🚀 Acunetix is now Invicti Web + API. Read the announcement.
Release Notes

Acunetix 360 On-Demand

RSS Feed

v26.9.1 - 24 Sep 2026

The latest release adds support for secrets in custom authentication scripts, extends scan data retention, and includes a PolyShell security check.

New features

  • Secrets in custom authentication scripts: Added support for secrets in custom authentication scripts, allowing you to securely manage and test sensitive credentials during automated scans.

Improvements

  • Extended scan data retention: Improved scan data retention settings to allow you to store scan results for longer periods.
  • API endpoint accuracy for HTTPS websites: Fixed an issue where API requests for HTTPS websites incorrectly returned HTTP records, ensuring the correct website data is retrieved based on the requested protocol.

Bug fixes

  • CyberArk NTLM authentication: Fixed an issue where CyberArk secret resolution failed for NTLM authentication, allowing credentials and vault connections to be verified successfully.

Security checks

  • PolyShell (APSB25-94): Added a security check that identifies Adobe Commerce and Magento installations where the unauthenticated guest-cart REST API allows attackers to upload PHP polyglot files, bypass image validation, and achieve remote code execution.

v26.9.0 - 10 Sep 2026

The latest release resolves authentication, stability, and recording issues.

Improvements

  • Login Screen Recorder content and interactions: Updated the Login Screen Recorder content and fixed an issue where button clicks weren’t correctly captured during recording sessions.
  • Chromium engine update: Updated the internal Chromium engine to version 149 to provide improved security, stability, and performance.

Resolved issues

  • Platform stability during target configuration: Fixed an issue where editing a target caused the platform to become unresponsive, ensuring the service remains available and stable during configuration updates.
  • Business Logic Recorder authentication with CyberArk: Fixed an issue where the Business Logic Recorder failed to authenticate with CyberArk credentials, ensuring recordings now correctly start from the authenticated session.
  • SSO and Okta authentication after upgrade: Fixed an issue where SSO and Okta logins failed after an upgrade, allowing users to successfully authenticate and access the application again.

v26.8.1 - 27 Aug 2026

The latest release adds opt-in HAR file generation for auth verification, fixes DB transactions, login paste, and scan agent failover.

Improvements

  • Generate HAR files option for authentication verification: Added an opt-in Generate HAR files option for authentication verification. The option is turned off by default to avoid unnecessary HAR file generation.
  • Background tasks no longer generate excessive database transactions: Fixed excessive database transactions generated by background tasks to prevent rapid audit log growth and ensure stable performance on Azure SQL Managed Instances.

Resolved issues

  • Text pasting in the Interactive Login window now works as expected: Fixed an issue preventing text from being pasted into the Interactive Login window, so you can now use keyboard shortcuts to enter credentials.
  • Scheduled scans now use available agents when the preferred agent is unavailable: Fixed an issue where scheduled scans failed if a specific agent became unavailable. Scans now correctly use other available agents within the assigned agent group.

v26.8.0 - 13 Aug 2026

The latest release includes .NET 10 upgrades, 730-day scan data retention, partial API updates, and OAuth 2 scheduled scan fixes.

New features

  • Partial API updates (PATCH semantics) for scan profile and policy endpoints: You can now modify specific settings through the API without resubmitting the entire configuration object, so existing values are preserved when you update only part of a profile or policy.

Improvements

  • 730-day scan data retention: You can now configure scan data retention for up to 730 days (two years), giving you longer access to historical scan results.
  • Scan control API endpoint no longer returns unauthorized errors: The scan control API endpoint now correctly accepts requests using valid API credentials, so you can manage scan settings without unexpected authentication failures.
  • Auth Verifier Service upgraded to .NET 10: The Auth Verifier Service now runs on .NET 10, ensuring long-term support, improved security, and access to the latest platform features.
  • Scan agent upgraded to .NET 10: The scan agent now runs on .NET 10, delivering improved performance and enhanced stability.

Resolved issues

  • Scheduled scans now authenticate correctly with OAuth 2: Fixed an issue where scheduled scans failed to authenticate using OAuth 2, ensuring automated scans complete as expected.
  • Scans no longer fail when encountering null values during concurrent scanning: Fixed an issue that caused scans to fail when encountering null values, ensuring more reliable performance during high-volume concurrent scanning.
  • Interactive Login and OAuth2 Test Connection now complete reliably: Fixed issues where Interactive Login hung during session saving and the OAuth2 Test Connection button remained unresponsive, ensuring authentication configurations and tests complete successfully.
  • GraphQL vulnerability reports now show correct request and response data: Security reports for GraphQL checks now display the accurate request and response details for the detected vulnerability.

v26.7.1 - 28 Jul 2026

The latest release includes OAuth2 and interactive login fixes, security updates, PDF report improvements, and scheduled scan profile corrections.

Improvements

  • Agents page now alerts you when vulnerability database updates can’t be completed: Added a notification to the agents page that alerts you when vulnerability database updates fail due to connection issues, with guidance on how to resolve the issue.

