Skip to content
English
  • There are no suggestions because the search field is empty.

Release Notes - 15th June 2026

Release notes from the Edgescan bi-monthly release


  • New Features & Enhancements (Generally Available) 
    • Date of last assessment
      As a user, I can view and filter by the date on which my asset had a specific assessment type (for example, "last pen-test date" or "last retest date").

       

    • AI Insights – look and feel
      As a user, I want the AI Insights page to match the look and feel of the rest of the site, so that I can browse, read, and manage my insights in a familiar, polished interface.

  • Bug Fixes (Generally Available)
    • Clearer error when adding an API file or link

      As a user, if I upload a multi-file API as an API descriptor, I get a clear error that multi-file API files are not supported.

    • Licence suggestion audit trail

      As a user, I want to see the correct values for accepted by, rejected by, and accepted at on licence suggestions.

    • Pentest add-on licence assignment

      As a user, I can assign pentest add-on licences to assets without getting an unexpected licence conflict error.

    • Jira integration sync

      As a user working with the Jira cloud plugin, I want all my settings to save correctly when updating them.

      As a Jira user reviewing synced vulnerabilities, I can see the screenshots embedded in the detail attached to the Jira ticket, so that I understand the proof of exploitation without switching to Edgescan.

    • Unfiltered exports

      As a user, I want the asset blocker export to work without an organization selected.

    • Scoped scheduled exports

      As a user, I can scope a scheduled assessments export to a single organization (and its descendants), so I can extract data more easily.

    • Notifications for disabled assets

      As a user who has disabled scanning on an asset, I no longer want to receive assessment notifications for that asset.

    • Filter by multiple severity levels

      As a user, I want to be able to filter vulnerabilities by multiple severity levels.

    • Hyperlinks in remediation advice

      As a user, I want links in remediation advice to appear as a hyperlink.

    • Retest status on the asset badge

      As a user, I want to see the asset's status badge reflect that a retest is in progress (e.g. "scanning", "validating").

    • Reason required when disabling an asset

      As a user disabling an asset, I want to be able to select a standardised reason, or "other" if I want to enter free text, so that disabled-asset data can be aggregated cleanly.

    • Accurate permissions in user export

      As a user generating a user export with permissions, I want the export to show each user's actual granted and denied permissions, including those derived from roles.

    • Autocomplete on Blocker cause and category filters

      As a user, I can see autocomplete suggestions when typing in the "Blocker category" and "Blocker cause" filter fields, so that I can quickly find and apply the correct filter values.

    • Name an EASM investigation during creation

      As a user, I want to name an investigation during creation.

    • Internal network assets scan straight after onboarding

      As a user onboarding an internal network asset, I want it to go straight to scan when it has a valid network location specifier, so that I don't have to wait on a manual onboarding support ticket.

    • "Organization (with children)" filter on the licensing page

      As a user on the licensing page, I would like an "organization (with children)" filter.

    • Pause schedule in non-integer UTC offset timezones

      As a user configuring a pause schedule in a non-integer UTC offset timezone (e.g. IST +5:30, NPT +5:45), I want the calendar to correctly display my configured pause hours, so that I can trust the schedule reflects what I set up.

    • Scope directives for token mappings and basic auth workflows

      As a user, my token mappings are appropriately scoped to my location specifiers by default, so that none of my sensitive tokens get sent in requests out of scope of the scan.

      As a user, I can create custom scope directives for token mappings, so that I can configure more complex session management.