# UpGuard release notes

Learn about new features, changes, and improvements to UpGuard.

2026

[September ](#2026-09)[August ](#2026-08)[July ](#2026-07)[June ](#2026-06)[May ](#2026-05)[April ](/releases.md?page=2#2026-04)[March ](/releases.md?page=2#2026-03)[February ](/releases.md?page=2#2026-02)[January](/releases.md?page=2#2026-01)

Previous releases

[2025 ](/releases.md?page=2#2025-12)[2024 ](/releases.md?page=4#2024-12)[2023 ](/releases.md?page=6#2023-12)[2022 ](/releases.md?page=9#2022-12)[2021 ](/releases.md?page=12#2021-12)[2020 ](/releases.md?page=15#2020-12)[2019](/releases.md?page=17#2019-12)

September 2026

## [Threat Posture: an executive view of external threat activity](/releases/threat-posture-an-executive-view-of-external-threat-activity)

Mark Barber September 22, 2026

Threat Monitoring no longer stops at the individual threat. When a scan and analysis completes, the Security Advisor reads across every triaged signal in Threat Monitoring and produces a Threat Posture brief: a short, executive-ready read on what the activity around an organization adds up to.

The Threat Analyst works signal by signal. The Security Advisor works one level up, surfacing the patterns behind the noise. Each insight follows the same structure: the pattern observed, why it matters, what it implies about the organization’s controls, and what leadership should prioritize. Recommendations are pitched at leadership priorities rather than individual remediation tasks.

The Threat Posture brief appears on the Threat Monitoring feed page and refreshes weekly. Insights are filterable, and each traces back to its underlying threats, so every statement presented to executives links to the evidence behind it.

### Faster threat closure in Threat Monitoring

Every threat card and threat details page now has a Manage threat button with the same options in the same order, replacing the three-dot menu. Two options have clearer names: No action needed replaces Risk Accepted for threats that do not warrant work, with an optional note, and False match replaces False positive for findings incorrectly attributed to the organization. Exposed credential threats close with a single quick action, and the confirmation message includes an undo option.

### Sanctions and geopolitical risks now affect security ratings

UpGuard’s Sanctions and Geopolitical Risks have had their provisional status removed, meaning they now contribute to both Breach Risk and Vendor Risk customers’ security rating. For more information see [Geopolitical Risks](https://help.upguard.com/en/geopolitical-risks).

### Vendor search matches any part of the name or domains

Vendor Risk users can now search both monitored and unmonitored vendors by any part of a vendor’s name or domain. For example searching ‘soft’ will bring up ‘Microsoft’.

### Attack surface check timeline in the Security Profile

Attack surface checks will now show a timeline of user actions that affect the check such as remediation requests and waiving risks. The timeline for both attack surface and evidence checks also show when notes are added or deleted and when documents are selected or deselected.

### Adding applications to User Risk before browser detection

User Risk administrators can now add an application to their app list and set a usage policy for it before the browser extension detects it. For more information see [User Risk: Adding Apps Manually](https://help.upguard.com/en/user-risk-adding-apps-manually).

## [Brand impersonation detection across mobile app stores](/releases/brand-impersonation-detection-across-mobile-app-stores)

Mark Barber September 9, 2026

Mobile app stores are a favorite venue for brand abuse. A convincing lookalike app can sit in a public storefront, carry an organization’s name and branding, and reach its customers directly, without touching any of its infrastructure. Threat Monitoring now scans the Apple App Store and Google Play Store for apps that reference a monitored domain or brand term. Scanning covers the app name, developer name, description, and listing metadata. The AI Analyst automatically dismisses listings it identifies as official. Security teams review only the listings it flags as potential brand impersonation.

### Threat Monitoring filtering by event, detection, or alert date

Threat Monitoring users can now choose which date the filter applies to. A toggle above the date range dropdown switches between event date, detection date, and alert date. The selection carries through the rest of the view: chart grouping and the date label on each threat result card both update to match, and the chosen date field is used in exports.

