Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

June 2026

  1. Pentest-Tools.com is available on Azure - Microsoft Marketplace

    Copy link to “Pentest-Tools.com is available on Azure - Microsoft Marketplace”

    You can now subscribe to Pentest-Tools.com directly through your Azure account. 

    All plans — NetSec, WebNetSec, and Pentest Suite — are available as transactable subscriptions, which means you can apply your existing Azure balance toward your subscription.

    Authentication uses Microsoft Entra ID (SSO), so setup takes a few minutes.

    The VPN Agent for internal network scanning is deployed as an Azure VM in your environment.

    For teams spending 10+ hours a week re-triaging alerts, now you can get confirmed findings with attached proof of exposure, directly through your Azure budget.

    Get started now.

  2. XSS Exploiter: fetch-based payload delivery

    Copy link to “XSS Exploiter: fetch-based payload delivery”

    The XSS Exploiter now offers two payload delivery options: the classic script tag (default), or fetch plus eval.

    Some targets strip or block inline script tags. With fetch plus eval as an alternative delivery path, you can adapt to how the target actually behaves and confirm exploitability where a script tag alone would fall short.

    Try the XSS Exploiter

  3. AI where it earns its place in the Website Scanner and URL Fuzzer

    Copy link to “AI where it earns its place in the Website Scanner and URL Fuzzer”

    We added AI to the Website Scanner and URL Fuzzer in the exact spots where deterministic logic used to give up. Three enhancements shipped:

    • AI-assisted authentication: when authentication fails to identify a login form the usual way, an AI fallback steps in to find it, so complex login flows stop cutting scans short.

    • Flowmapper: an AI agent explores your site like a real user, filling forms and following flows to reach endpoints the regular spider misses, then adds them to the scan.

    • ML Classifier: filters out fake “not found” pages that return a 200 status, so the admin console, sensitive file, and information disclosure checks report real findings instead of error pages in disguise. The URL Fuzzer runs the same classifier, so its results list only the files and directories that actually exist.

    Why it matters

    Fewer false positives and fewer missed endpoints, without manual tuning. The AI handles the judgment calls that used to break scans or bury real findings in noise.

    How to use

    Everything is on by default. You can disable any or all of it under My account, then AI.

    See it live

  4. Two phpBB authentication vulnerabilities our research team discovered (CVE-2026-48611 & CVE-2026-48612)

    Copy link to “Two phpBB authentication vulnerabilities our research team discovered (CVE-2026-48611 & CVE-2026-48612)”

    Our offensive security research team found two authentication flaws in phpBB, one of the most widely deployed forum platforms on the web. Detection for CVE-2026-48611 is now live in the Network Scanner, and a working proof of concept for each is published in the research.

    CVE-2026-48611 is a critical, unauthenticated authentication bypass (CVSS 9.4). One HTTP request with a target username and a wrong password phpBB never checks returns a valid session cookie for that account, admins included. It works on every default install up to and including phpBB 3.3.16, with no prior access needed. The vulnerable code path sat in the codebase for over a decade, surviving multiple major releases and security reviews.

    CVE-2026-48612 is a high-severity OAuth account takeover (CVSS 8.3). It chains two OAuth defects for a silent takeover on boards with OAuth configured. In some cases the victim doesn’t click anything: an image tag embedded in a forum post is enough to trigger it.

    Why it matters

    A bypass that hands an attacker an admin session on a default install means full control of the board, its users, and whatever sits behind it. phpBB runs on countless community and corporate forums, so a single exposed instance is a foothold with real blast radius. We reported both to phpBB on June 4, 2026, and a fix shipped two days later in phpBB 3.3.17.

    How to use

    Detect CVE-2026-48611 with the Network Scanner, patch to phpBB 3.3.17, then re-scan to confirm the fix is in place and rule out residual exposure across multiple assets.

    If the board has OAuth configured, audit the oauth_accounts table for unexpected entries after upgrading. A successful CVE-2026-48612 exploit leaves a record there.

    Read the research

May 2026

  1. Network Scanner now detects NGINX Rift (CVE-2026-42945)

    Copy link to “Network Scanner now detects NGINX Rift (CVE-2026-42945)”

    A critical, unauthenticated, remote code execution vulnerability in NGINX.

