Change log of the Cyberwatch software
15.8 (2026-06-18)
As of this release, group-based access management has been removed. Projects are now the only way to manage permissions, a feature introduced in version 14.7.
Highlighted features:
- AI: added the ability to configure custom MCP clients to make it easier to integrate tools compatible with the MCP server (preview)
- Details of an Asset: added a new tab displaying observed network connections to make asset communication analysis easier (preview)
- Discoveries: added Palo Alto Cortex XDR discovery for monitoring assets with Cortex XDR agents (preview)
New features:
- Asset rules: added an action to set an initial project for assets without a project
- API: added new routes to create, update, and retrieve discoveries
- Cloud: Oracle Cloud Infrastructure resources are now visible in the “Resources” tab
- Compliance:
- Added support for operating system families in custom compliance rules
- Added support for Windows CIS Benchmark rules using local variables from OVAL definitions
- Added SUSE Linux Enterprise Server 16 CIS Benchmark and updated several CIS Benchmarks, including Debian, macOS, Ubuntu, and Windows
- Dashboard: added a widget to track asset count over time
- Scanning engine: added in-depth analysis of Java archives to report embedded dependencies
- Scope:
- Added support for Cisco APIC and Cisco Unified Communications (CUCM, CUC) devices
- Added support for Citrix NetScaler Console and SDX devices
- Added support for F5 rSeries devices
- Added support for Meinberg LANTIME devices
- Added support for Nutanix Prism Element devices
Updated features and performance improvements:
- Details of an Asset: from the patch management tab, you can now change the vulnerability analysis status for the selected patches
- Discoveries:
- Fortinet discovery now also reports devices from all VDOMs configured on FortiGate
- Support for AWS GovCloud environments in EC2 discoveries
- MITRE ATT&CK: Cyberwatch now relies on attack techniques from version 19
- Projects: Cyberwatch now automatically restores the last global project filter used at each login
- Reports: optimized report processing and generation
- Scanning engine:
- Improved detection of already fixed vulnerabilities on Windows assets
- Improved detection of Go dependencies embedded in binaries
- Improved detection of Red Hat packages
- Improved vulnerability detection on SUSE and openSUSE systems
Bugfixes:
- Agentless connections:
- Fixed an issue with firmware detection for Cisco NX-OS devices over SNMP
- Fixed an issue with ForcePoint device detection over SNMP
- Details of an Asset: fixed an issue where comments were not saved in the modal used to change vulnerability analysis status
- Discoveries: fixed an issue that could interrupt GitLab Container Registry discoveries on SaaS instances
- Scanning engine:
- Fixed an inconsistency in the suggested patch version for Microsoft Office 2021
- Fixed an issue where the fixed version was reported incorrectly when analyzing applications on Linux assets
15.7 (2026-05-11)
Highlighted features:
- AI: improved performance and relevance of MCP queries on assets and vulnerabilities
- Compliance: added Oracle Cloud Infrastructure CIS Benchmark
- Network targets and websites: added screenshots to scan results to make analysis easier (preview)
New features:
- Dashboard: added a chart to show the distribution of vulnerabilities by status
- Compliance: added the ability to create declarative custom rules, extending compliance coverage to network devices and air-gapped assets
- Discoveries: added discovery for Cisco Meraki devices
- Docker images: globally installed NPM packages are now also detected
- Network targets and websites: added the ability to configure Nmap modules through scan policies
- Scope:
- Added end-of-life dates for Drupal and Ivanti Connect Secure
- Added security advisories from the Norwegian NSM and the UK NCSC
- Added support for Azure Data Studio, Centreon, Microsoft Defender Antivirus, Microsoft SQL Server 2025 and Ubuntu 26.04
Updated features and performance improvements:
- API:
- The
/api/v3/serversroute now also supports filtering by operating system family - Compliance rule and vulnerability routes now include comments
- The
- Discoveries:
- Docker images detected through the discovery of running images on Linux assets now also show their source assets
- Improved error handling for AWS discoveries
- Exports: comments are now included in CSV exports for compliance rules and vulnerabilities
- External tools: enhanced data sent through syslog with additional information related to vulnerability prioritization and exposure
- Scanning engine:
- Enhanced Python library detection by taking installation metadata into account
- Improved detection for Cisco NX-OS devices, Microsoft System Center Configuration Manager, and Red Hat (AUS, E4S support and more accurate technology identification)
- Updated vulnerability detection on Linux systems to reflect a change in package architecture handling
- Searches: more accurate results through improved filtering that takes search anchors into account (beginning and end of text)
Bugfixes:
- Agentless connections:
- Fixed an issue with firmware detection for OpenGear LightHouse devices over SNMP