### NIST SP 800-171 Rev. 3 in the Security Profile

Vendor Risk users can now select NIST SP 800-171 Rev. 3 in the Security Profile to assess vendors against. Our control library maps directly to all 97 requirements, so assessing against NIST SP 800-171 runs on the same core checks used across all other frameworks in the Security Profile. This framework sets the security requirements for protecting Controlled Unclassified Information (CUI) across US federal and defense supply chains.

### Browser extension branding for User Risk

User Risk admins can now customize the User Risk browser extension to reflect their organization. Admins can set a theme, a company logo, an accent color, and a display name so users see extension nudges, blocks, and other messages branded to their organization instead of UpGuard’s default.

### Other improvements

* Vendor Risk users can now select multiple additional evidence documents and archive, delete, or download them in a single action.
* Trust Exchange now captures the countersigner’s name when an NDA is countersigned and writes it into the signed NDA document.
* UpGuard now detects Gitea and its version on scanned sites, so vulnerabilities affecting a specific Gitea release appear in risk findings.
* UpGuard now detects two critical Gitea vulnerabilities on scanned hosts: CVE-2026-27771, an authentication bypass where the built-in container registry accepts an anonymous bearer token regardless of repository visibility, allowing unauthenticated attackers to enumerate and pull private container images; and CVE-2026-59774, an improper input validation vulnerability in the Org-mode markup renderer that allows unauthenticated attackers to read arbitrary files on the server.

August 2026

## [Clearer citations and timeline for Security Profile checks](/releases/clearer-citations-and-timeline-for-security-profile-checks)

Mark Barber August 26, 2026

The check drawer in Security Profile now opens as a whole page, showing which citations contribute to a pass or fail result and an explanation of why. Citations are now more easily excluded and restored giving users more control over the AI Security Profile scan results. A new timeline for evidence checks records every change to a check, including new citations, manual overrides, citation exclusions, and remediation requests, so users can audit the history of the check. The check drawer and citation updates are available now. The new timeline will be available from 27 August. For more information see [Work with Controls and Checks](https://help.upguard.com/en/work-with-controls-and-checks-).

### N-able N-central verified vulnerability detection

We now have improved product detection for N-able N-central. Customers with N-able N-central in their attack surface will now see the product in Breach Risk Detected Products. Breach Risk & Vendor Risk now also include verified vulnerability detection for N-able N-central across 9 CVEs, including CVE-2026-18577 and CVE-2026-18556, authentication bypass vulnerabilities exploited in the wild; CVE-2025-8875, an insecure deserialization vulnerability; and CVE-2025-8876, a command injection vulnerability.

### Other improvements

* Trust Center tabs now have direct URLs, allowing Trust Exchange users to easily share a single link directly to their security controls or subprocessor list with Trust Center viewers across both public and signed-in views.
* Importing security questionnaires is now significantly upgraded, delivering up to 10x faster processing to determine column mappings alongside smarter heading detection and enhanced accuracy for multi-sheet files and UpGuard exported workbooks.

## [Subprocessors in Trust Center](/releases/subprocessors-in-trust-center)

Mark Barber August 12, 2026

Trust Exchange users on the paid tier can now publish their subprocessor list directly on their Trust Center. Subprocessors are the third party vendors that handle customer data on their behalf, such as cloud hosting or payment processing. Prospects and customers can see this list without having to request it, which resolves a common compliance question early in every security review.

### General availability for new Trust Exchange and Vendor Risk APIs

Customers can now build against new stable, supported endpoints across Trust Exchange and Vendor Risk, as a set of public APIs moves to general availability. In Vendor Risk, the new APIs cover retrieving vendor classic assessment details, lists, and versions, adding and updating vendor contacts, adding questionnaire comments, and updating questionnaire status. Trust Exchange NDA and Trust Center access management APIs are also generally available, giving users a stable, supported interface to automate their NDA workflows and access management programmatically.

### NCA compliance badges on the Trust Center

Trust Exchange customers can now display National Cybersecurity Authority (NCA) compliance badges on their Trust Center for NCA ECC (Essential Cybersecurity Controls) and NCA DCC (Data Cybersecurity Controls). Visitors see which frameworks an organization meets without needing to request them. This matters to buyers in Saudi Arabia, where both frameworks are mandatory for government entities and critical infrastructure operators.

