Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

September 2026

  1. 99 new detections added to the Network Scanner

    Copy link to “99 new detections added to the Network Scanner”

    The Network Scanner gained 99 new detections in September. As always, if Sniper can exploit it, the Network Scanner can detect it.

    Three examples, each with a CVSS v3 score of 10.0:

    • unauthenticated arbitrary file read in GitLab CE/EE (CVE-2026-85706)

    • remote code execution in Ruby on Rails Active Storage (CVE-2026-66066)

    • pre-authentication remote code execution in N-able N-central (CVE-2026-86218)

    Why it matters

    Coverage that lands within days of disclosure is the difference between finding an exposure yourself and reading about it in an incident report.

    How to use

    Run a scan to check your targets, then put the high-value ones on scheduled monitoring so new coverage applies automatically as it ships.

    Scan your targets

  2. We're consolidating tools for an easier setup

    Copy link to “We're consolidating tools for an easier setup”

    From October 20, 2026, the WAF Detector, the SSL/TLS Scanner, and the Kubernetes Scanner won't be available as standalone tools in the product interface anymore.

    The WAF Detector is folding into Website Recon, so you can run the same checks without the setup spread. We'll automatically migrate scheduled WAF Detector scans to Website Recon by November 17, 2026.

    SSL/TLS Scanner and Kubernetes Scanner are folding into the Network Scanner, so the same checks run in fewer places. We'll automatically migrate the scheduled scans to the Network Scanner by November 17, 2026.

  3. From October 6, 2026, the SharePoint Scanner, the Joomla Scanner, and the Subdomain Takeover won't be available as standalone tools in the product interface anymore.

    If you're currently using these tools, we suggest replacing them with the Network Scanner for both on-demand and scheduled scans.

    Scheduled and API-triggered scans keep running until November 17, 2026.

    Your past scans and reports stay in your account.

    Run a network scan →

  4. Sniper now exploits 13 new critical vulnerabilities

    Copy link to “Sniper now exploits 13 new critical vulnerabilities”

    The biggest drop of the month includes:

    The rest cover SonicWall and SonicWall GMS, 3 Joomla-related CVEs, and a few more.

    Why it matters

    Sniper turns a detection into proof of exploitation, so the conversation with the people who own the fix starts from evidence.

    Prove it with Sniper

  5. Ping is our AI assistant that guides customers and website visitors. When something's beyond what it can handle on its own, type "I want to talk to a human." Ping now automatically creates a support ticket and hands our team the full conversation, so you get the answers you need without the hassle.

  6. AI Pentests, powered by Specter, is now in the product

    Copy link to “AI Pentests, powered by Specter, is now in the product”

    AI Pentests combines AI with offensive security expertise in a way that holds up technically and fits real security workflows. Our autonomous web application pentesting capability is priced separately from the product you already use, and you can purchase it on demand.

    Specter, the autonomous pentesting engine behind it, has already found valid vulnerabilities in infrastructure that belongs to the U.S. Department of Defense, UK Ministry of Defence, and companies like Vodafone, Booking.com, and Sony.

    Some of the most secure organizations in the world deemed those findings important enough to acknowledge and fix. You can see the 16 public thanks so far on our HackerOne profile.

August 2026

  1. PATCH /findings can now update risk and the verified flag, not just status

    Copy link to “PATCH /findings can now update risk and the verified flag, not just status”

    The /findings PATCH endpoint used to only update a finding's status. It can now update risk and the verified flag as well.

    This closes a gap for teams managing findings through automation. A ticketing system or CI/CD pipeline can now adjust risk and mark a finding verified without a manual step in the product.

    See the API reference

    API security
  2. 155 new detections added to the Network Scanner, 70 of them critical

    Copy link to “155 new detections added to the Network Scanner, 70 of them critical”

    The Network Scanner gained 155 new detections in August, 70 of them critical, prioritized by CVSS, EPSS, and CISA KEV.

