Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

March 2026

  1. Exploit for Remote Code Execution in SolarView Compact (CVE-2022-29303)

    Copy link to “Exploit for Remote Code Execution in SolarView Compact (CVE-2022-29303)”

    Sniper now supports exploitation of CVE-2022-29303 (SolarView Compact), with Network Scanner detection included.

    Why it matters

    SolarView Compact devices are common in industrial and OT environments. A compromised device makes a useful pivot point into broader network infrastructure.

    How to use

    Detect with the Network Scanner → prove exploitability in Sniper → document the finding for remediation prioritization.

  2. AI-enhanced authentication inside the Website Scanner

    Copy link to “AI-enhanced authentication inside the Website Scanner”

    The Website Scanner's Automatic and Recorded authentication methods now use AI as a fallback when standard login detection fails. On complex or dynamic pages, the AI layer kicks in and completes the login reliably. It only intervenes when the current method can't.

    What's in it for you:

    • Fewer failed scans on modern web apps with non-standard login flows

    • No configuration changes needed

    • More consistent scan coverage across authenticated areas of your targets

  3. Tests performed by a scan are now visible in results

    Copy link to “Tests performed by a scan are now visible in results”

    Scan results now show the tests that ran during a scan, grouped by port. Previously, this information surfaced as Informational findings which added noise. That distinction is now clear.

    Why this matters:

    • Easier to verify scan coverage at a glance

    • Cleaner reports, as findings are now presented separately from tests

    • Helps with scope verification and compliance documentation

  4. Exploit for Remote Code Execution in HPE OneView (CVE-2025-37164)

    Copy link to “Exploit for Remote Code Execution in HPE OneView (CVE-2025-37164)”

    Sniper: Auto-Exploiter now includes an exploit for CVE-2025-37164 (HPE OneView), paired with Network Scanner detection.

    Why it matters

    This unauthenticated RCE compromises the controls that govern an entire datacenter, not just a single host. A successful exploit here has a wide blast radius.

    How to use

    Detect with the Network Scanner → confirm exploitability in Sniper → use the evidence to fast-track remediation sign-off.

  5. Exploit for Remote Code Execution in MeteoBridge (CVE-2025-4008)

    Copy link to “Exploit for Remote Code Execution in MeteoBridge (CVE-2025-4008)”

    We added an exclusive exploit for CVE-2025-4008 (MeteoBridge) into Sniper and paired it with Network Scanner detection.

    Why it matters

    This RCE gives you root-level access on a device most teams don't monitor or patch. MeteoBridge devices often sit quietly on internal segments, making them easy pivot points.

    How to use

    Detect with the Network Scanner → validate the risk with a one-click proof-of-concept in Sniper → check for forensic traces of exploitation to assist your post-compromise hunting.

  6. We've rolled out the Model Context Protocol (MCP) server. Connect it to Claude, Cursor, VS Code, Gemini CLI, or any MCP-compatible client and run scans, manage targets, retrieve findings, and generate reports through plain-language prompts.

    Use this to:

    • Cut context-switching during investigations

    • Kick off scans by describing a target in natural language, no UI required

    • Connect your AI workflows to real-time pentest data from your account

    Every tool call requires your explicit approval before it runs. Strict JSON-Schema validation keeps execution more predictable.

    👉 Read the MCP documentation 👈

February 2026

  1. Pentest-Tools.com is ISO/IEC 27001:2022 certified

    Copy link to “Pentest-Tools.com is ISO/IEC 27001:2022 certified”

    We protect your findings with the same rigor we use to find them.

    This certification validates that your data is governed by a continuously reviewed system of security controls covering access management, risk assessment, incident response, physical security, and asset management.

    For your team, this means audited, third-party proof of our security practices, helping reduce friction during vendor reviews and procurement assessments.

    👉 See our certification 👈

  2. Detection & exploit validation for Ivanti EPMM RCE (CVE-2026-1281)

    Copy link to “Detection & exploit validation for Ivanti EPMM RCE (CVE-2026-1281)”

    We added detection for CVE-2026-1281 (Ivanti Endpoint Manager Mobile RCE) into the Network Vulnerability Scanner and paired it with exploit validation in Sniper.

