Knowledge base

Release Notes September 2026

Release Date: 2026-09-23



Outscan Classic & HIAB End of Support – January 31, 2027

Support for Outscan Classic and HIAB ends on January 31, 2027. Begin planning your transition to the Outpost24 Portal and next-generation scanning solutions.

Learn more about the transition → End of Support Notice - HIAB and Outscan Classic


New Features

Portal

Asset Import from CSV

We have introduced the ability to import assets directly from CSV files, removing the need for manual entry or external API scripts when onboarding new environments. The new Import action, available in the Assets view, features a guided wizard that auto-detects column headers and provides a live preview of the mapping before processing.

The system supports mapping to standard asset fields including names, IP addresses, hostnames, and tags. To ensure data integrity, the import process prefers unique Asset group IDs when associating assets with groups and automatically defaults missing scanner assignments to the local appliance. Once started, the import runs as a background task visible in the Scans view, where you can monitor progress and review any row-level validation errors.

Screenshot 2026-09-21 at 10.33.14.png

PTaaS Workspace Enhancements

The PTaaS Workspace now surfaces engagements that need immediate action more clearly. The Needs attention card explicitly flags blocked engagements where testing cannot continue, so security managers can resolve blockers faster.

We have also added an App context management feature, letting you provide detailed application overviews and upload relevant attachments directly to an Asset group. This information is shared with the GhostLabs team to provide better context for manual assessments.

Advanced Asset Filtering

To support more complex network environments, we have updated the asset identifier filter to support multi-level subdomain matching. You can now use a single asterisk (*) to match exactly one subdomain level, or a double asterisk (**) to match any number of subdomain levels.

RC-Scanners

Performance and Observability

We have introduced several improvements to the RC-Scanner appliance to ensure stability during large-scale assessments. This includes optimized memory management for DAST segments and improved internal egress handling. RC-Scanners now also support full Role-Based Access Control (RBAC), allowing administrators to manage appliance permissions with the same granularity as other Portal resources.


Public Preview Features

Follow the link to read more about our Product Stages.

Enhanced Scan Wizard

Building on our commitment to a unified user experience, we have fully integrated Network Host Assessment, Network Discovery, and Docker Image Discovery into the new Scan Wizard. This modern interface replaces the legacy multi-tab configuration forms with a streamlined, step-by-step workflow.

The wizard now supports complex configurations including:

  • Chained workflows that automatically link discovery results to subsequent assessments.

  • Granular scanner settings and concurrency limits.

  • Integrated Ignore List selection to refine scan scope.

  • Dynamic step adjustment based on your authentication and transport layer choices.


Bug Fixes and Minor Improvements

Portal

  • Fixed an issue where the Asset Groups panel could collapse to zero width and fail to persist its size on reload.

  • Added the Actual Scanner column to the Scans view to provide clear visibility into which appliance performed a specific task.

  • Fixed a bug where the Schedules side panel was missing the Scan calendar tab.

  • Updated the Catalog view to allow filtering and sorting by the number of Occurrences.

  • Improved the Japanese UI translations based on customer feedback, including corrections for asset and discovery terminology.

  • Fixed a bug where the Type dropdown in the Subscriptions create panel would appear empty after opening an existing subscription.

  • Improved the contrast of the reason text shown for disabled menu items to meet accessibility standards.

  • Fixed an issue where the CVE Trend Chart would not update correctly when switching between findings.

  • Improved the Jinja editor to provide better tab-completion for variables, filters, and tests.

  • Improved the Activity log to remove unnecessary spacing between categories.

PCI in Portal

  • Improved PCI discovery to include common hostname prefixes (www, mail, etc.) and MX record expansion, matching legacy ASV capabilities.

  • Fixed an issue where the PCI scope overview would count out-of-scope assets in the "evaluating" total.

  • Fixed a bug where PCI finding comments could not be deleted by their author.

  • Improved the PCI report generation popup to correctly direct users to the Download report action for final submissions.

  • Fixed an issue where PCI assets could not be filtered or listed by virtual host.

  • Added a quarterly schedule preset when creating a new schedule directly from the PCI environment dialog.

DAST

  • Improved memory management for Scale scans to prevent out-of-memory errors during large SPA crawls.

  • Improved the Playwright crawler to reduce excessive debug logging.

  • Fixed a bug where Scale scans would fail to save reports containing certain illegal control characters. Versions


Versions

HIAB XML Application Version: v14.38.48

HIAB Image Version: 1789478683

Agent Version: 1.32.24

For more information about Agent versions, see Agent Latest Version.


Vulnerability Detection Update

The latest updates are published here: Vulnerability Detection Update.


End of Life Announcement

Classic UI & HIAB Platform

Support for Outscan Classic and HIAB ends on January 31, 2027. After this date, Outpost24 will no longer provide fixes, enhancements, or maintenance for either platform. All customers should complete their migration to the Portal and, where applicable, the relevant HIAB replacement solution before the End of Support date.

As part of our continued investment in Outpost24, we are modernizing both the Portal and our scanning infrastructure to provide a more scalable, integrated, and efficient vulnerability and risk management experience.

The Portal provides the foundation for ongoing product development, while our next-generation scanning solutions are designed to improve deployment flexibility and performance. This modernization allows us to focus development and support on a unified technology foundation, enabling us to deliver new capabilities faster and provide a more consistent experience for customers.

  • Official End of Support date:
    2027-01-31

Authenticated scanning – commands over SMB

In June 2023, we began introducing WinRM as an alternative to running commands on Windows targets during authenticated scans. We are announcing the End of Life of the legacy SMB-based mechanism for running commands on Windows targets.

WinRM is therefore required for authenticated scanning of Windows hosts after the End of Life date. Existing configurations that have not been migrated to WinRM will no longer function.

For now, the scanner continues to connect to the Windows registry over SMB, including when WinRM credentials are configured.

  • Official End of Life date:
    2027-01-25

  • Official End of Support date:
    2027-01-25

Selenium

  • Official End of Life date:
    2027-01-31

  • Official End of Support date:
    2027-01-31

Cloudsec

We are announcing the End of Life of our Cloudsec products. These products remain available until the end of 2026, after which they will be removed. Cloudsec will no longer be available as a standalone product or as part of OutscanNX licensing.

  • Official End of Life date:
    2026-12-31

  • Official End of Support date:
    2026-12-31