Release notes

New threat signal: Published MCP server definitions

Mark Barber June 3, 2026

Threat Monitoring now surfaces Model Context Protocol (MCP) server definitions that references organizations in public registries and marketplaces. This gives security teams visibility into emerging AI tooling, integrations, and ecosystem activity associated with their organization, supporting earlier identification and assessment of potential exposures. As AI ecosystems continue to mature, Threat Monitoring is evolving to help security teams identify risks associated with AI-native technologies before they become established parts of the attack surface.

AI Analyst advice fields in Threat Monitoring exports

Threat Monitoring exports now include the AI Analyst advice fields shown in the threat details UI: threat context, indicators of risk, and remediation guidance. These fields are now available in XLS and CSV exports, so teams working with exported data retain the full context they need for triage and reporting.

Expanded CVE Coverage: 17 new Citrix NetScaler CVEs Added

We now have improved product detection for Cisco Netscaler. Customers with Netscaler in their attack surface will now see the product in Breach Risk Detected Products. Breach Risk and Vendor Risk now also include verified vulnerability detection for Cisco Netscaler across 17 CVEs, including CVE-2023-4966 (Citrixbleed), CVE-2025-5777 (Citrixbleed 2), CVE-2026-3055 (Citrixbleed 3), CVE-2025-6543, CVE-2025-7775, and CVE-2025-7776.

Multi-select attribute assignment in automations

Vendor Risk onboarding automations now support multi-select attribute assignment. When building vendor onboarding automation rules for a multi-select attribute, multiple matching values can be applied in a single rule, applied to a multi-select question. To learn more about Vendor onboarding automations see How to use automation to apply tiers, labels, portfolios and custom attributes to your vendors.

Faster AI Autofill review with direct match indicators

Trust Exchange questionnaire AI Autofill now identifies and displays direct matches in green throughout the review UI, including the progress bar and answer sidebar. A direct match means the AI found an exact match to a previously completed questionnaire in the platform, so the answer text is unchanged. These answers are represented with an “Exact match” confidence rating label, so reviewers can skip them and focus only on answers that need review.

Trust Exchange Public APIs now generally available

The Trust Exchange Public APIs previously available in beta, are now generally available. These APIs allow organizations to integrate Trust Exchange workflows with external systems and automate content library uploads, access management and listing questionnaires programmatically.

Questionnaire recipient email unsubscribe

Questionnaire recipients can now unsubscribe from new message notification emails on a per-questionnaire basis, giving vendors more control over their inbox without affecting the questionnaire workflow itself.

Usage tracking for Risk Automations

Risk Automations now allows customers to see how many executions have been used, so that you can track your total executions, executions used, burn rate, and expiry date in the UI.

Workflow list actions in Risk Automations

Common workflow actions are now available directly from the Workflow list in Risk Automations, without needing to open the canvas editor. Actions such as duplicate, rename, and archive can be taken from the list view, making it faster to manage multiple workflows.

Other improvements

  • Trust Center content library now supports bulk document uploads. Users can select and upload multiple files at once using the upload modal, rather than adding documents one at a time.
  • Vendor Risk risk assessment report templates now support HTML comments, allowing teams to annotate and document their templates without affecting rendered output.
  • In Risk Automations, the Slack integration channel lists now load correctly for organizations with large numbers of channels, resolving an issue where the channel selector would spin indefinitely.
View all release notes

UpGuard Release Notes

Learn about new features, changes, and improvements to UpGuard.

Clearer citations and timeline for Security Profile checks

Mark Barber August 26, 2026
Read more

Subprocessors in Trust Center

Mark Barber August 12, 2026
Read more

Cloud and core infrastructure frameworks in Security Profile

Mark Barber July 29, 2026
Read more

Complete questionnaires without closing remediation

Mark Barber July 15, 2026
Read more

Company name aliases for smarter detection

Mark Barber July 1, 2026
Read more

FortiBleed Exposure Detection

Mark Barber June 25, 2026
Read more

Updated application usage policy controls

Mark Barber June 17, 2026
Read more

Security Profile redesigned for faster vendor reviews

Mark Barber May 20, 2026
Read more
View all release notes

See UpGuard In Action

Book a free, personalized onboarding call with one of our cybersecurity experts.
Free instant security score

How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
Website Security scan results table Cyber security rating score 850 out of 950