
When a Security Profile answer cites a vendor’s SOC 2 report, the citation can now include the control reference (for example, CC 1.3) alongside the quoted text. Users can go straight to the relevant control in the source document and see which audit principle the evidence relates to. Coverage includes SOC 2 control references and similar numbered control formats.
Security Profiles now include 385 additional public documents for top monitored vendors. The documents are available as evidence in Vendor Risk and have been pre-scanned against the Security Profile, so users spend less time chasing evidence and can start assessing vendors sooner.
The List all questionnaires endpoint, together with Add collaborator, Add recipient, and Delete contacts, has moved to general availability. List all questionnaires returns every questionnaire across an organization in one call. Add recipient and Add collaborator invite people to a questionnaire or onboarding request after it has been sent. Delete contact removes a vendor contact, completing the set alongside the Add and Update endpoints so vendor onboarding can run end to end through the API.
UpGuard has added detections for three vulnerabilities. CVE-2026-35292 is an unauthenticated takeover of Oracle WebLogic Server Console, exploitable over HTTP (CVSS 10.0), affecting versions 14.1.2.0.0 and 15.1.1.0.0. CVE-2026-19490 is an authentication bypass using an alternate path or channel in NetScaler ADC and Gateway, affecting 13.1 builds 63.21 and earlier and 14.1 builds 73.32 and earlier. CVE-2022-27486 is an OS command injection in the FortiDDoS and FortiDDoS-F execute CLI commands that lets an authenticated attacker run shell code as root. Each detection raises a verified vulnerability in Breach Risk for an organization’s own assets and in Vendor Risk for monitored vendors.