Invicti Enterprise on-demand release notes
RSS feedThis document highlights the new features, improvements, and fixed issues introduced in Invicti Enterprise on-demand across recent releases. Each update focuses on enhancing usability, security coverage, and integration capabilities for security teams.
2026
This section summarizes all releases, features, improvements, and fixes for 2026 as they're added.
Release v26.1.2 - Hot fix
Release date: 22 January 2026
Resolved issues
- Fixed SCIM endpoint timeouts caused by concurrent requests blocking indefinitely on resource locks
Release v26.1.1
Release date: 15 January 2026
Improvements
- Improved Maven chatbot
Release v26.1.0
Release date: 13 January 2026
This update includes changes to the internal agents. The internal scan agent’s current version is 26.1.0. The internal authentication verifier agent’s current version is 26.1.0.
New features
- Added a 1-year retention policy for Sitemap records
- Added Browser Network and Console logs to the verification log area
Improvements
- Added support for Fix Versions when creating Jira issues via integration. Multiple fix versions can now be assigned to a single issue. Supports mixed usage of name and id attributes such as
[{"name":"v1.2"},{"id":"10001"},{"name":"v1.0"}] - Chatbot pop-up now displays after redirection and persists until manually closed by the user
Resolved issues
- Fixed OAuth2 update issue regarding the use of 'secret'
- Updated the vulnerable libtiff6 package
- Fixed TempPath-dependent errors when the path contains whitespace
- Fixed next execution time recalculation for on-premises environments after scan is triggered
- Fixed InvictiProxy usage on Auth Verifiers
- Fixed incorrect redirect for More Information link on URL Rewrite Custom Mode
- Fixed OAuth2 3-legged Authorization code issue
- Fixed sitemap issue causing URLs with /#/ to be missing
- Fixed gRPC attack engine to use form values
- Fixed retest scan launch failure
- Fixed scan data archiving error
2025
This section summarizes all releases, features, improvements, and fixes for 2025 as they're added.
Release v25.12.0
Release date: 9 December 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.12.0. The internal authentication verifier agent’s current version is 25.12.0.
New features
- Enhanced REST API compliance by implementing proper PUT verb endpoints for 13 update operations (AgentGroups, AuthenticationProfiles, Discovery, Issues, Members, Notifications, Roles, ScanPolicies, ScanProfiles, Team, WebsiteGroups, Websites). Legacy POST endpoints remain fully supported for backward compatibility.
- Added support for retrieving OAuth2 credentials from secrets storage
Improvements
- Added agent type information to Queue Reason for improved clarity
- Added the
InterceptDocumentOnlysetting to the Scan policy section under the Browser tab for easier access - Limited all discovery settings entries to 100 lines to address performance issues and improve data retrieval efficiency
- Upgraded the underlying engine to
Chromium 137.0.7151.68, delivering critical security patches, improved stability, and better performance - Unified the Splunk Enterprise and Splunk Cloud add-ons into a single package for simplified deployment and maintenance. The legacy on-premises app is now deprecated, with full support for both platforms available in the consolidated add-on.
Resolved issues
- Proxy credentials are now properly masked in
InvictiProxylogs - Resolved API request errors that occurred when
UrlRewriteExcludedLinkswas added to a profile - Fixed a permissions issue where users without Edit Members permissions were unable to perform API Token Reset operations
- Resolved an issue where manually disabling an agent assigned to queued or active scans would cause those scans to become stuck indefinitely. The system now prevents disabling agents with assigned scans and displays clear error messages
- Fixed the
/api/1.0/agentgroups/listendpoint returning null for the Teams field when TeamAgentGroupAssignmentEnabled was enabled, ensuring team assignments for agent groups are properly retrieved - Corrected an issue where excluded cookies were incorrectly appearing in scan reports
- Fixed missing
Known issuesandCVE detailson the Scan Summary page - Resolved an issue that prevented large JSON files from being scanned properly during scan archiving
Release v25.11.2- Hot fix
Release date: 5 December 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.11.2. The internal authentication verifier agent’s current version is 25.11.2.
New security checks
- Implemented security checks for Next.js/React Server Components RCE:
Release v25.11.1- Hot fix
Release date: 20 November 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.11.1-hf. The internal authentication verifier agent’s current version is 25.11.1-hf.
Resolved issues
- Fixed an issue that was causing login failures during authenticated scans
Release v25.11.1
Release date: 19 November 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.11.1. The internal authentication verifier agent’s current version is 25.11.1.
New features
- Implemented Acunetix security checks into the report policy, aligning it with the existing functionality in Invicti Standard
Resolved issues
- Prevented scan fails due to syntax errors on custom security scripts
Release v25.11.0
Release date: 11 November 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.11.0. The internal authentication verifier agent’s current version is 25.11.0.
