Invicti Professional is a dynamic application security testing (DAST) tool for Web applications and APIs. It provides automated crawling and vulnerability scanning, detection of common Web vulnerabilities such as SQL injection and XSS, API security testing, authenticated scanning, Proof-Based Scanning™ for automated vulnerability verification, IAST-assisted testing, compliance reporting, and CI/CD integration, helping security teams identify, verify, and manage application security risks. Building on these capabilities, **version 26.7.0** focuses on improvements to vulnerability verification, security configuration, and scan stability. It adds Proof data for legacy TLS protocol vulnerabilities, automatically preserves existing sensitive credentials when scan configurations are updated through the API, masks OTP Secret Keys in the user interface, and adds CWE-829 classification for Polyfill.io supply chain attack detection. It also addresses service stability issues caused by large numbers of scheduled scans starting concurrently, improves the identification of affected parameters in vulnerability details, and fixes Agent assignment issues when scheduled scans use the “Any available Agent” option, improving vulnerability evidence, sensitive information protection, and scan task management.
Invicti Professional v26.7.0 continues to provide automated web and API vulnerability detection through dynamic crawling, attack testing, and Proof-Based Scanning. These capabilities help security teams identify issues and prioritize findings that include supporting exploitability evidence. Version 26.7.0 mainly improves accuracy and scan data quality. It refines outdated TLS and weak cipher-suite detection to reduce incorrect findings, adds CWE-829 classification for the Polyfill.io supply-chain issue, corrects incomplete request-body processing when importing OpenAPI 3.0.x YAML files, and ensures that configured vulnerability severity overrides are applied correctly. The value of this release is therefore mainly in reducing false positives, improving API scan completeness, and maintaining more consistent vulnerability classification and reporting.
Invicti Professional v26.7.0 provides automated DAST for web applications and APIs, including application discovery, active security testing, and supported vulnerability verification. Instead of introducing major changes to the underlying scanning approach, version 26.7.0 concentrates on reducing reporting inconsistencies and improving imported API data. The handling of outdated TLS versions and weak cipher suites has been updated to avoid false findings caused by rejected connections. CWE-829 has been added to the Polyfill.io supply-chain vulnerability classification, OpenAPI 3.0.x YAML request-body parsing has been corrected, and custom severity settings are now applied correctly to outdated component findings. These adjustments support more accurate reporting and more predictable vulnerability-management workflows.
Invicti Professional v26.7.0 is a web and API dynamic security testing tool that uses automated crawling, active checks, and Proof-Based Scanning for supported vulnerabilities. Version 26.7.0 does not significantly change the overall scan model but instead addresses several areas that affect result quality. TLS and weak cipher-suite detection now handles rejected connections more accurately, Polyfill.io-related findings are mapped to CWE-829, OpenAPI 3.0.x YAML imports retain the required request-body information, and custom severity rules are correctly reflected in outdated component findings. The release is therefore mainly focused on reducing reporting inconsistencies and improving the accuracy of API and vulnerability-management data.
Invicti Professional v26.7.0 maintains the same DAST-oriented approach used in earlier versions, including automated discovery, dynamic testing, and verification of supported vulnerabilities. The main changes in this release relate to data quality and result handling. Connection failures are now treated more carefully during outdated TLS and weak cipher checks, reducing the chance of incorrect findings. Polyfill.io supply-chain findings receive CWE-829 classification, OpenAPI 3.0.x YAML files retain the required request-body data for API testing, and configured severity overrides are applied properly to outdated component issues. These corrections make the resulting scan data more suitable for review, reporting, and prioritization.
Invicti Professional v26.7.0 focuses more on “whether the discovered vulnerabilities are real.” By combining automated Web/API scanning with vulnerability validation, it reduces false positives and the cost of manual verification associated with traditional security scanning. This enables security teams to identify genuine vulnerabilities with real security impact more quickly and accurately.
|