- You can once again bulk edit saved credentials
- Alerts:
- Fixed an issue when editing alerts without filters
- Fixed an issue where the “Status” filter was not applied to security issues
- Compliance: fixed an issue with the time unit that could affect the evaluation of some Windows CIS rules
- Discoveries: fixed an issue where search filters in the side panel caused incomplete display of discovered assets
- Scanning engine:
- Fixed detection issues on Amazon Linux 2, Check Point, Oracle Linux and HPE Aruba devices
- Fixed a name-casing issue in malicious package detection
- Fixed an issue where already patched vulnerabilities were detected on Windows assets
15.6 (2026-03-30)
Highlighted features:
- Discoveries: added Oracle Cloud Infrastructure and Oracle Kubernetes Engine discoveries (preview) (preview)
- Kibana: user scope is now enforced: each user can only access assets from their own projects. Kibana access can be enabled in bulk from the interface. This feature requires orchestrator base version 5.30 or later
- Languages: the application is now available in Spanish
- Network targets and websites: redesigned the OWASP web application scanning engine. This engine improves overall performance and replaces the WSTG framework with the OWASP Top 10 2025 (preview)
- Reports: added the ability to generate a PDF information system coverage report for audits and regulatory compliance
- Vulnerability encyclopedia: added the MITRE D3FEND framework to complement ATT&CK, with matrices displayed in a tabbed view, to enhance analysis using associated defense techniques (preview)
New features:
- Scanning engine:
- Installed Windows drivers are reported in the list of technologies
- Python packages from virtual environments are also reported
- Scope:
- Added security advisories from the NCSC Ireland
- Added support for Arista devices
- Added support for VMware Cloud Director
- Added support for ZPE Systems Nodegrid Serial Console devices
Updated features and performance improvements:
- Agents: included the project in the names of MSI files
- AI: improved MCP server performance and analysis capabilities
- Authentication provider: you can now enable verification of IdP certificate expiration in SAML
- Cloud: the wizard also facilitates the creation of Microsoft Entra ID applications for Azure and Microsoft 365, simplifying integration with Cyberwatch
- Corrective actions: improved the Windows Package Manager support for updating third-party applications
- Customization: new settings to refine the CVEs included in alerts
- Details of a Vulnerability: the CSV export can be limited to selected assets
- Details of an Asset: improved management of vulnerability statuses during corrective actions
- Projects: analysis scripts can also be defined at the project level
- Repositories: performance improvements to optimize page load time
Bugfixes:
- Agentless connections: fixed a detection issue on Aruba devices in SNMP
- Alerts: fixed an issue that prevented alerts from being edited
- Docker images: fixed an issue that prevented some images from being scanned when added from the details page of an asset
- Prioritization policies: fixed an issue that prevented system administrators with limited project access from creating policies
- Projects: users associated with a single project can once again select their stored credentials
- Scanning engine:
- Fixed a detection issue on Veeam Backup & Replication
- Fixed an analysis problem on Microsoft Office
- Fixed an analysis problem on Mozilla Firefox
- Security issues: fixed inconsistent behavior when their status changes
15.5 (2026-02-23)
Highlighted features:
- AI: added a new MCP feature allowing artificial intelligence to interact with the application and automate specific actions
- Criticalities: renamed to “Prioritization policies” to better reflect its intended use (preview)
- Security issues: added detection of malicious software packages affecting assets, based on data from the OpenSSF repository (preview)
New features:
- Corrective actions: patch deployment for Snap applications is now supported
- Scope:
- Added security advisories from ABB
- Added security advisories from Nozomi Networks
- Added security advisories from SICK
- Added security advisories from the CNCS Portugal
- Added security advisories from the NCSC Netherlands
- Added security advisories from VARIoT
- Added support for SUSE Linux Enterprise Server 16.0
Updated features and performance improvements:
- API: updated documentation to clarify route access rights based on user roles
- Assets: declarative data for all assets can now be updated via air-gap import
- Authentication provider: enhanced project association through SAML user groups, including automatic linking of unknown projects based on name matching
- Benchmarks: the compliance benchmark configuration view has been moved to the “Administration” menu
- Cloud environment compliance: updated Microsoft 365 compliance rules for Exchange Online, Purview, OneDrive, SharePoint Online and Teams
- Compliance: improved implementation of some CIS Benchmark rules on Windows Server 2022 and 2025
- External tools: Syslog logs can now be sent over TCP with TLS encryption
- Network targets and websites:
- Improved consistency of scan results between normal and headless modes
