

We’ve expanded the security profile template library to include templates for cloud service providers and core infrastructure providers. These map to the Cloud Security Alliance Cloud Controls Matrix (CCM), UK Cyber Essentials, the Center for Internet Security Critical Security Controls (CIS), and NIST Special Publication 800-53 Revision 5. Vendor Risk users can run AI assessments and gap analysis in Security Profile against these standards when reviewing SaaS, PaaS, IaaS, MSP, and data center vendors. For more information see Control Templates.
Remediation requests for Security Profile risks
Vendor Risk users can now request remediation for evidence risks in Security Profile directly from document citations, without sending a questionnaire. Vendors can share supporting evidence as part of the remediation process, and Vendor Risk users can manually mark risks as remediated based on their evidence and responses.
Breach Risk detected products added to detected vendors in Vendor Risk
To help Vendor Risk users more easily surface and manage risk from unknown vendors, we now surface Breach Risk detected products in the Detected tab on the Vendors page. The Detected tab on the Vendors list now shows vendors detected by Breach Risk alongside those detected by User Risk (for Breach Risk and User Risk users respectively), and vendors can be monitored directly from the list.
Automated suppression for inactive account credentials
Breach Risk Threat Monitoring can automatically suppress exposed credential detections for inactive or known-benign accounts, cutting down noise from reposted ULP and combolist data. Organizations can import, as well as manually curate, a list of known inactive accounts so future detections are triaged without manual dismissal.
Detection for the wp2shell WordPress vulnerability chain
Breach Risk and Vendor Risk now detect WordPress installations affected by CVE-2026-60137, a SQL injection vulnerability and CVE-2026-63030, a REST API batch-route confusion vulnerability. Chained together they enable unauthenticated remote code execution, and both are listed in CISA's Known Exploited Vulnerabilities catalog. Fixes are available in WordPress 7.0.2, 6.9.5, and 6.8.6.
Other improvements
- Breach Risk and Vendor Risk now detect 13 additional high and critical severity CVEs in VMware vCenter Server: CVE-2024-38813, CVE-2024-38812, CVE-2024-37080, CVE-2024-37079, CVE-2024-22274, CVE-2023-34048, CVE-2023-20895, CVE-2023-20894, CVE-2023-20893, CVE-2022-31680, CVE-2022-22982, CVE-2022-22948, and CVE-2021-22049.
- Breach Risk and Vendor Risk now detect two medium severity CVEs in the Jetpack plugin for WordPress, CVE-2024-9926 and CVE-2021-24374.
- Vendor Risk and Breach Risk users can receive an email when a risk waiver is approved or declined and can turn the notification on or off for each product from notification settings.
- Threat Monitoring snippet and image downloads use descriptive filenames built from the post date, content type, source, author, and threat ID.
- UpGuard’s preset control templates in the Security Profile have been renamed with the prefix 'UpGuard' (for example 'UpGuard Core' instead of ‘Core controls’) to clearly differentiate our recommended templates from external framework templates.