New features
- Added support for referencing secrets from SEM integrations when configuring Basic, Digest, NTLM/Kerberos, or Negotiate authentication
Improvements
- Added "Fix versions" field to the JIRA integration
- Added "Queue reason" to the Scan summary page
- Improved IP Restriction Logic
- Improved the "SameSite Cookie Not Implemented" security check
- Improved the "JWT Signature is not Verified" security check
Resolved issues
- Fixed a layout problem when adding a new certificate
- Fixed an issue showing wrong Vulnerability Database (VDB) version
- Fixed a cache cleaning issue
- Fixed an issue where users without an API Discovery license saw the error “ApiHub Service URL cannot be empty” when updating items on the Settings > General page
- Fixed "The deletion of the website continues" issue when adding a target
- Fixed an empty list issue in the Mend integration
- Fixed an issue where Linux/cloud agents couldn't parse secrets pre-request query parameters
- Updated Java sensor
- Fixed an issue with confirmation SMS messages
Release v25.10.1
Release date: 27 October 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.10.1.The internal authentication verifier agent’s current version is 25.10.1.
Improvements
- Updated .NET 8 runtime to fix a security issue (CVE-2025-55315)
Release v25.10.0
Release date: 14 October 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.10.0.The internal authentication verifier agent’s current version is 25.10.0.
New features
- Added WebLogic support for JAVA Shark sensor
- The Secrets screen now supports selecting and referencing secrets from SEM integrations in addition to manually entered
name–valuepairs. This allows for more secure and centralized secret management
Improvements
- Replaced old POST deletion methods with standard DELETE endpoints for a more consistent API. The POST endpoints are now deprecated - please update your integrations.
Resolved issues
- Corrected a typo in the Ivanti RCE CVE-2024-21887 report template
- Improved detection of CSP directives
- Resolved containerized Agents being stuck during auto-updates
- Fixed “Unable to Load Scan Session” and “Unable to Find Scan Files” errors
- Corrected discrepancies in Roles permission counts
- Enabled Agent auto-updater to use encrypted proxy credentials from appsettings.json
- Added RegEx validation to prevent invalid patterns causing scan failures
- Fixed Intel instance assignment issue for On-Prem Cloud Provider
Release v25.9.1
Release date: 23 September 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.9.1. The internal authentication verifier agent’s current version is 25.9.1.
New feature
- Introduced Global Client Certificates: Admins can now add client certificates to the Global Certificate section and apply them directly to Scan Profiles
Improvements
- Added “Export to CSV” functionality to several pages, including Scan Policies, Report Policies, Scan Profiles, Scheduled Scans, and Website Groups
- Updated GitHub Actions to their latest stable versions to take advantage of new features and performance improvements
Resolved issues
- Resolved an issue where clicking “Toggle Content” did not display the list of Imported Links on scan profiles
- Resolved an issue with parsing JIRA Custom Complex Fields in JSON
- Addressed SSL errors in certificate-based environments by adding support for the IgnoreSslCertificateErrors parameter
- Corrected an issue where NTLM "Test Credentials" incorrectly passed using default credentials; invalid credentials now fail as expected
- Resolved issues with previously problematic Report Policies
Release v25.9.0
Release date: 9 September 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.9.0. The internal authentication verifier agent’s current version is 25.9.0.
New feature
- Added a new setting, Page Top Warning Banner, under Settings > General > Warning Text Settings. This feature allows administrators to display a persistent, plain-text banner at the top of every page for compliance and informational purposes
Improvements
- Improved Pega version detection
- Improved page performance
- Updated the GitHub Actions plugin to address multiple security vulnerabilities by sanitizing user inputs, validating URLs, and remediating outdated dependencies to ensure compliance with secure coding standards
- Encrypted OAuth2 section in Scan Profile to maintain information security
- Updated GetTags endpoint for Asana integration
Resolved issues
- Resolved the inconsistency between the UI and reports in displaying known issue severity
- Resolved pagination issue on the Agent Group Index page
- Mend-related profiles have been hidden from the UI
- Updated the signature for Mend vulnerabilities to improve management of Mend-related issues. As a result, previously reported vulnerabilities will appear as resolved and then re-detected
- Fixed a UI filter bug where created websites could be incorrectly ignored on the Discovered Websites page
- Fixed authentication and simulation stucks due to script syntax
- Resolved zombie "Pick an app"(OpenWith.exe) processes that runs out resources on Windows servers
Release v25.8.1
Release date: 26 August 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.8.1. The internal authentication verifier agent’s current version is 25.8.1.