    The most notable:

    ◉ JetBrains TeamCity < 2026.1.3, 2025.11.7, remote code execution (CVE-2026-63077)

    ◉ Metabase, unauthenticated SQL injection (CVE-2026-72898)

    ◉ ForgeRock AM/OpenAM, remote code execution (CVE-2021-35464)

    ◉ Cisco ISE < 3.4P2, unauthenticated arbitrary file upload (CVE-2025-20282)

    Why it matters

    Coverage that lands within days of disclosure is the difference between finding an exposure yourself and reading about it in an incident report.

    How to use

    Run a scan to check your targets, then put the high-value ones on scheduled monitoring so new coverage applies automatically as it ships.

    Scan your targets

  3. Ping, our AI-based assistant is now present in the product, not just on the public website

    Copy link to “Ping, our AI-based assistant is now present in the product, not just on the public website”

    Ping is now part of the product and there to help whenever you have a question. Its current capabilities are limited to answering questions based on our documentation. For the moment, it cannot take actions on your behalf.

    Why it matters

    Getting unstuck used to mean leaving the product to search docs or wait on support. Now the answer is a question away, without a tab switch.

    How to use

    Look for Ping inside the product and ask it what you're trying to figure out.

  4. Findings now flag CISA's known ransomware campaign use via the API

    Copy link to “Findings now flag CISA's known ransomware campaign use via the API”

    Findings pulled through the API now carry a flag for CISA's known ransomware campaign use, separate from the general KEV tag.

    The new known_ransomware_campaign_use field sits alongside the existing in_cisa_catalog field on the finding object, both nullable booleans.

    Why it matters

    Not every KEV entry carries the same urgency. A finding tied to an active ransomware campaign is a different conversation with a stakeholder than one that's merely on the list, and now that distinction is available to any workflow that consumes the API.

    How to use
    See the API reference

    API security
  5. AI-enhanced authentication on Password Auditor

    Copy link to “AI-enhanced authentication on Password Auditor”

    When the login console can't be found on a complex or dynamic page, an AI agent now locates it so your password audits keep running instead of stalling out.

    Why it matters

    One complex or dynamic login page used to mean a skipped target or a manual workaround. Now the audit keeps moving on its own.

    How to use

    Run a Password Auditor scan as usual. The AI fallback engages automatically whenever it's needed.

    Run a Password Auditor scan

  6. New Pentest-Tools.com customers can choose to host their data in the United States or Europe at signup.

    Many teams need their data hosted in a specific region for compliance or internal policy reasons. Until now, every customer’s data was hosted in Europe by default. Existing customers stay hosted in Europe for now, we'll share more on hosting migration options in the upcoming weeks.

    Find out more

  7. Sniper adds an exploit for a Forgerock OpenAM RCE still active in the wild (CVE-2021-35464)

    Copy link to “Sniper adds an exploit for a Forgerock OpenAM RCE still active in the wild (CVE-2021-35464)”

    Sniper Auto-Exploiter added a new exploit module this month for CVE-2021-35464, a remote code execution vulnerability in Forgerock OpenAM.

    The CVE has been public for years, but it's still showing up in live environments, which makes it a good reminder that "old" and "settled" aren't the same thing. Detection is now live in the Network Scanner as well.

    Why it matters

    A five-year-old CVE still causing damage is exactly the kind of exposure that slips through when a scan schedule assumes older vulnerabilities are already handled. Sniper turns the finding into exploit-backed evidence instead of a CVSS score on a slide.

    How to use

    Run Sniper against a confirmed target to generate exploit-backed evidence. As always, if Sniper can exploit it, the Network Scanner can detect it.

    Prove it with Sniper

July 2026

  1. Detect wp2shell now! Check for CVE-2026-63030 & CVE-2026-60137 exposure or confirm patching.

    Copy link to “Detect wp2shell now! Check for CVE-2026-63030 & CVE-2026-60137 exposure or confirm patching.”

    Yesterday, it got two CVEs.