    Why it matters

    Unauthenticated. Remote. Full server compromise.

    CVE-2026-1281 allows attackers to execute arbitrary commands on exposed Ivanti EPMM servers without credentials. Public reporting confirms active exploitation, and proof-of-concept code is available.

    Because EPMM servers often integrate with identity systems and manage mobile fleets, compromise can provide attackers with a direct path into enterprise infrastructure.

    How to use

    Detect exposed Ivanti EPMM instances with the Network Scanner → validate exploitability with controlled proof-of-concept execution in Sniper → re-scan after patching to confirm remediation

  3. Authentication Bypass in GNU Inetutils Telnetd (CVE-2026-24061)

    Copy link to “Authentication Bypass in GNU Inetutils Telnetd (CVE-2026-24061)”

    We added an exclusive exploit for CVE-2026-24061 (GNU Inetutils Telnetd) into Sniper and paired it with Network Scanner detection, available exclusively to Pentest-Tools.com customers.

    Why it matters

    This critical authentication bypass (CVSS 9.8) lets unauthenticated attackers gain immediate root access via a malicious USER environment variable. With over 200,000 instances exposed globally, it is a high-impact target for mass exploitation against legacy and embedded systems.

    How to use

    Detect with the Network Scanner → validate the risk with a one-click proof-of-concept in Sniper → check for forensic traces of exploitation to assist your post-compromise hunting.

  4. New detection for Redis CVE-2025-62507

    Copy link to “New detection for Redis CVE-2025-62507”

    The Network Vulnerability Scanner now detects CVE-2025-62507, a remote code execution vulnerability affecting Redis.

    This check helps identify Redis instances that may be exposed to this vulnerability, particularly in internet-facing deployments or misconfigured internal environments.

    Why this matters:

    • Identify Redis servers vulnerable to remote code execution

    • Detect exposed or improperly configured Redis deployments

    • Prioritize remediation for systems reachable from external networks

    • Add coverage for Redis environments in continuous network scanning

    If you run Redis in production or development environments, this detection helps you quickly assess potential exposure.

    👉 Know your Redis exposure

  5. Deeper visibility into findings, directly in scan logs

    Copy link to “Deeper visibility into findings, directly in scan logs”

    The Website Scanner and API Scanner already display findings while the scan runs. Scan logs now also record the exact moment when a new finding is added directly in the console output.

    This provides a more granular, step-by-step view of discovery as the scan progresses.

    Scan log new finding

    Why this matters:

    • See the precise moment a vulnerability is identified during longer scans

    • Correlate findings with specific scan phases or payloads

    • Troubleshoot unexpected behavior with additional context

    • Gain better traceability in API-driven or automated workflows

    For teams running continuous or automated testing, this adds clearer operational insight during the scan itself, not only after it finishes.

January 2026

  1. Allow filtering /scans API requests by tool

    Copy link to “Allow filtering /scans API requests by tool”

    You can now filter scan results by tool ID when calling the GET /scans endpoint.

    This update allows you to combine tool and start_time filters to return only the scans you care about, making it easier to work with large scan histories and automate downstream workflows.

    Use this to:
    • Build tool-specific dashboards
    • Generate targeted reports
    • Reduce post-processing in API consumers

    👉 See the updated API documentation 👈

  2. Surface more request smuggling issues with fewer false positives

    Copy link to “Surface more request smuggling issues with fewer false positives”

    We’ve improved the detection accuracy of active detectors in the Website Vulnerability Scanner to surface more real issues with less noise.

    This update adds coverage for:
    • CSRF bypass via POST/PUT to GET conversion
    • Insecure CORS configurations caused by subdomain trust
    • Serialized object detection in JSON payloads to flag potential deserialization risks

    These improvements help reduce false positives and provide clearer signals during validation and triage.

  3. Exploit for WordPress SMTP Plugin account takeover (CVE-2025-11833)

    Copy link to “Exploit for WordPress SMTP Plugin account takeover (CVE-2025-11833)”

    Sniper now includes an exploit module for CVE-2025-11833, an account takeover vulnerability in the WordPress SMTP Plugin.