Improvements
- The character limit for the New Target/Target Group > Description field has been increased from 255 to 1000 characters. - -
- This change has also been implemented on the API side
- The character limit for the Scan Profile > Comments field has been increased from 500 to 1000 characters. This change has also been implemented on the API side
- Starting 1 September, 2025, HTTP Request/Response data for vulnerabilities older than 180 days is going to be removed (except for the most recent occurrence). Read more
Resolved issues
- Other users are prevented from editing the Primary User's account
- Fixed filtering Mend SAST results for Critical and High priority vulnerabilities
- Added file size control message for imported link or API definitions files
- Fixed Tag IDs field in Asana integration
Release v25.8.0
Release date: 12 August 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.8.0. The internal authentication verifier agent’s current version is 25.8.0.
New security checks
- Added detection of Pega Infinity as a technology in the Vulnerability Database (VDB)
Improvements
- Defined the Hawk check delay in the scanning policy
- Added configurable User and Group ObjectClass settings to LDAP integration, enabling custom values (for example userProxy for AD LDS), updating synchronization logic, ensuring compatibility with diverse LDAP servers, maintaining backward compatibility
- Added a Maximum Cookie Count setting to manage cookie numbers when necessary
- Updated Bootstrap component
- Updated Highlight component
- Added Affected Versions field for on-prem JIRA to custom fields
Resolved issues
- Added missing Technology icons
- Fixed logging in Post-Request scripts
- Implemented fix to ensure Post-Request script is triggered for all requests in the browser context
- Fixed SCIM activity logs duplicate issue
- Fixed an issue where importing link via API to Scan Profile did not generate URL Rewrite Rule
Release v25.7.1
Release date: 29 July 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.7.1. The internal authentication verifier agent’s current version is 25.7.1.
Improvements
- Improved visibility and transparency of customer impersonation scenarios initiated by the Support Team
- Extended the Notifications (New & Update) REST API endpoints to include report configuration options, allowing finer control over alerting workflows
- Improved stability by identifying and notifying users about misconfigured Jira webhooks causing excessive and unrelated requests to the scanner
- Added tag-based filtering support to the Scheduled Scans page. Users can now filter scheduled scans by tags
- Adding Imported Links via API now generates URL Rewrite Rules automatically
Resolved issues
- Fixed false-positive reporting for Web Cache Deception vulnerability
- Implemented immutable logs for deleted users to ensure audit integrity and traceability even after user removal
- Fixed an issue where scripts defined on the Custom Script page could not be executed for testing purposes
- Resolved an issue where SSL certificate chain errors blocked UI or auto-update of Internal Verifier Agents on Linux
Release v25.7.0 - Hot fix
Release date: 21 July 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.7.0. The internal authentication verifier agent’s current version is 25.7.0.
Improvements
- Minor security patch for Authentication Verifier Service
Release v25.7.0
Release date: 8 July 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.7.0. The internal authentication verifier agent’s current version is 25.7.0.
Security checks
- Added a new CVE check for CVE-2019-19326
- Added a new XSS attack for CVE-2024-11831
Improvements
- Improved prototype-pollution detection to reduce noise
- Improved XSS detection to reduce noise
- Increased the timeout duration for IAST responses to prevent premature failures
- Updated dependencies with known vulnerabilities
- Implemented an enhancement to capture the token information present in the response during the OAuth2 Implicit Flow
- Implemented an enhancement to enable more effective cookie management when HTTP/2 is enabled
- Updated plugin dependencies to address known security vulnerabilities and improve overall stability; upgraded Jenkins compatibility to version 2.474
- When user roles changes details are now available on Activity Logs
- Jenkins Plugin: Corrected misleading UI validation for the "Report Type" parameter within the "Netsparker Enterprise Scan" build step. The field no longer incorrectly appears as required, clarifying its optional nature
- LDAP Integration: Permanently enabled LDAP integration for on-premise WebApp installations by removing its associated feature flag. LDAP functionality is now available by default
- Shark (IAST) versions upgraded
- Agent and Verifier download names now come in a specific format
- Added new columns while exporting with All Attributes CSV
API changes
- Addresses discrepancies in global vulnerability counts between scan tasks and website issues
Resolved issues
- Corrected the MOVEit SQLi check to avoid reporting an incorrect version
- Enhanced support for using multiple secrets simultaneously within a single custom header
- Resolved an issue where duplicate X-Content-Type-Options headers triggered false missing header reports
- Addressed an issue encountered during report policy migration
- File Uploads: Added support for additional ZIP MIME types to resolve upload issues from some operating systems
- Fixed broken link issue
- Fixed integration duplication issue on Notification UI
- Fixed an issue where starting a new scan after a failed PCI scan could cause the PCI scan status to remain stuck in the "Stopping" state
Release v25.6.0
Release date: 18 June 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.6.0. The internal authentication verifier agent’s current version is 25.6.0.
