2026.09¶
Features & Enhancements¶
Network Pivoting¶
- External tests now provide Network Pivoting options, enabling expansion beyond the test's originally configured scope to include additional hosts discovered during the operation. Pivot-based findings are called out on the test’s Summary tab, Impacts tab, and attack graph.
Integrations and Workflow Updates¶
- The ServiceNow VR integration now offers additional
nameanddns_domainfields for more-reliable interoperation between systems. - Integration Settings now supports search, filtering, and sorting across tabs, with expanded Activity Log filtering and graceful handling of unexpected connector types.
- Integration Settings now includes a detail page for Activity Log rows, while retaining legacy settings.
Attack Configuration Enhancements¶
- Password Spray configuration now includes rate-limiting options to set Attempts per User and Spray Window (in hours). You can also now disable or rate-limit the Domain User option.
- MS SQL Local User default credentials are now moved to Password Spray, where you can disable or rate-limit the option to reduce the risk of account lockouts.
- You can now disable the AWS Credential Pivot option to reduce attack surface.
- You can now disable the SSL Vulnerability Check option.
- Post Exploitation options now include toggles to enable/disable Golden Ticket Attack and Domain Credential Dumping.
WebApp Pentest¶
- WebApp credentials configuration now supports custom fields for applications that require additional login inputs.
- Injected-credential usernames now accept the
@symbol, enabling email-format usernames. - Auto-injected web application credentials now support secrets longer than 110 characters.
- The WebApp credentials panel now warns when the assigned Runner does not support long credentials, and prevents new credentials from being added until the Runner is updated.
- The Runners API (Application Programming Interface) now supports filtering for Runners that handle large credentials.
- WebApp configuration now respects account-level and client-level read-only states.
- The WebApp configuration form now includes alternate URLs in the testing-rules host selector.
- WebApp configuration now opens automatically after a custom application is designated.
- The WebApp pentest is now included in the schedule modal when creating or reviewing scheduled operations.
- WebApp operations and credential mutations now display a reason when a read-only state prevents the action.
Identity and Active Directory¶
- Azure test types are now named Entra ID for additional clarity.
- NodeZero now verifies Active Directory credentials using the full UPN (User Principal Name) instead of only the SAM (Security Account Manager) account name or email local-part.
External Pentest and Asset Discovery¶
- NodeZero can now attempt subdomain takeover of dangling CNAME (Canonical Name) targets without authorizing the targets for additional attacks.
- Elasticsearch scanning no longer silently skips HTTPS (Hypertext Transfer Protocol Secure) targets because of certificate verification.
- Added fingerprints for self-hosted Git servers.
Rapid Response¶
- Added filter chips to the Rapid Response advisories table.
- Rapid Response notification and summary cards are now ordered by urgency.
- Rapid Response Test Summary now distinguishes assets successfully tested by NodeZero from assets that were unreachable.
- The Rapid Response Advisories table now presents a single Risk Assessment instead of a list of asset exposure levels.
- The Rapid Response Advisories table now uses the Horizon3 Updated column to show the most pertinent Horizon3 actions.
Portal & Reporting¶
- Real-Time View > Artifacts and Activity > Artifacts tabs now support CSV export.
- The Portal now confirms before the Intelligent Scope toggle clears values already entered.
- The domains table now includes richer scope information.
New Attack Content¶
- PaperCut MF and NG – CVE-2026-81578, CVE-2026-82078. Added coverage for an access-control flaw that can let unauthenticated users modify system settings, and unsafe dynamic class loading that can execute Java code when driver settings are manipulated.
- GeoTools and GeoServer – CVE-2023-25158, CVE-2026-76904. Added coverage for SQL injection in OGC (Open Geospatial Consortium) filter processing with JDBCDataStore and PostGIS data stores.
- Oracle E-Business Suite Payables – CVE-2026-70700. Added a safe reachability check for an unauthenticated vulnerability that can cause a denial of service.
- Oracle E-Business Suite iSupplier Portal – CVE-2026-70777, CVE-2026-70779. Added coverage for unauthenticated access to sensitive data and unauthorized data modification.
- Microsoft SharePoint – CVE-2026-50522, CVE-2026-58644, CVE-2026-55040, CVE-2026-63520. Added coverage for two deserialization remote code execution (RCE) vulnerabilities, a security-feature bypass, and an input-validation RCE vulnerability.
- Sangoma Switchvox SMB Edition – CVE-2026-9586. Added coverage for unauthenticated SQL injection through the
/paendpoint that can lead to remote code execution. - JFrog Artifactory – CVE-2026-82329. Added coverage for an authentication weakness that can grant unauthenticated attackers administrator privileges.
- Ubiquiti UniFi Protect – CVE-2026-77537. Added coverage for command injection that can let a network-reachable attacker execute commands on the host device.
- Oracle E-Business Suite Marketing Administration – CVE-2025-53072, CVE-2025-62481. Added coverage for vulnerabilities that can let an unauthenticated attacker compromise Oracle Marketing over HTTP.
- N-able N-central – CVE-2026-86218. Added coverage for unauthenticated remote code execution in versions before 2026.3.1.14.
- GitLab CE/EE Repository Commits API – CVE-2026-85706. Added coverage for unauthenticated arbitrary file reads caused by path traversal.
- MikroTik RouterOS – CVE-2026-67279, CVE-2026-86060. Added coverage for SSH (Secure Shell) authentication and argument-handling flaws that can be chained for privilege escalation.
- Oracle WebLogic Server – CVE-2022-21371. Added coverage for unauthenticated access to sensitive server data, along with checks for exposed
WEB-INFconfiguration. - Cisco Catalyst SD-WAN Manager – CVE-2026-76504. Added coverage for an unauthenticated API authentication bypass.
- Citrix NetScaler ADC and Gateway – CVE-2026-88771. Added coverage for unauthenticated remote code execution caused by improper input validation.
- Grandstream GXP16xx – CVE-2026-2329. Added coverage for an unauthenticated stack-based buffer overflow in the HTTP API that can lead to remote code execution.
Platform Performance & Stability¶
- Improved scan performance and reliability by limiting connections to a single port per host, reducing network strain on fragile systems.
Bug Fixes¶
- Fixed the WebApp test form to use the standard attack-flags component and correctly filter Large Language Model (LLM) group flags.
- Corrected route counts on the sunburst chart, Arc Stats, WebApp executive summary, and Insights to consistently agree by properly excluding out-of-scope and non-testable routes.
- Fixed External Attack scope behavior to prevent automatic authorization of domain-only IP addresses.
- Corrected discovery-junction seeding and pause behavior on reruns for external operations.
- Fixed an Active Directory Agent failure that occurred when a domain controller's SYSVOL was unreadable.
Federal
Users of NodeZero Federal might experience a 1–2 week delay in the availability of some features, Attack Content, or bug fixes.