July 2026

## [Cloud and core infrastructure frameworks in Security Profile](/releases/cloud-and-core-infrastructure-frameworks-in-security-profile)

Mark Barber July 29, 2026

We’ve expanded the security profile template library to include templates for cloud service providers and core infrastructure providers. These map to the Cloud Security Alliance Cloud Controls Matrix (CCM), UK Cyber Essentials, the Center for Internet Security Critical Security Controls (CIS), and NIST Special Publication 800-53 Revision 5. Vendor Risk users can run AI assessments and gap analysis in Security Profile against these standards when reviewing SaaS, PaaS, IaaS, MSP, and data center vendors. For more information see [Control Templates](https://help.upguard.com/en/framework-templates).

### Remediation requests for Security Profile risks

Vendor Risk users can now request remediation for evidence risks in Security Profile directly from document citations, without sending a questionnaire. Vendors can share supporting evidence as part of the remediation process, and Vendor Risk users can manually mark risks as remediated based on their evidence and responses.

### Breach Risk detected products added to detected vendors in Vendor Risk

To help Vendor Risk users more easily surface and manage risk from unknown vendors, we now surface Breach Risk detected products in the Detected tab on the Vendors page. The Detected tab on the Vendors list now shows vendors detected by Breach Risk alongside those detected by User Risk (for Breach Risk and User Risk users respectively), and vendors can be monitored directly from the list.

### Automated suppression for inactive account credentials

Breach Risk Threat Monitoring can automatically suppress exposed credential detections for inactive or known-benign accounts, cutting down noise from reposted ULP and combolist data. Organizations can import, as well as manually curate, a list of known inactive accounts so future detections are triaged without manual dismissal.

### Detection for the wp2shell WordPress vulnerability chain

Breach Risk and Vendor Risk now detect WordPress installations affected by CVE-2026-60137, a SQL injection vulnerability and CVE-2026-63030, a REST API batch-route confusion vulnerability. Chained together they enable unauthenticated remote code execution, and both are listed in CISA’s Known Exploited Vulnerabilities catalog. Fixes are available in WordPress 7.0.2, 6.9.5, and 6.8.6.

### Other improvements

* Breach Risk and Vendor Risk now detect 13 additional high and critical severity CVEs in VMware vCenter Server: CVE-2024-38813, CVE-2024-38812, CVE-2024-37080, CVE-2024-37079, CVE-2024-22274, CVE-2023-34048, CVE-2023-20895, CVE-2023-20894, CVE-2023-20893, CVE-2022-31680, CVE-2022-22982, CVE-2022-22948, and CVE-2021-22049.
* Breach Risk and Vendor Risk now detect two medium severity CVEs in the Jetpack plugin for WordPress, CVE-2024-9926 and CVE-2021-24374.
* Vendor Risk and Breach Risk users can receive an email when a risk waiver is approved or declined and can turn the notification on or off for each product from notification settings.
* Threat Monitoring snippet and image downloads use descriptive filenames built from the post date, content type, source, author, and threat ID.
* UpGuard’s preset control templates in the Security Profile have been renamed with the prefix ‘UpGuard’ (for example ‘UpGuard Core’ instead of ‘Core controls’) to clearly differentiate our recommended templates from external framework templates.

## [Complete questionnaires without closing remediation](/releases/complete-questionnaires-without-closing-remediation)

Mark Barber July 15, 2026

Vendor Risk users can now mark a questionnaire complete while leaving its remediation requests open, giving you more granular status to improve tracking. We’ve added a new setting, Allow changes to completed questionnaires in remediation, giving you the flexibility to define whether vendors can update responses to remediate risks after completion.

### Search and filtering for Trust Center access management

Trust Center users can now search and filter the Access logs by name or email, eliminating the need to scroll through long lists. Additionally, denied access requests are now visible, allowing internal team members to track the access requests declined and when.

### IRAP badge for Trust Center

Trust Center now displays an IRAP badge, so organizations assessed under the Infosec Registered Assessors Program can show that status to visitors reviewing their security posture.

