Release notes

Cloud and core infrastructure frameworks in Security Profile

Mark Barber July 29, 2026

We’ve expanded the security profile template library to include templates for cloud service providers and core infrastructure providers. These map to the Cloud Security Alliance Cloud Controls Matrix (CCM), UK Cyber Essentials, the Center for Internet Security Critical Security Controls (CIS), and NIST Special Publication 800-53 Revision 5. Vendor Risk users can run AI assessments and gap analysis in Security Profile against these standards when reviewing SaaS, PaaS, IaaS, MSP, and data center vendors. For more information see Control Templates.

Remediation requests for Security Profile risks

Vendor Risk users can now request remediation for evidence risks in Security Profile directly from document citations, without sending a questionnaire. Vendors can share supporting evidence as part of the remediation process, and Vendor Risk users can manually mark risks as remediated based on their evidence and responses.

Breach Risk detected products added to detected vendors in Vendor Risk

To help Vendor Risk users more easily surface and manage risk from unknown vendors, we now surface Breach Risk detected products in the Detected tab on the Vendors page. The Detected tab on the Vendors list now shows vendors detected by Breach Risk alongside those detected by User Risk (for Breach Risk and User Risk users respectively), and vendors can be monitored directly from the list.

Automated suppression for inactive account credentials

Breach Risk Threat Monitoring can automatically suppress exposed credential detections for inactive or known-benign accounts, cutting down noise from reposted ULP and combolist data. Organizations can import, as well as manually curate, a list of known inactive accounts so future detections are triaged without manual dismissal.

Detection for the wp2shell WordPress vulnerability chain

Breach Risk and Vendor Risk now detect WordPress installations affected by CVE-2026-60137, a SQL injection vulnerability and CVE-2026-63030, a REST API batch-route confusion vulnerability. Chained together they enable unauthenticated remote code execution, and both are listed in CISA’s Known Exploited Vulnerabilities catalog. Fixes are available in WordPress 7.0.2, 6.9.5, and 6.8.6.

Other improvements

  • Breach Risk and Vendor Risk now detect 13 additional high and critical severity CVEs in VMware vCenter Server: CVE-2024-38813, CVE-2024-38812, CVE-2024-37080, CVE-2024-37079, CVE-2024-22274, CVE-2023-34048, CVE-2023-20895, CVE-2023-20894, CVE-2023-20893, CVE-2022-31680, CVE-2022-22982, CVE-2022-22948, and CVE-2021-22049.
  • Breach Risk and Vendor Risk now detect two medium severity CVEs in the Jetpack plugin for WordPress, CVE-2024-9926 and CVE-2021-24374.
  • Vendor Risk and Breach Risk users can receive an email when a risk waiver is approved or declined and can turn the notification on or off for each product from notification settings.
  • Threat Monitoring snippet and image downloads use descriptive filenames built from the post date, content type, source, author, and threat ID.
  • UpGuard’s preset control templates in the Security Profile have been renamed with the prefix ‘UpGuard’ (for example ‘UpGuard Core’ instead of ‘Core controls’) to clearly differentiate our recommended templates from external framework templates.
View all release notes

UpGuard Release Notes

Learn about new features, changes, and improvements to UpGuard.

Brand impersonation detection across mobile app stores

Mark Barber September 9, 2026
Read more

Clearer citations and timeline for Security Profile checks

Mark Barber August 26, 2026
Read more

Subprocessors in Trust Center

Mark Barber August 12, 2026
Read more

Complete questionnaires without closing remediation

Mark Barber July 15, 2026
Read more

Company name aliases for smarter detection

Mark Barber July 1, 2026
Read more

FortiBleed Exposure Detection

Mark Barber June 25, 2026
Read more

Updated application usage policy controls

Mark Barber June 17, 2026
Read more

New threat signal: Published MCP server definitions

Mark Barber June 3, 2026
Read more
View all release notes

See UpGuard In Action

Book a free, personalized onboarding call with one of our cybersecurity experts.
Free instant security score

How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
Website Security scan results table Cyber security rating score 850 out of 950