Skip to content

2026.09


Features & Enhancements

Network Pivoting

  • External tests now provide Network Pivoting options, enabling expansion beyond the test's originally configured scope to include additional hosts discovered during the operation. Pivot-based findings are called out on the test’s Summary tab, Impacts tab, and attack graph.

Integrations and Workflow Updates

  • The ServiceNow VR integration now offers additional name and dns_domain fields for more-reliable interoperation between systems.
  • Integration Settings now supports search, filtering, and sorting across tabs, with expanded Activity Log filtering and graceful handling of unexpected connector types.
  • Integration Settings now includes a detail page for Activity Log rows, while retaining legacy settings.

Attack Configuration Enhancements

  • Password Spray configuration now includes rate-limiting options to set Attempts per User and Spray Window (in hours). You can also now disable or rate-limit the Domain User option.
  • MS SQL Local User default credentials are now moved to Password Spray, where you can disable or rate-limit the option to reduce the risk of account lockouts.
  • You can now disable the AWS Credential Pivot option to reduce attack surface.
  • You can now disable the SSL Vulnerability Check option.
  • Post Exploitation options now include toggles to enable/disable Golden Ticket Attack and Domain Credential Dumping.

WebApp Pentest

  • WebApp credentials configuration now supports custom fields for applications that require additional login inputs.
  • Injected-credential usernames now accept the @ symbol, enabling email-format usernames.
  • Auto-injected web application credentials now support secrets longer than 110 characters.
  • The WebApp credentials panel now warns when the assigned Runner does not support long credentials, and prevents new credentials from being added until the Runner is updated.
  • The Runners API (Application Programming Interface) now supports filtering for Runners that handle large credentials.
  • WebApp configuration now respects account-level and client-level read-only states.
  • The WebApp configuration form now includes alternate URLs in the testing-rules host selector.
  • WebApp configuration now opens automatically after a custom application is designated.
  • The WebApp pentest is now included in the schedule modal when creating or reviewing scheduled operations.
  • WebApp operations and credential mutations now display a reason when a read-only state prevents the action.

Identity and Active Directory

  • Azure test types are now named Entra ID for additional clarity.
  • NodeZero now verifies Active Directory credentials using the full UPN (User Principal Name) instead of only the SAM (Security Account Manager) account name or email local-part.

External Pentest and Asset Discovery

  • NodeZero can now attempt subdomain takeover of dangling CNAME (Canonical Name) targets without authorizing the targets for additional attacks.
  • Elasticsearch scanning no longer silently skips HTTPS (Hypertext Transfer Protocol Secure) targets because of certificate verification.
  • Added fingerprints for self-hosted Git servers.

Rapid Response

  • Added filter chips to the Rapid Response advisories table.
  • Rapid Response notification and summary cards are now ordered by urgency.
  • Rapid Response Test Summary now distinguishes assets successfully tested by NodeZero from assets that were unreachable.
  • The Rapid Response Advisories table now presents a single Risk Assessment instead of a list of asset exposure levels.
  • The Rapid Response Advisories table now uses the Horizon3 Updated column to show the most pertinent Horizon3 actions.

Portal & Reporting

  • Real-Time View > Artifacts and Activity > Artifacts tabs now support CSV export.
  • The Portal now confirms before the Intelligent Scope toggle clears values already entered.
  • The domains table now includes richer scope information.

New Attack Content

  • PaperCut MF and NG – CVE-2026-81578, CVE-2026-82078. Added coverage for an access-control flaw that can let unauthenticated users modify system settings, and unsafe dynamic class loading that can execute Java code when driver settings are manipulated.
  • GeoTools and GeoServer – CVE-2023-25158, CVE-2026-76904. Added coverage for SQL injection in OGC (Open Geospatial Consortium) filter processing with JDBCDataStore and PostGIS data stores.
  • Oracle E-Business Suite Payables – CVE-2026-70700. Added a safe reachability check for an unauthenticated vulnerability that can cause a denial of service.
  • Oracle E-Business Suite iSupplier Portal – CVE-2026-70777, CVE-2026-70779. Added coverage for unauthenticated access to sensitive data and unauthorized data modification.
  • Microsoft SharePoint – CVE-2026-50522, CVE-2026-58644, CVE-2026-55040, CVE-2026-63520. Added coverage for two deserialization remote code execution (RCE) vulnerabilities, a security-feature bypass, and an input-validation RCE vulnerability.
  • Sangoma Switchvox SMB Edition – CVE-2026-9586. Added coverage for unauthenticated SQL injection through the /pa endpoint that can lead to remote code execution.
  • JFrog Artifactory – CVE-2026-82329. Added coverage for an authentication weakness that can grant unauthenticated attackers administrator privileges.
  • Ubiquiti UniFi Protect – CVE-2026-77537. Added coverage for command injection that can let a network-reachable attacker execute commands on the host device.
  • Oracle E-Business Suite Marketing Administration – CVE-2025-53072, CVE-2025-62481. Added coverage for vulnerabilities that can let an unauthenticated attacker compromise Oracle Marketing over HTTP.
  • N-able N-central – CVE-2026-86218. Added coverage for unauthenticated remote code execution in versions before 2026.3.1.14.
  • GitLab CE/EE Repository Commits API – CVE-2026-85706. Added coverage for unauthenticated arbitrary file reads caused by path traversal.
  • MikroTik RouterOS – CVE-2026-67279, CVE-2026-86060. Added coverage for SSH (Secure Shell) authentication and argument-handling flaws that can be chained for privilege escalation.
  • Oracle WebLogic Server – CVE-2022-21371. Added coverage for unauthenticated access to sensitive server data, along with checks for exposed WEB-INF configuration.
  • Cisco Catalyst SD-WAN Manager – CVE-2026-76504. Added coverage for an unauthenticated API authentication bypass.
  • Citrix NetScaler ADC and Gateway – CVE-2026-88771. Added coverage for unauthenticated remote code execution caused by improper input validation.
  • Grandstream GXP16xx – CVE-2026-2329. Added coverage for an unauthenticated stack-based buffer overflow in the HTTP API that can lead to remote code execution.

Platform Performance & Stability

  • Improved scan performance and reliability by limiting connections to a single port per host, reducing network strain on fragile systems.

Bug Fixes

  • Fixed the WebApp test form to use the standard attack-flags component and correctly filter Large Language Model (LLM) group flags.
  • Corrected route counts on the sunburst chart, Arc Stats, WebApp executive summary, and Insights to consistently agree by properly excluding out-of-scope and non-testable routes.
  • Fixed External Attack scope behavior to prevent automatic authorization of domain-only IP addresses.
  • Corrected discovery-junction seeding and pause behavior on reruns for external operations.
  • Fixed an Active Directory Agent failure that occurred when a domain controller's SYSVOL was unreadable.

Federal

Users of NodeZero Federal might experience a 1–2 week delay in the availability of some features, Attack Content, or bug fixes.