### Exclude Entra guest users from monitoring

User Risk users can now exclude Entra guest users from monitoring through the existing monitoring rules. After each scan or rule change, an audit event records which users were unmonitored.

### Multiple approved apps in the browser extension

When User Risk nudges or blocks an app in the browser extension, it now lists all approved alternatives in alphabetical order.

### Severity-first sorting for the Threat Monitoring queue

Breach Risk’s Threat Monitoring queue now sorts by severity by default, highest first (Critical to Low), so analysts see the most critical threats before the most recent. Within the same severity, threats fall back to newest first. Users can still change the sort manually.

## [Company name aliases for smarter detection](/releases/company-name-aliases-for-smarter-detection)

Mark Barber July 1, 2026

Company name Transforms now support AI-generated aliases. Each Transform suggests up to two aliases, helping identify legitimate company references while reducing false positives caused by short or ambiguous names. Customers can accept the suggested aliases or request alternatives.

### SharePoint vulnerability detection (CVE-2026-32201)

Breach Risk and Vendor Risk now include vulnerability detection for CVE-2026-32201, a remote network spoofing vulnerability with no available mitigation beyond patching. Customers with SharePoint in their attack surface will see this appear in Breach Risk, and Vendor Risk customers will now see this on their vendors where detection confirms exposure.

### Excel export for control templates

Vendor Risk administrators can now export any control template to Excel to share it for review when setting up Security Profile control templates. The file lists each check with its domain, control family, control, and the framework mappings selected for that template.

### Expiry reminders for shared resource access

Trust Exchange now emails users seven days before their access to shared vendor assets expires. Users can request an extension from the notification itself.

### App access automation workflows for User Risk

Security and IT teams can now automate app access requests and usage reviews in User Risk via Risk Automations. Users can request access to an app directly from the User Risk browser extension, and the automation notifies the admins via Microsoft Teams, Slack, or an ITSM ticket. Administrators can survey selected users about their app usage, sending each user a chat message or ticket through the same connected tools to inform app policy decisions.

### Detected vendors from app usage

For customers using both User Risk and Vendor Risk, a new Detected vendors tab in Vendor Risk surfaces the vendors behind approved apps that User Risk has detected in use but are not yet monitored. Security teams can quickly spot coverage gaps and decide which vendors to monitor.

### FortiBleed exposure detection

Breach Risk and Vendor Risk now flag assets affected by FortiBleed, a credential-exposure campaign targeting internet-facing Fortinet devices. The risk is raised when a customer’s own asset appears on the impacted list, or when a monitored vendor has an asset on it, giving teams fast visibility to prioritize validation and remediation. It is a temporary signal and stays active until 29 July 2026.

June 2026

## [FortiBleed Exposure Detection](/releases/fortibleed-exposure-detection)

Mark Barber June 25, 2026

We are introducing a temporary risk to respond to the FortiBleed incident. FortiBleed is a credential-exposure campaign affecting internet-facing Fortinet devices, where we believe attackers gained access through a mix of unpatched vulnerabilities and credential-stuffing techniques, then extracted device configuration data and used hashcracking techniques to break credentials into plaintext. Because this can indicate real compromise risk on affected infrastructure, we are adding a short-term detection signal that will remain active until 29 July 2026.

This change adds a new risk that can raise in both products: in Breach Risk, it raises when a customer’s own asset is on the impacted list; in Vendor Risk, it raises when a monitored vendor has an asset on that list. The signal is intended for fast visibility and triage so teams can prioritize validation and remediation on potentially impacted systems.

## [Updated application usage policy controls](/releases/updated-application-usage-policy-controls)

Mark Barber June 17, 2026

User Risk administrators can now set a policy on any application: approve it, block it, nudge users toward alternatives, or mark it as tolerated. Role, team, and individual user exceptions layer on top of a base policy, with no parallel rule sets to manage. For example, Social Media apps can be blocked for everyone while remaining approved for the Marketing team. Newly discovered apps inherit the organization’s default state automatically. For more information see [App Usage Policies](https://help.upguard.com/en/app-usage-policies).

