Release notes

Security Profile citations now include source control references

Mark Barber October 6, 2026

When a Security Profile answer cites a vendor’s SOC 2 report, the citation can now include the control reference (for example, CC 1.3) alongside the quoted text. Users can go straight to the relevant control in the source document and see which audit principle the evidence relates to. Coverage includes SOC 2 control references and similar numbered control formats.

More vendor evidence added to the Security Profile

Security Profiles now include 385 additional public documents for top monitored vendors. The documents are available as evidence in Vendor Risk and have been pre-scanned against the Security Profile, so users spend less time chasing evidence and can start assessing vendors sooner.

Questionnaire and contact endpoints now generally available in the Vendor Risk API

The List all questionnaires endpoint, together with Add collaborator, Add recipient, and Delete contacts, has moved to general availability. List all questionnaires returns every questionnaire across an organization in one call. Add recipient and Add collaborator invite people to a questionnaire or onboarding request after it has been sent. Delete contact removes a vendor contact, completing the set alongside the Add and Update endpoints so vendor onboarding can run end to end through the API.

Vulnerability detections for three new CVEs

UpGuard has added detections for three vulnerabilities. CVE-2026-35292 is an unauthenticated takeover of Oracle WebLogic Server Console, exploitable over HTTP (CVSS 10.0), affecting versions 14.1.2.0.0 and 15.1.1.0.0. CVE-2026-19490 is an authentication bypass using an alternate path or channel in NetScaler ADC and Gateway, affecting 13.1 builds 63.21 and earlier and 14.1 builds 73.32 and earlier. CVE-2022-27486 is an OS command injection in the FortiDDoS and FortiDDoS-F execute CLI commands that lets an authenticated attacker run shell code as root. Each detection raises a verified vulnerability in Breach Risk for an organization’s own assets and in Vendor Risk for monitored vendors.

View all release notes

UpGuard Release Notes

Learn about new features, changes, and improvements to UpGuard.

Threat Posture: an executive view of external threat activity

Mark Barber September 22, 2026
Read more

Brand impersonation detection across mobile app stores

Mark Barber September 9, 2026
Read more

Clearer citations and timeline for Security Profile checks

Mark Barber August 26, 2026
Read more

Subprocessors in Trust Center

Mark Barber August 12, 2026
Read more

Cloud and core infrastructure frameworks in Security Profile

Mark Barber July 29, 2026
Read more

Complete questionnaires without closing remediation

Mark Barber July 15, 2026
Read more

Company name aliases for smarter detection

Mark Barber July 1, 2026
Read more

FortiBleed Exposure Detection

Mark Barber June 25, 2026
Read more
View all release notes

See UpGuard In Action

Book a free, personalized onboarding call with one of our cybersecurity experts.
Free instant security score

How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.
Website Security scan results table Cyber security rating score 850 out of 950