your data and services secure.

    Verify the Hash value for package integrity in Acunetix 360 on-premises

    The hash value for the “26.6.1.zip” file is C8584500B45405273DC6B1650523555214268630B751D3BABDBD295F764B0001.

    You can verify the integrity of the file by checking its hash value using one of the outlined methods:

    PowerShell (Windows):
    
    Get-FileHash -Path "26.6.1.zip" -Algorithm SHA256
    Command Prompt (Windows):
    
    certutil -hashfile "26.6.1.zip" SHA256
    Linux or macOS:
    
    sha256sum "26.6.1.zip"

    v26.5.1 - 21 May 2026

    The latest release includes AutoMapper CVE-2026-32933 fix, .NET 8 security patches, faster incremental scans, GraphQL, invite, and login fixes.

    Security checks

    • CVE-2026-32933 remediation: Upgraded the AutoMapper library to remediate CVE-2026-32933, protecting your environment against the recently disclosed unbounded-recursion vulnerability.

    Improvements

    • .NET 8 security patches in scanner/AV agent: Updated the .NET 8 SDK to the latest version to include Microsoft’s newest security patches in the internal scanner/AV agent, keeping your agents protected against recently disclosed .NET vulnerabilities.
    • Incremental scan efficiency: Incremental scans now retest with the detection pattern only instead of re-running full attack payloads on unchanged content, so subsequent scans complete faster without behaving like full scans.

    Resolved issues

    • GraphQL audit duplicate findings: The GraphQL Audit script now runs as an active check with a groupable signature, so unrelated payloads sent to GraphQL endpoints are no longer reported as separate “Introspection Query Enabled” findings.
    • Invite email protection: You can no longer change the invitee’s email during team or account invitations, ensuring invitations always go to the correct, intended address.
    • Login & logout verification: The “Verify login & logout” button has been fixed, ensuring you can validate your authentication settings without interruption.

    Verify the Hash value for package integrity in Acunetix 360 on-premises

    The hash value for the “26.5.1.zip” file is 0294ABC6E3C7C03221323373F5CD95FAEA9632CBC2D2DC7A2711D768285D5ABA.

    You can verify the integrity of the file by checking its hash value using one of the outlined methods:

    PowerShell (Windows):
    
    Get-FileHash -Path "26.5.1.zip" -Algorithm SHA256
    Command Prompt (Windows):
    
    certutil -hashfile "26.5.1.zip" SHA256
    Linux or macOS:
    
    sha256sum "26.5.1.zip"
    1 2 … 7