### Safer web controls with User Risk

User Risk now gives administrators browser-level controls that govern what employees can do on a site, not just whether they can access it. Administrators can prevent employees from pasting or uploading sensitive data into shadow AI tools. Corporate sign-in can be enforced on approved apps. Predictable passwords are flagged before they’re set. For more information see [Browser Defense Policies](https://help.upguard.com/en/browser-defense-policies).

### Email notifications for expiring additional evidence

In addition to in-app notifications, Vendor Risk users can now enable email notifications when additional evidence documents are approaching their expiry date.

### Other improvements

* Vendor Risk users can now export Incidents and News data to Excel for their own organization and their vendors.
* Vendor Risk risk assessment templates now support using merge tags within HTML content, allowing HTML styling to dynamically change based on vendor attributes.
* Breach Risk and Vendor Risk now include Bootstrap version detection, enabling identification of assets running outdated or vulnerable Bootstrap versions.
* When uploading documents to the Trust Center content library, duplicate files are now flagged inline with a blue pill indicator, allowing users to view and manage all duplicates at a glance rather than resolving them one by one.

## [New threat signal: Published MCP server definitions](/releases/new-threat-signal-published-mcp-server-definitions)

Mark Barber June 3, 2026

Threat Monitoring now surfaces Model Context Protocol (MCP) server definitions that references organizations in public registries and marketplaces. This gives security teams visibility into emerging AI tooling, integrations, and ecosystem activity associated with their organization, supporting earlier identification and assessment of potential exposures. As AI ecosystems continue to mature, Threat Monitoring is evolving to help security teams identify risks associated with AI-native technologies before they become established parts of the attack surface.

### AI Analyst advice fields in Threat Monitoring exports

Threat Monitoring exports now include the AI Analyst advice fields shown in the threat details UI: threat context, indicators of risk, and remediation guidance. These fields are now available in XLS and CSV exports, so teams working with exported data retain the full context they need for triage and reporting.

### Expanded CVE Coverage: 17 new Citrix NetScaler CVEs Added

We now have improved product detection for Cisco Netscaler. Customers with Netscaler in their attack surface will now see the product in Breach Risk Detected Products. Breach Risk and Vendor Risk now also include verified vulnerability detection for Cisco Netscaler across 17 CVEs, including CVE-2023-4966 (Citrixbleed), CVE-2025-5777 (Citrixbleed 2), CVE-2026-3055 (Citrixbleed 3), CVE-2025-6543, CVE-2025-7775, and CVE-2025-7776.

### Multi-select attribute assignment in automations

Vendor Risk onboarding automations now support multi-select attribute assignment. When building vendor onboarding automation rules for a multi-select attribute, multiple matching values can be applied in a single rule, applied to a multi-select question. To learn more about Vendor onboarding automations see [How to use automation to apply tiers, labels, portfolios and custom attributes to your vendors](https://help.upguard.com/en/articles/8073950-how-to-use-automation-to-apply-tiers-labels-portfolios-and-custom-attributes-to-your-vendors).

### Faster AI Autofill review with direct match indicators

Trust Exchange questionnaire AI Autofill now identifies and displays direct matches in green throughout the review UI, including the progress bar and answer sidebar. A direct match means the AI found an exact match to a previously completed questionnaire in the platform, so the answer text is unchanged. These answers are represented with an “Exact match” confidence rating label, so reviewers can skip them and focus only on answers that need review.

### Trust Exchange Public APIs now generally available

The Trust Exchange Public APIs previously available in beta, are now generally available. These APIs allow organizations to integrate Trust Exchange workflows with external systems and automate content library uploads, access management and listing questionnaires programmatically.

### Questionnaire recipient email unsubscribe

Questionnaire recipients can now unsubscribe from new message notification emails on a per-questionnaire basis, giving vendors more control over their inbox without affecting the questionnaire workflow itself.

### Usage tracking for Risk Automations

Risk Automations now allows customers to see how many executions have been used, so that you can track your total executions, executions used, burn rate, and expiry date in the UI.