    Today, you have detection and exploitation - in one click.

    We’re talking about wp2shell, the Wordpress RCE chain that won’t let security and IT teams have a weekend.

    Let’s help you get back to yours as fast as possible. 

    How to confirm exposed - or patched - Wordpress targets

    ◉ Run a single-CVE scan for CVE-2026-63030 with the Network Scanner (which also covers CVE-2026-60137 - the SQL injection flaw that chains to give attackers RCE)

    OR

    ◉ Use Sniper Auto-Exploiter with the single-CVE scan option for both detection and exploitation covering both CVEs.

    AND

    ◉ Based on your scan results, either patch or confirm you're already on WP 6.8.6, 6.9.5, or 7.0.2.

    ◉ Re-scan to confirm remediation and rule out residual exposure across your other assets.

    Remember: updating your main install doesn't cover every WP instance you own. The attack surface view in your account expands your visibility, so you don’t stop at the site you remember exists.

    Why wp2shell calls for an emergency CVE response

    wp2shell chains a REST API batch-route confusion (CVE-2026-63030) with a pre-auth SQL injection (CVE-2026-60137) to reach remote code execution.

    It needs no login and no plugins, so a default WordPress install in the 6.9.0-6.9.4 or 7.0.0-7.0.1 range is enough to make it a target.

    It’s not in the CISA KEV catalog yet, and CVE-keyed inventories were slow to flag it, so version checks alone can leave you guessing.

    That is why our research team operationalized detection within a day of the July 17 patch, as part of our emergency CVE response.

    Now teams like yours can ✔ confirm exposure, ✔ patch, and ✔ verify the fix held before mass-exploitation tooling catches up.

    When someone inevitably asks you “does wp2shell impact our websites?”, you’ll already have the report.port.

    Log in to scan

June 2026

  1. API: the /scans endpoint now returns why a scan didn’t start

    Copy link to “API: the /scans endpoint now returns why a scan didn’t start”

    We added an info_text key to the /scans endpoint, so a scan that doesn’t start cleanly finally tells you why, straight from the API.

    This context was already visible inside the product but not exposed through the API. A customer asked for it, so now automated workflows can read the same explanation the UI shows, which makes failed scans easier to diagnose without opening the app.

    See the API reference

  2. 80 new detections added to the Network Scanner

    Copy link to “80 new detections added to the Network Scanner”

    The Network Scanner gained 80 new detections in June, prioritized by CVSS, EPSS, and CISA. The most notable this month:

    • Oracle PeopleSoft PSEMHUB, pre-auth Java deserialization RCE (CVE-2026-35273)

    • Palo Alto PAN-OS, authentication bypass (CVE-2026-0257)

    • Splunk Enterprise & Cloud, unrestricted file upload (CVE-2026-20253)

    • Joomla! JCE extension, unauthenticated RCE (CVE-2026-48907)

    • Ivanti Sentry, OS command injection (CVE-2026-10520)

    • LiteLLM, SQL injection (CVE-2026-42208) and command injection (CVE-2026-42271)

    • UniFi OS Server, command injection (CVE-2026-34910)

    • Check Point IKEv1 VPN, certificate authentication bypass (CVE-2026-50751)

    Why it matters

    Coverage that lands within days of disclosure is the difference between finding an exposure yourself and reading about it in an incident report. These are the issues attackers are already weighing, ranked so you can see what to prioritize first.

    How to use

    Run a scan to check your targets, then put the high-value ones on scheduled monitoring so new coverage applies automatically as it ships.

    Scan your targets

  3. Jira integration: credentials are checked before saving

    Copy link to “Jira integration: credentials are checked before saving”

    Jira integrations now test your credentials before saving them, so a typo gets caught up front instead of the first time you try to push a finding.

    A wrong token or a mistyped host used to sit quietly until a push failed mid-workflow. Now the integration briefly validates what you entered and tells you immediately if it won’t work, which cuts out a common source of broken integrations and support tickets.