- You can now select which Wapiti modules to run during scans
- Projects: prioritization policies can also be defined at the project level
- Vulnerabilities: functional and UI adjustments in preparation for the upcoming vulnerability tracking feature
Bugfixes:
- Network targets and websites: fixed error handling when a target is unavailable
15.4 (2026-01-26)
Highlighted features:
- Discoveries: you can now ignore a discovered asset (preview)
New features:
- Compliance: added and updated multiple CIS Benchmarks, including AlmaLinux 10, Debian 13, Oracle Linux 10, Red Hat Enterprise Linux 10 and Rocky Linux 10
- Discoveries: added UDP-based (SNMP) network discovery
- Scope:
- Added support for CloudLinux 10
- Added support for Fedora 43
- Added support for HPE Aruba Airwave devices
- Added support for IBM InfoSphere Information Server on Windows
- Added support for WALLIX Access Manager devices
Updated features and performance improvements:
- Activities:
- Improved user experience for activity visualization
- The search bar now includes a new time‑based filter for activity CSV export
- API:
- The
/api/v3/servers/{id}/exportroute now returns metadata, groups, and project when exporting an asset in SBOM SPDX or CycloneDX format - The
/api/v3/vulnerabilities/servers/{id}route now returns additional security‑issue payload details and corrective‑action titles for the asset - The ARN role can now be provided when creating or updating an AWS SSM agentless connection
- The
- Cloud environment compliance: implemented new Microsoft 365 compliance rules
- Compliance: updated the behavior and applicability of custom rules
- Discoveries:
- Execution timeout is now displayed in network or industrial safe queries discovery details
- IP addresses of assets identified during network discovery are now always displayed in the application, alongside the hostname when available
- Pod annotations and labels are now reported for Kubernetes discoveries
- Docker images: removed support for external runtime engines; all scans now run exclusively through the application’s native scanner
- Network targets and websites: additional URLs can now be specified for scanning
- Scanning engine: Snap applications are now supported on compatible Linux distributions
Bugfixes:
- Agentless connections: fixed detection issues for Check Point and Opengear devices via SNMP
- API: fixed an issue affecting compliance scans performed by security administrators
- Assets rules: fixed an issue preventing rule execution during asset creation in agentless connection
- Corrective actions: fixed the Windows package manager support for third-party application updates
- Discoveries: fixed an automatic asset registration issue for Proxmox discoveries
- Scanning engine: fixed Red Hat systems detection and analysis
15.3 (2025-12-15)
Highlighted features:
- Criticalities: you can now integrate European CERT catalogs into vulnerability prioritization (preview)
- Discoveries: added ServiceNow discovery (preview)
New features:
- Agentless connections: added support for HashiCorp Vault KV v2
- Air-gapped assets: you can now import PortSwigger Burp Suite XML vulnerability reports as air-gapped assets
- API: added a route for importing air-gapped assets
- Cloud environment compliance: added new Microsoft 365 compliance rules for multi-factor authentication
- Scope:
- Added support for Cisco Identity Services Engine devices
- Added support for Fortinet FortiWeb devices
- Added support for Microsoft Configuration Manager client on Windows
- Added support for Microsoft Office 2024
- Added support for MobaXterm on Windows
Updated features and performance improvements:
- Administration: refactored SMTP configuration form
- API: the
/api/v3/users/{id}route now returns the list of accessible projects for the user - Cloud: the wizard also offers the option to create Entra ID credentials for certificate-based authentication on Microsoft Azure or Microsoft 365
- Network targets and websites:
- Enhanced detection of various CMS systems
- Improved error management in case the target is unavailable
- You can create stored credentials for the target from the creation form
- Compliance:
- A security administrator can now ignore compliance rules
- Updated multiple CIS Benchmarks
- Harbor: you can disable the use of the proxy for image analysis
- Integrations: UX improvements on the creation form
- MITRE ATT&CK: Cyberwatch now relies on attack techniques from ATT&CK version 18
- Users: strengthened password complexity requirements
Bugfixes:
- Agentless connections: fixed the Fortinet FortiGate device detection
15.2 (2025-11-12)
New features:
- API:
- Compliance benchmark management is now possible
- Introduced routes for creating an API key and retrieving connected user key information
- Scope:
- Added support for Broadcom Brocade devices
- Added support for Fortinet FortiSwitch devices
- Added support for macOS 26
- Added support for Microsoft Visual C++ Redistributable
- Added support for Oracle Linux 10
- Added support for SBC Mediant Audiocodes devices
- Added support for Ubuntu 25.10
Updated features and performance improvements:
- API: implemented new routes for full compliance repository management
- Cloud: improved cloud resource loading performance
- Discoveries: you can now define scan timing for network discoveries