    This allows you to validate impact directly by demonstrating account takeover when the vulnerability is present, helping turn detection into clear, actionable evidence.

December 2025

  1. The Network Scanner is ready to detect CVE-2025-14847 - MongoBleed

    Copy link to “The Network Scanner is ready to detect CVE-2025-14847 - MongoBleed”

    🫤 We know the last thing you want to deal with on Dec 31st is a new vulnerability. But MongoBleed (CVE-2025-14847) isn't waiting for the ball to drop.

    Our team already updated the Pentest-Tools.com Network Scanner to detect this information disclosure flaw that's currently letting unauthenticated attackers leak MongoDB server info.

    Whether you’re on-call or just checking in, we’ve made it fast to see if your servers are at risk. 🎯 Scan your IPs for CVE-2025-14847, patch it fast, and have a safe New Year!

    👉 Get the CVE details 👈

  2. You helped us make 2025 our most accurate year yet!

    Copy link to “You helped us make 2025 our most accurate year yet!”

    If you spent part of this year juggling “just one more scan,” one more CVE, and one more person asking “so… are we actually exposed?”, you’re not alone.

    Security work kept getting broader, louder, and more accountable - and the hardest part often wasn’t finding issues, but making sense of them fast enough to act.

    That’s the lens for our 2025 year in review: what your day-to-day looked like when scanning became routine, and when “more findings” stopped helping.

    Before we dive into 2026, here is a look at what we achieved together over the last 12 months.

    👉 Read the full 2025 review 👈

  3. Exclusive exploit for React2Shell (CVE-2025-55182)

    Copy link to “Exclusive exploit for React2Shell (CVE-2025-55182)”

    We’ve just added an exclusive exploit for CVE-2025-55182 (React2Shell) into Sniper and paired it with Network Scanner detection - available exclusively to Pentest-Tools.com customers.

    Why it matters

    React2Shell is a critical, unauthenticated, remote code execution (RCE) vector—prime for mass exploitation given the ubiquity of Next.js and React. This release gives you fast detection and zero-guesswork validation in one place.

    How to use

    Detect with the Network Scanner → validate in Sniper → re-scan to confirm remediation and rule out residual exposure across multiple assets.

    Exclusive exploit for React2Shell - detect & validate CVE-2025-55182
  4. Exploit for CVE-2025-64446 & CVE-2025-58034 (Fortinet FortiWeb)

    Copy link to “Exploit for CVE-2025-64446 & CVE-2025-58034 (Fortinet FortiWeb)”

    We’ve just added an exclusive exploit for CVE-2025-64446 & CVE-2025-58034 (Fortinet FortiWeb) into Sniper and paired it with Network Scanner detection - available exclusively to Pentest-Tools.com customers.

    Why it matters

    Fortinet FortiWeb is a critical authentication bypass and remote code execution (RCE) vector, allowing remote unauthenticated attackers to fully compromise the FortiWeb server and steal confidential information, install ransomware, or pivot to the internal network.

    How to use

    Detect with the Network Scanner → validate in Sniper → re-scan to confirm remediation and rule out residual exposure across multiple assets.

November 2025

  1. Findings page is now taking port into account for grouping

    Copy link to “Findings page is now taking port into account for grouping”

    We’ve improved the Findings experience: grouping now takes the port into account. If the same issue is detected on the same target but on different ports, you’ll see separate entries, so nothing gets merged away by accident.

    Why it matters
    In real environments, the same vulnerability can show up on multiple exposed services. For example, a misconfiguration on :80 and :8080, or the same TLS issue on several HTTPS ports. Previously, grouping by target + finding could collapse these into one row, which made reporting and remediation tracking messier. With port-aware grouping, each affected service keeps its own finding, evidence, status, and notes, giving you cleaner remediation workflows and more accurate reports.

    How to use

    Run your scans as usual → open Findings → filter or group duplicates if you want a compact view → edit, verify, or export each port-specific finding separately → re-scan after fixes to confirm every exposed port is clean.