2026.07¶
Features & Enhancements¶
Tripwires¶
- Deploying AWS credential and MySQL dump Tripwires during a pentest no longer requires the Remote Access Tool (RAT), reducing Endpoint Detection and Response (EDR) noise. Windows Suspicious Process Monitor Tripwires still require the RAT, and Tripwire Jobs continue to use it where possible.
- Updated Tripwire alert timestamps to use Coordinated Universal Time (UTC).
Vulnerability Management Hub (VMH)¶
- Added a Port column to the Weaknesses table for additional technical context.
- Updated processing pentests to sort by completion date.
External Asset Discovery (EAD)¶
- Improved retry handling for Known Exploited Vulnerabilities (KEVs) on fragile network appliances.
- Added clearer, more user-friendly names for External Asset Discovery schedules.
- Scope configuration now rejects bare public suffixes, such as
.co.ukand.ind.br. - Re-enabled the NodeZero Portal's Subdomain Takeover configuration option.
Identity & Active Directory¶
- Added support for enumerating and storing AD (Active Directory) group information.
- Added NTLM (NT LAN Manager) posture detection to identify domains where NTLM is disabled.
- Replaced secretsdump-based DCSync detection with LDAP Access Control List (ACL) scanning.
MCP Server¶
- Added a more focused and predictable set of tools.
- Added support for refreshing tokens, to minimize the frequency of manual sign-ins.
- Added more-robust OAuth authentication, with clearer sign-in error handling, new setup and usage flow, and leaner tool responses for faster interactions.
- Deprecated the general-purpose
run_h3_graphql_requesttool in favor of our new scoped, purpose-built tools. If you've relied onrun_h3_graphql_requestfor direct queries, please migrate to the corresponding dedicated tools linked above.
Rapid Response¶
- Updated the Rapid Response Home, Detail, and Results views to display CVE (Common Vulnerabilities and Exposures) identifiers instead of internal weakness identifiers.
- Action-item descriptions now support the Vulnerable status.
- Limited the configuration form to 3,000 IP addresses.
- Enabled Org Admins of parent accounts to manage the Rapid Response exploitability-testing setting for child accounts.
- We now display a warning banner when users add notes to unreachable assets.
Attack Path & Findings Intelligence¶
- Enhanced Threat Actor Intelligence (TAI) mapping and visualizations across key attack findings.
Endpoint Detection & Response¶
- Added an empty state for assets that have no EDR (Endpoint Detection and Response) coverage.
Managed Service Provider & Enterprise Platform¶
- We now enforce contract limits independently for each product licensed to Managed Service Provider (MSP) client accounts.
- Improved asset allocation calculations for MSP parent and child accounts.
- Added default asset allocation settings when creating MSP client accounts.
- We now enforce read-only restrictions on co-branding and white-labeling settings.
- Manual asset allocation mode now blocks clients from pentesting only when enforcement is active and the parent asset pool is exhausted.
- We now prevent Admins from setting a client’s allocation below the number of assets that the client has already tested.
- Usage notification emails are now suppressed when contract-limit checking is disabled.
New Attack Content¶
-
Cisco Unified Communications Manager – CVE-2026-20230
A Server-Side Request Forgery (SSRF) vulnerability in the WebDialer service enables an unauthenticated attacker to write files to the operating system that could later be used to gain root privileges. :llmCitationRef[2] -
Squid Proxy (SquidBleed) – CVE-2026-47729
An out-of-bounds read vulnerability in Squid’s File Transfer Protocol (FTP) gateway enables a trusted client to retrieve data from unrelated transactions through a malicious FTP server. :llmCitationRef[3] -
SonicWall SMA1000 Series – CVE-2026-15409 & CVE-2026-15410
An SSRF vulnerability enables unauthenticated attackers to make requests to unintended locations, while a separate code-injection vulnerability enables authenticated administrators to execute arbitrary operating system commands. :llmCitationRef[4] :llmCitationRef[5] -
Adobe ColdFusion – CVE-2026-48282
A path traversal vulnerability can lead to arbitrary code execution in the context of the current user without requiring user interaction. :llmCitationRef[6] -
ManageEngine ADAudit Plus – CVE-2026-6516
Vulnerabilities in the agent application programming interface (API) can be combined by an unauthenticated attacker to achieve remote code execution on affected systems. :llmCitationRef[7] -
Alibaba Fastjson – CVE-2026-16723
A remote code execution vulnerability affects Fastjson versions 1.2.68 through 1.2.83 under the default configuration, without requiring AutoType or a classpath gadget. :llmCitationRef[8] -
Hermes WebUI – H3-2026-1011
Missing authentication checks on embedded terminal endpoints enable unauthenticated attackers to execute arbitrary commands as the server process user. -
Hikvision IP Cameras – CVE-2017-7921
An improper authentication vulnerability in multiple Hikvision products can enable attackers to elevate privileges and access sensitive information. :llmCitationRef[9]
Platform Performance & Stability¶
- Optimized organization-wide Mean Time to Remediate (MTTR) queries so that the NodeZero Portal's trend chart loads more reliably.
Bug Fixes¶
- Fixed failed Vulnerability Risk Intelligence uploads.
- Fixed a missing Weakness link in attack path details.
- Fixed both Signed and Not signed certificates appearing for the same functional URL.
- Fixed credential analysis incorrectly associating credentials with endpoints.
- Fixed Business Email Compromise (BEC) impacts missing from pentest results.
- Fixed in-scope hosts being incorrectly labeled Out of Scope during asset authorization.
- Improved detection accuracy for H3-2025-0002.
- Fixed Simple Network Management Protocol (SNMP) services on non-standard ports skipping proof collection.
- Fixed External Asset Discovery omitting subdomains redirected through Domain Name System (DNS) DNAME records.
- Restored SharePoint and OneDrive support following authentication changes.
- Fixed Scope editing failing to add domains and IP addresses.
- Fixed Azure Front Door handling during domain fingerprinting and asset authorization.
- Fixed External Asset Discovery accepting country-specific generic second-level domains.
- Fixed External pentest provisioning failures for scopes without authorized assets.
- Fixed External pentests incorrectly treating discovered subdomains as explicit targets.
- Fixed password-spray tests locking out user accounts.
- Fixed credential verification running during AD Password Audits when it was not required.
- Fixed AD enumeration failures across disjoint domains.
- Fixed credential extraction timing out after four hours on large AD domains.
- Fixed Server Message Block (SMB) result parsing after connection failures.
- Fixed duplicate proof resources in SMB guest-access findings.
- Fixed Rapid Response action items and exposure-status tooltips for unreachable assets.
- Fixed the Time Open value continuing to increase after an asset was mitigated.
- Fixed Rapid Response scope fields failing to reset after users changed the pentest type.
- Fixed white-label branding failing to appear for MSP clients.
- Fixed parent-account asset allocation totals when child accounts lacked allocation records.
- Fixed customers being incorrectly blocked from testing after exceeding allocation limits.
- Fixed Comma-Separated Values (CSV) download status in the Rapid Response relevant-assets table.
Federal
Users of NodeZero Federal might experience a 1–2 week delay in the availability of some features, Attack Content, or bug fixes.