    Why it matters

    RCE on an unpatched NGINX instance is a short trip to a very bad day. NGINX sits everywhere it counts: reverse proxies, load balancers, and front-line web servers, so a single exposed instance can hand an attacker a foothold into the systems behind it. Our detection is evidence-based: confirmation comes from the server's actual response, not a banner check.

    How to use

    Detect with the Network Scanner → validate the risk with a one-click proof-of-concept in Sniper → re-scan to confirm remediation and rule out residual exposure across multiple assets.

    You're a quick scan away from being the one who finds it, not the one who gets the call at 2am because someone else did.

    👉 Scan for CVE-2026-42945 👈

    As always, if Sniper can exploit it, our Network Scanner can detect it.

  2. Findings page is now dramatically faster

    Copy link to “Findings page is now dramatically faster”

    If you manage large accounts, you've felt the wait. Loading a Findings page packed with hundreds of thousands of results meant watching a spinner long enough to lose your train of thought.

    We've added a composite index to the findings table, and the difference is hard to overstate.

    Why it matters

    On accounts with over 900K findings, load times dropped from 17–43 seconds to 300–600 milliseconds. On the largest accounts, over 4 million findings, that's a fall from up to 111 seconds down to about 1.4 seconds. Faster pages mean faster triage, and faster triage means you spend your time on the findings that matter instead of waiting to see them.

    How to use

    The improvement is automatic. No configuration, no setup. The next time you log in, open the Findings page and put it to the test.

    👉 Go to the Findings page 👈

  3. CVE-2026-41940: cPanel & WHM authentication bypass detection

    Copy link to “CVE-2026-41940: cPanel & WHM authentication bypass detection”

    CVE-2026-41940 is a CVSS 9.8 authentication bypass in cPanel & WHM, added to CISA's Known Exploited Vulnerabilities catalog and actively exploited in the wild for 64 days before any patch or advisory existed. No credentials. No user interaction. Full server access.

    The Network Vulnerability Scanner detects it by sending a crafted CRLF payload to the login endpoint and assessing exploitability from the actual server response. Version banners won't tell you if your target is genuinely at risk. This will.

    IT Security Guru covered the scanner release during active exploitation. If your targets were internet-accessible between February 23 and April 28 without port restrictions, treat them as compromised until confirmed otherwise.

    Scan for CVE-2026-41940

April 2026

  1. XSS Exploiter: callback IP address and request headers

    Copy link to “XSS Exploiter: callback IP address and request headers”

    Two new data points are now visible on every XSS Exploiter callback:

    • IP address: see exactly which IP the callback came from. Confirms whether it originated from the target's browser, a bot, or an unintended third party.

    • Request headers: now visible alongside cookies, page content, screenshots, and keystrokes. Session tokens, authentication cookies, and custom app headers, all at callback time.

    Both surface directly in tool results. Two common validation gaps, closed without leaving the product.

    Use it to see callbacks

  2. Private key detection in Website Scanner

    Copy link to “Private key detection in Website Scanner”

    The Website Scanner now detects private keys exposed in HTTP responses. The check runs passively - no configuration required, no extra setup.

    RSA, EC, and other common formats are included. If a private key is leaking from your target, this surfaces it. An attacker with that key has full access to whatever server infrastructure it belongs to. These findings get missed in manual testing because the response looks like noise until you look closely.

    Useful for external pentests and internal security reviews of web application infrastructure.

    Run a web scan

  3. You can now export the full list of scheduled scans configured across your workspaces. Each row includes scan name, target, frequency, last run time, and workspace.

    One file. Every workspace. Ready to hand to an auditor or drop into compliance documentation where recurring scans are a control requirement.

    This one came from a feature request. Thanks for flagging it.

    Export your scheduled scans

  4. Filter /findings output by risk level via API

    Copy link to “Filter /findings output by risk level via API”

    The /findings endpoint now accepts min-risk-level and max-risk-level parameters. Use either or both:

    • min-risk-level: returns findings at or above the specified level (e.g. high and critical only)

    • max-risk-level: returns findings at or below the specified level (e.g. medium and below)

    • Combine both to retrieve a specific range (e.g. medium only)

    Automation pipelines no longer need to pull everything and filter client-side. Payload size drops for integrations feeding SIEMs, ticketing systems, or reporting tools. Pairs with existing /findings filters for more precise data retrieval.