- Integrations: you can now retrieve technologies affected by a CVE
- Network targets and websites: improved detection of various CMS systems
- Projects: a system administrator with limited access can now download analysis scripts for adding air gap assets
- Repositories: you can now add a description to a repository
- Vulnerability and security issues encyclopedia: the search bar includes new time-based filters
Bugfixes:
- Authentication provider: fixed a problem with project association through SAML user groups
- Users: fixed an issue preventing the time zone defined in the profile from being applied correctly
15.1 (2025-10-06)
Highlighted features:
- Discoveries: Certificate Transparency discovery now offers a new option to search for neighboring organizations (preview)
New features:
- API: added a route to retrieve compliance repository information
- Compliance: added CIS Azure Kubernetes Service (AKS) Benchmark
- Details of an Asset: you can sort by date in the patch management history
- Discoveries: added a Rancher discovery
- Scope:
- Added support for OPNsense devices
- Added support for Trend Micro Deep Security Agent on Windows
Updated features and performance improvements:
- Cloud: CloudFormation template now ensures EKS compliance across all discovered clusters
- Compliance: CERTFR_AD analysis now takes into account sub-organizational units for domain controllers
- Projects:
- A system administrator with limited access can now manage deployment and restart policies of their accessible projects
- A system administrator with limited access can now manage scan policies of their accessible projects
Bugfixes:
- Cloud environment compliance:
- Cloud EKS assets will now have AWS as the operating system
- Fixed the script of CIS-Microsoft365-2.1.7 rule
15.0 (2025-09-29)
This version is a major release.
Highlighted features:
- Assets: add velocity indicators to track response times to vulnerabilities based on defined objectives (preview)
- UX: selecting a CVE, corrective action, security issue, compliance rule, or discovery from the list or the details of an Asset opens a side panel displaying the corresponding detailed information (preview) (preview)
- Projects: multiple improvements, including project-stored credentials, now offering system administrators with limited access the ability to add assets for all application scan modes
- UX: project activation in context is now more visible in the application (preview)
- Details of an Asset: added a map visualization of an asset and its relationships (preview)
- Cloud: support for integration with CloudFormation, to simplify the addition of your AWS environments to Cyberwatch and gain enhanced visibility across all your resources (preview)
New features:
- API: all users can now access the API
- Authentication provider: you can set a time limit before users are deactivated or deleted
- Compliance: added CIS Amazon Elastic Kubernetes Service (EKS) Benchmark
- Docker images: you can now scan Podman containers on Linux assets
- Discoveries:
- Added AWS Organizations discoveries
- Added Microsoft Hyper-V discoveries
- Kibana: added a new dashboard dedicated to priority vulnerabilities
- Network targets and websites: pages scanned during a target scan are now displayed on the Web pages tab of the details of an Asset
- Scope:
- Added security advisories from Veeam Backup & Replication
- Added support for Amazon SSM Agent on Windows
- Added support for Debian 13
- Added support for Erlang OTP
- Added support for ManageEngine ADSelfService Plus
- Added support for Rocky Linux 10
Updated features and performance improvements:
- Agentless mode connection: the SNMP device detection feature has been refactored
- API: the
/api/v3/servers/{id}/cve_announcements/{cve_code}route also allows you to set a reactivation date for a vulnerability - Cloud: UX improvements to the assistant to facilitate the use of discovery and compliance features
- Compliance:
- Updated multiple CIS Benchmarks
- You can define project-specific compliance repositories, allowing system administrators with limited access to manage the compliance of their assets
- Discoveries:
- A system administrator with limited access can now create discoveries
- Amazon ECR discoveries now rely on the AWS API
- AWS discoveries are renamed to Amazon EC2
- DNS and Certificate Transparency discoveries now rely on Nmap
- Docker images:
- Failed analyses are automatically relaunched
- Support for images with UIDs and GIDs greater than 60000
- External tools: you can specify the body format of Syslog requests
- Vulnerability encyclopedia: extension of CVE catalogs to authorities other than CERT-FR ALE and CISA KEV
- MITRE ATT&CK: Cyberwatch now relies on attack techniques from ATT&CK version 17
- Scanning engine: improved the IBM AIX equipment analysis
- Scope: improved the Veritas Netbackup support
- Stored credentials: improved endpoint support for Amazon ECR registries
Bugfixes:
- Corrective actions: fixed the Windows Package Manager support to update third-party applications
- Compliance:
- Fixed the script of Microsoft Windows Server 2022 CIS Benchmarks rules
- Fixed the script of rule ICS-LIN-6.6.9
- Discoveries:
- Fixed an IP address retrieval problem for Proxmox discoveries
