Knowledge base

Vulnerability Detection Update, September 28, 2026

Release Date:




New Detections

  • Added detection of certificates whose private key is publicly known, such as keys affected by the Debian OpenSSL vulnerability or ROCA.

  • Added detection of RSA certificate keys that can easily be factored.

  • Added detection of certificates that share a public key or an RSA prime factor with another certificate in the same scan.

  • Added detection of certificates with invalid serial numbers.

  • Added detection of NLnet Labs Unbound DNS servers.

  • Added detection of catch-all web virtual hosts that serve content not reachable through any declared virtual host.

  • Added technology fingerprints for the following:

    • 18 WordPress plugins, including Elementor, Jetpack, Smart Slider 3 and GTranslate

    • DOMPurify

    • Hugo

    • CKAN

Bug Fixes and Minor Improvements

  • Certificate issues on services scanned without virtual hosts are now reported regardless of the IP virtual host setting.

  • Certificate issues affecting every configured virtual host of a service are now reported once for the service instead of once per virtual host.

  • TLS protocol and cipher results are no longer reported twice for the same service.

  • Weak certificate keys are now detected on every certificate in the chain.

  • Improved detection of Drupal, Plone, TYPO3, nginx and JFrog Artifactory.

  • The CrushFTP authentication bypass check no longer interprets timeouts as an indication of vulnerability.

  • Improved the reliability of checks against slow or unresponsive targets.

  • Malformed TLS responses no longer interrupt the TLS scan.