    Read the API docs

  5. Offensive Security Research Hub: the full FuelCMS stack

    Copy link to “Offensive Security Research Hub: the full FuelCMS stack”

    Seven CVEs. One CMS. A chain that reaches unauthenticated RCE at CVSS 9.8 if you pull the right two.

    • PTT-2025-025 / CVE-2026-30455: unauthenticated account takeover via email array. The entry point for the highest-severity chain.

    • PTT-2025-026 / CVE-2026-30456: authenticated RCE via Dwoo template escape. Chained with 025, this reaches CVSS 9.8 unauthenticated.

    • PTT-2025-027 / CVE-2026-30457: improper authorization on Blocks. Widens the access surface post-authentication.

    • PTT-2025-028 / CVE-2026-30461: authenticated RCE via git submodules. A second RCE path, independent of 026.

    • PTT-2025-029 / CVE-2026-30459: password reset poisoning via Host header. Opens a second account takeover path and delivers the token that 030 needs.

    • PTT-2025-030 / CVE-2026-30460: SQL injection via password reset token. Needs a valid token — 025 and 029 both hand you one.

    • PTT-2025-031 / CVE-2026-30462: sensitive file read via path traversal. Reads .php files as www-data. The readable file is database.php.

    FuelCMS v1.5.2. Master branch hasn't moved in roughly four years. Vendor notified.

    Research by Matei "Mal" Bădănoiu and Raul Bledea.

    Read the full writeups

  6. Got questions about scan coverage, authentication workflows, reporting, or anything else on the platform? Bring them to a live session with Jan, our channel account manager. He answers in real time and covers whatever's on your mind.

    Sessions run on Zoom. We announce registration links via email, LinkedIn, and on the website. Can't make it live? All past sessions are recorded and available to watch at any time.

    Watch replays

  7. How we use AI in Pentest-Tools.com (and why)

    Copy link to “How we use AI in Pentest-Tools.com (and why)”

    Most AI claims in security tooling are vague by design. This isn't that.

    We think like attackers, which means we question assumptions before we build on them, including assumptions about where AI actually helps in a penetration testing workflow. This page explains exactly where AI fits into the platform, what it does, and why we made those calls.

    No hype. Just the reasoning.

    See how we use AI

  8. CVE-2026-40321 is a stored XSS in DNN Platform that chains into RCE via SVG upload. The payload travels through the application's own internal messaging system. The admin sees an image file. The backdoor is already running.

    Matei "Mal" Bădănoiu published the research. Cybernews covered it the same day. That's what sharp attack chain documentation looks like.

    Read the original research

  9. Automation works best when it earns its place in a workflow. This resource shows exactly where Pentest-Tools.com fits in a real engagement, not as a replacement for manual testing, but as the part that handles what doesn't need your full attention.

    Watch our teammates run through actual penetration testing workflows, with commentary on when to lean on automation and when to go hands-on.

    See how it works IRL

  10. False positives waste time you don't have. Getting scan results your team can act on without spending half the engagement triaging noise takes deliberate engineering choices, and deliberate workflow ones.

    This overview covers the configuration and workflow options that give you the most control over scan precision, built around how the team here actually thinks about accuracy.

    See how we cut FPs

March 2026

  1. Two new API endpoints let you retrieve the tests performed during a scan or the tests that triggered a specific finding: /scans/{id}/tests and /findings/{id}/tests.

    Use this to:

    • Pull granular scan coverage data into your own tooling or SIEM

    • Link findings to the exact test that detected them, programmatically

    • Support automation pipelines that need full scan test data

    👉 See the API documentation 👈

  2. Exploit for Remote Code Execution in Hikvision IP camera/NVR (CVE-2021-36260)

    Copy link to “Exploit for Remote Code Execution in Hikvision IP camera/NVR (CVE-2021-36260)”

    We added an exploit for CVE-2021-36260 (Hikvision IP camera/NVR) to Sniper, paired with Network Scanner detection.

    Why it matters

    Hikvision is one of the most widely deployed camera vendors globally, including in corporate physical security systems. These devices typically sit on the same network segments as everything else.

    How to use

    Detect with the Network Scanner → validate the risk in Sniper → use the proof to prioritize remediation.