- Fixed an issue with uniqueness in group relationships that occurred when automatically adding groups to their associated assets in synchronization mode
14.8 (2025-06-23)
New features:
- Scope:
- Added security advisories from the BSI Germany
- Added security advisories from the CERT Centre for Cybersecurity Belgium
- Added security advisories from the CERT INCIBE Spain
- Added security advisories from the ENISA EUVD
- Added security advisories from the EU CSIRTs Network
- Added security alerts and advisories from the CERT Austria
- Added support for AlmaLinux 10
- Added support for Broadcom RabbitMQ Server
- Added support for Red Hat 10
Updated features and performance improvements:
- Agentless mode connection:
- The boot date of SNMP devices is now reported
- The SHA-512 authentication on SNMP devices is now supported
- API: modified some PUT routes to PATCH in Swagger/OpenAPI documentation
- Integrations: technologies without associated CVEs are now taken into account in corrective action integrations
- Kibana: the vulnerability modification dates are now referenced in the
cve_computersindex - UX: you can now sort by project in the assets management views
Bugfixes:
- Alerts: fixed an issue with item retrieval in compliance rule alerts
- Compliance: fixed the script of rule ICS-WIN-5.1
14.7 (2025-05-14)
Highlighted features:
- Administration: introduction of a new project-based management system to distribute assets according to your organization’s specific requirements, while making administration and control of associated rights easier (preview) (preview) (preview)
New features:
- Authentication provider: added an option to deny connection requests from new SAML or OpenID Connect users
- Compliance: added CIS Windows Server 2025 Benchmark
- Scope:
- Added support for Fedora 42
- Added support for HPE Aruba Networking EdgeConnect devices
- Added support for Microsoft Visual Studio
- Added support for Puppet Agent on Windows
- Added support for Ubuntu 25.04
Updated features and performance improvements:
- Agentless mode connection: improved the IP address detection for SNMP devices
- Agents: the installation interface now allows you to create or select an API key for adding agents
- Authentication provider: you can configure a parameter for the OpenID Connect authentication assurance level (ACR)
- Cloud: the wizard includes new options, such as the ability to automatically create an Amazon Elastic Kubernetes Service (EKS) or Azure Kubernetes Service (AKS) discovery when a cloud asset is added
- Cloud environment compliance: implemented and updated compliance rules for Microsoft Azure and Microsoft 365
- Corrective actions: improved the Windows Package Manager support to update third-party applications
- External tools: a log is now sent to the Syslog server when a vulnerability is fixed on an asset
- Stored credentials: you can authenticate using a certificate on Microsoft Entra ID
Bugfixes:
- Agentless mode connection: fixed a detection issue on Extreme Networks devices in SNMP
- Discoveries: fixed a problem with the registration of Docker images discovered during an Amazon Elastic Kubernetes Service (EKS) discovery
- Docker images: fixed an operating system detection problem in Docker images when scanning with the application’s native scanner
- Scanning engine: fixed a detection issue on Alpine Linux
14.6 (2025-04-07)
Highlighted features:
- Cloud: introduced a wizard to facilitate the use of Discoveries and Compliance features (preview)
- Cloud environment compliance: added Microsoft 365 compliance rules (preview)
- Corrective actions: added the Windows Package Manager support to update third-party applications (preview)
- Criticalities: integrated EPSS Version 4 into the vulnerability prioritization method called “3D prioritization”
Updated features and performance improvements:
- API: the
/api/v3/cve_announcementsroute now also retrieves the vulnerabilities referenced in the CISA KEV and CERT-FR ALE catalogs - Authentication provider: improved user experience for creating and configuring OpenID Connect or SAML providers, including an auto-suggestion function to assist in filling out attributes
- Cloud environment compliance: implemented new Google Cloud Platform compliance rules
- Discoveries: you can now report only powered-on virtual machines during a VMware vSphere discovery
- Exports: technology installation paths are now included in the patches list CSV exports
- External tools: improved error management in case the Syslog server is down
- Kibana: custom comments on a vulnerability are now referenced in the
cve_announcementsindex - Network targets and websites: implemented scan support for Ivanti and Palo Alto Networks network devices
- Performance: further global performance improvements for the application
- Scanning engine: improved analysis of Microsoft SQL Server applications
Bugfixes:
- Cloud environment compliance: fixed a migration issue related to updating compliance rules
- Corrective actions: you can once again deploy patches from the corrective actions page
- Ignoring policies: you can once again remove keywords when editing an ignoring policy
- Kibana: fixed an issue that could prevent security issues from being sent to Kibana
- Scanning engine: fixed detection issues on Palo Alto Networks devices