### Workflow list actions in Risk Automations

Common workflow actions are now available directly from the Workflow list in Risk Automations, without needing to open the canvas editor. Actions such as duplicate, rename, and archive can be taken from the list view, making it faster to manage multiple workflows.

### Other improvements

* Trust Center content library now supports bulk document uploads. Users can select and upload multiple files at once using the upload modal, rather than adding documents one at a time.
* Vendor Risk risk assessment report templates now support HTML comments, allowing teams to annotate and document their templates without affecting rendered output.
* In Risk Automations, the Slack integration channel lists now load correctly for organizations with large numbers of channels, resolving an issue where the channel selector would spin indefinitely.

May 2026

## [Security Profile redesigned for faster vendor reviews](/releases/security-profile-redesigned-for-faster-vendor-reviews)

Mark Barber May 20, 2026

We’ve redesigned the Vendor Risk Security Profile with a new tabular format. Users can search and filter checks to pinpoint where risks are. Bulk actions then make it faster to act on multiple risks at once. To learn more, see [working with controls and checks](https://help.upguard.com/en/work-with-controls-and-checks-).

### Selective social media platform monitoring

Threat Monitoring users can now choose which social media platforms to include in their monitoring configuration. Platforms can be toggled on or off individually, so security teams can track only the channels relevant to them.

### Time-limited access to shared Trust Center assets

Trust Exchange administrators can configure automatic access expiry for shared Trust Center assets. A time limit (such as 30, 60, 90 days or 1 year) can be set, after which access is automatically revoked, minimising the risk of long-term data exposure especially for sensitive documents.

### Batch questionnaire notification emails

Trust Exchange now groups questionnaire messages into single notifications. This reduces inbox volume for both questionnaire senders and responders while maintaining real-time visibility into active questionnaires.

### Other improvements

* The AI model powering Trust Exchange questionnaire autofill has been upgraded to a newer Gemini backend, improving the accuracy of AI-generated responses.
* Trust Exchange administrators can now create custom security link categories directly within the Trust Center, moving beyond the generic “Other” label.
* The “Refine prompt” editor in the questionnaire AI autofill allows for direct custom prompt editing during the review process, targeting either specific unreviewed answers or the full questionnaire.
* Users can now review and interact with completed questionnaire answers while the AI autofill is still processing the remaining questions, rather than waiting for the full run to finish.
* Duplicating a Risk Automations workflow with unsaved changes now prompts you to save first, preventing edits from being lost.

## [Customizable AI prompts for questionnaire responses](/releases/customizable-ai-prompts-for-questionnaire-responses)

Mark Barber May 6, 2026

Trust Exchange users can now customize the AI prompts used to generate questionnaire responses, giving them greater control over tone, format, and how the AI handles gaps in documentation. Prompts can be tailored to specific personas (Security Analyst, Sales Engineer, CISO) and support custom instructions such as automatically inserting pre-approved language.

### AI confidence ratings for questionnaire responses

Trust Exchange now shows a confidence rating alongside each AI-generated questionnaire suggestion, indicating how certain the AI is based on the available source data. This helps reviewers to quickly validate high-confidence responses while focusing on the ones that need closer attention.

### Admin countersigning for NDAs

Trust Exchange administrators on the Paid tier can now require counter-signature before granting access to requested assets. When enabled, access requests remain pending until an admin reviews and countersigns, or rejects, the signed NDA agreement. Admins receive a notification for each new signing that requires their approval.

### Notifications for onboarding request status updates

Vendor Risk customers can now set up notifications for when the status of a vendor onboarding request changes, including assignee updates, due date changes, and priority updates, keeping internal teams informed without needing to check manually.

### Other improvements

* Our monthly import of public vendor security documents has expanded coverage to include 53 new documents, enhancing the data available in vendors’ Security Profiles.
* Users can now display a set of healthcare industry compliance badges on their Trust Centers to demonstrate compliance with certifications and standards.
* The character limit for the Trust Center About section has been increased from 500 to 4,000 characters, giving organizations more space to describe their company.

1 / 18

[Next](/releases.md?page=2)

Sign up for UpGuard's monthly newsletter

Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](https://www.upguard.com/instant-security-score?)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