Resolved issues

  • OAuth2 Test Connection and Interactive Login now complete reliably: Fixed issues where Interactive Login hung during session saving and the OAuth2 Test Connection UI remained unresponsive, ensuring authentication configurations and tests complete successfully.
  • Docker agents updated with security improvements: Updated Docker agents to address reported security findings and improve overall system security.
  • PDF reports now correctly handle special characters in vulnerability titles: Fixed an issue where vulnerability titles containing special characters weren’t properly escaped during PDF report generation, which could allow unintended access to system files.
  • Scheduled scans now apply the most recent primary scan profile: Fixed an issue where scheduled scans used outdated profile information, ensuring that updates to primary scan profiles are correctly applied to all future scans.
  • Agents and verifiers now download the correct runtime payload versions: Fixed an issue where the license download path could deliver incorrect agent and verifier runtime payloads, resulting in mixed component versions being installed.
  • AWS Load Balancer configuration no longer hides dropdown menus and agent options: Fixed an issue where AWS Load Balancer settings could cause dropdown menus and agent selection options to disappear.

v26.6.1 - 16 Jun 2026

The latest release introduces pre-scan auth validation, interactive MFA login, sitemap data retention, and security patches.

New features

  • Pre-scan authentication validation for NTLM, Basic, and Kerberos: Scans can now be configured to fail immediately if credentials are invalid, preventing unauthenticated scans from running silently.
  • Sitemap data retention policy now available in General Settings: Root users can now enable automatic cleanup of sitemap data older than one year, helping manage storage and keep scan data relevant.
  • Interactive Login now supported on the Form Authentication page: Users can now handle MFA, CAPTCHA, and other interactive authentication steps directly within the UI during scan setup. Captured sessions are stored encrypted and reused automatically across future scans.

Improvements

  • Docker agent updated with latest security patches: The Docker agent base image has been updated to address a critical OpenSSL vulnerability.
  • Scans now fail immediately when the target returns HTTP 502: If the first response is a 502, the scan stops right away rather than continuing against an unreachable target.

Resolved issues

  • Custom policy severity settings no longer reset after a product update: User-configured severity levels in custom report policies are now preserved across upgrades.
  • Multiple scan notifications can now be created for the same target with different scan groups: Creating more than one “New Scan Notification” for the same target was incorrectly blocked when scan groups differed. The duplicate check now accounts for scan group selection.
  • Login/Logout Verification dialog no longer shows stale errors on quick reopen: Closing and immediately reopening the verification modal no longer causes outdated error messages or incorrect UI state to appear.
  • Targets can no longer be re-imported before the deletion grace period has elapsed: A target deleted within the last week could cause “already exists” errors when re-adding the same URL. This is now handled correctly.
  • Remediation scans now correctly use the target’s assigned agent group: On-Prem remediation scans triggered via “Mark as Fixed (Unconfirmed)” were getting stuck in queue because the wrong agent was selected instead of the target’s configured internal agent group. Remediation scans now use the same agent selection logic as full and retest scans.
  • Splunk plugin link now directs to the correct page: The Splunk integration link was pointing to an incorrect destination and has been fixed.
  • Report generation no longer fails for findings with expired request/response data: Generating reports that included older findings where HTTP request/response data had been purged per the retention policy could cause the report to fail entirely. The report engine now handles missing evidence gracefully.
  • Sensitive information masking logic improved: The “Prevent any sensitive information showing within the product” option now works more reliably across relevant areas of the UI.
  • FIDO2 security key (YubiKey) registration no longer fails with “Incorrect U2F security key” error: A dependency version mismatch was causing YubiKey registration to fail. This has been resolved and FIDO2 keys can now be registered successfully.

Security checks

  • JavaScript Source Map detection now available Added Javascript Source Map detected vulnerability into security checks.

v26.6.0 - 11 Jun 2026

The latest release provides enhanced security checks and updates.

Security & reliability updates

  • Enhanced Security: Dependency Vulnerability Fixes We have resolved security vulnerabilities in third-party libraries used within the platform. These fixes eliminate potential attack vectors and ensure your environment remains protected against known exploits.
  • Platform Security Patches (.NET 8.0.28) We have updated the core runtime powering our Scanner/AV Agent and Auth Verifier Service Hub to incorporate the latest Microsoft security patches. This ensures your environment benefits from the most recent protections against emerging threats, keeping your data and services secure.

Security checks

  • Imported scripts, including Javascript sourcemap detection.

v26.5.1 - 21 May 2026

The latest release includes AutoMapper CVE-2026-32933 fix, evidence field for version disclosure, MongoDB detection accuracy, and notification fix.

Security checks

  • CVE-2026-32933 remediation: Upgraded the AutoMapper library to remediate CVE-2026-32933, protecting your environment against the recently disclosed unbounded-recursion vulnerability.

New features

  • Evidence field for version disclosure and outdated technology findings: Version disclosure and outdated technology findings now include an evidence field that shows exactly where the scanner detected the library, so you can locate and remediate the source faster.

Improvements

  • MongoDB injection detection accuracy: Improved the Boolean-based MongoDB injection detection engine to reduce false positives on applications that don’t use MongoDB.

Resolved issues

  • Notifications to deactivated or deleted users: Notification emails no longer reach users who have been deactivated or deleted while an active notification relationship still exists, so scan-completion alerts only go to active recipients.

v26.5.0 - 12 May 2026

The latest release includes agent security patches, fixes for report policy upgrades, and SSO team API assignment.

Improvements

  • .NET 8 security patches in scanner/AV agent: Updated the .NET 8 SDK to the latest version to include Microsoft’s newest security patches in the internal scanner/AV agent, keeping your agents protected against recently disclosed .NET vulnerabilities.

Resolved issues

  • User-edited report policy sections preserved on upgrade: Your customizations to CWE values and vulnerability template sections in report policies are no longer overwritten during version upgrades, so you don’t lose tuning work each time you upgrade.
  • Team assignment via member invitation API: The /members/newinvitation endpoint now applies and returns the Teams field for SSO-only users, matching the UI and the /members/new endpoint.
1 2 … 18