Improvements
- Improved Stack Trace Disclosure (Java) detection pattern
- Added support for configuring the temp file via appsettings.json or an environment variable (Read more)
- Updated plugin dependencies to address known security vulnerabilities and improve overall stability; upgraded Jenkins compatibility to version 2.462
- Updated the Jenkins plugin script generation to use the latest GitHub Actions versions and ubuntu-latest runner for improved compatibility and security
- Updated
Microsoft.OpenApito version 2.0 preview to support OpenAPI 3.1.0 for improved API scanning - Added API GET method to retrieve scheduled scans by ID
Resolved issues
- Added an event notification name to the logs for email notifications
- Resolved an issue where multiple versions of Next.js were not properly displayed in the Technologies dashboard and Scan Reports
Release v25.5.1
Release date: 27 May 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.5.1. The internal authentication verifier agent’s current version is 25.5.1.
New features
- Added Post-Request script feature (Read more)
- Integrated AI Assist Bot intoInvicti Enterprise On-Demand
Security checks
- Added a new XSS Security check
Improvements
- Updated workflows to improve reliability and security while maintaining alignment with GitHub’s best practices
- Addressed multiple versions of GitHub Actions available in the marketplace
- Added new REST API endpoint (agents/listverifiers) to retrieve AV agents data
- Restricted the Vulnerability Note field to 1000 characters
Resolved issues
- Resolved an issue causing scans to get stuck during archiving
- Resolved discrepancy between API (listByWebsite) and UI (Recent Scans) results
- Fixed an issue with verifying the existence of links in the link pool
- Improved incremental scanning
- Implemented logic to create the UserDocumentsDirectoryPath when it doesn't already exist
- Added support for defining headers and HTTP method during CSV import
Release v25.5.0
Release date: 6 May 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.5.0. The internal authentication verifier agent’s current version is 25.5.0.
New features
- Implemented webapp for secure storage and retrieval of passwords for Pre-Request scripts
- Added an integration for NTA with NGINX (Read more)
Improvements
- Implemented default limit setting to 1000 without flag for all fields except Second Level Domains
- Implemented custom field Parent option in integration with Azure Boards
- Implemented agent for secure storage and retrieval of passwords for Pre-Request scripts
Resolved issues
- Fixed an issue with Bad Request Response on Scan Summary
- Fixed naming issues of WordPress plugin Contact Form 7
- Implemented possibility to keep the report history of PCI scans with exceptions defined
- Fixed the issue of LoginRequiredUrl and Pre-Request script requests causing bottlenecks in HTTP requests
- Fixed an issue that unnecessarily included the code parameter in OAuth2 authorization requests
- The scanning engine now correctly processes merged request headers received from browser
Release v25.4.1
Release date: 24 April 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.4.1. The internal authentication verifier agent’s current version is 25.4.1.
Resolved issues
- Resolved an issue on the Technologies Dashboard
- The 'Tags' filter in All Issues now works correctly when using the 'Not Contains' condition
- Resolved issue where no results appeared when filtering the target list on the Target Group page. This was linked to the 'View Target List' permission
- Resolved communication issues in the TestBasicAuthCredentials process and improved HTTP connection handling
- Resolved an issue where not all attributes were exported correctly from the Issues page
Release v25.4.0
Release date: 8 April 2025
This update includes changes to the internal agents. The internal scan agent’s current version is 25.4.0. The internal authentication verifier agent’s current version is 25.4.0.
New feature
- Added an option to prevent reopening Issue Tracker issues when a vulnerability is marked as False Positive and later revived (Read more).
Improvements
- Requests with empty or default values are not sent to DeepInfo
- Introduced a new setting under the Account General settings, within the Data Privacy and Security section, to modify the X-AMZ-Expires parameter while downloading the scan data
- Enhanced the "Configure New Agent" page to include additional details for auth verifier agents (Read more)
- Updated remediation details for outdated AngularJS versions
- [BREAKING CHANGE]: Updated the Docker agent's compression method and file extension; ensure any automation or scripts referencing the old format are updated accordingly.
Resolved issues
- Fixed an issue where the Issue note field could not be updated
- Fixed inefficient algorithmic complexity in DotNet IAST Sensor
- Resolved the issue where an invalid character response occurred when attempting to add a user
- Resolved the "Invalid Target URI" error that occurred when editing the Target URI to end with multiple slashes (///) on the new scan page
- Resolved the issue where the scan profile was not updating with the support account
- Fixed restrictions for JIRA integration
- Fixed an issue where pressing "Enter" instead of clicking the "Check" button during password verification triggered a full scan instead of the intended login verification
- Updated Chromium and Node.js versions, resolving Chromium-related issues, including the unexpected increase in Chromium count.
- Exclude URL rules now function correctly even when the excluded URL is the target
- Fixed an issue with retrieving OAuth2 token data from JSON responses
Release v25.3.1 - API Hub Hotfix
Release date: 3 April 2025
This update did not include changes to the internal agents.
Improvement
- Improved API Discovery of API specifications spread across multiple files in Mulesoft Anypoint Exchange