- Checkmarx Documentation
- Checkmarx One
- Release Notes
- Current Multi-Tenant Version | 3.67
Current Multi-Tenant Version | 3.67
Warning
The /presets API was deprecated a year ago when it was replaced by /preset-manager. We are now announcing EOL for the /presets API. Please ensure that it is no longer used in your workflows as we will soon stop supporting it entirely.
New Features and Enhancements
Improved Repository URL Sync for Code Repository Integration Projects
General Availability: October 4, 2026
Checkmarx One now keeps the repository URL for Code Repository Integration Projects consistently synchronized across project-related APIs. When a project is created or updated, whether through the UI or via API, the repository URL is automatically reflected in both the Project and Project Settings API responses, so no manual synchronization is needed afterward.
This ensures accurate, up-to-date repository information is always available to any service or integration that relies on project data.
Bulk Triage in Risk Orchestration
General Availability: October 4, 2026
Risk Orchestration now supports bulk triage, letting you apply severity, state, and change log updates to multiple risks at once instead of triaging them one by one. Select the risks you want to update using checkboxes in the risk table, then use the Triage action in the bulk action toolbar to apply changes across all selected risks, including risks from different scanners in the same selection.
When the selection includes SCA risks, the triage editor also lets you adjust VEX parameters for those risks as part of the same bulk update. Because each update is processed independently, successfully applied changes are preserved even if others fail, and any failures can be reviewed and retried without re-applying risks that already succeeded.
This significantly reduces the time needed to clear large triage backlogs and lets you act on entire risk clusters in a single step.
Added Events to Audit Trail
General Availability: October 4, 2026
Project deletion (projects.delete) is now logged in the Audit Trail API.
Expanded Scheduled Scans for Code Repository Integration Projects
General Availability: October 4, 2026
Scheduled scans now support all Code Repository Integration projects.
With this update, teams can rely on consistent, automated scan coverage across their full project portfolio, regardless of how the project was imported.
Improved Accessibility for Presets and Side Navigation
General Availability: October 4, 2026
Checkmarx One now provides improved reflow support in the Presets and side navigation areas, ensuring content adapts properly to different screen sizes and zoom levels without loss of information or functionality.
These enhancements make navigation clearer and more reliable for users relying on assistive technologies or working with enlarged text and layouts.
Extended Exemption Rules to Azure DevOps CLI
General Availability: October 4, 2026
Checkmarx One now extends Exemption Rules support to scans triggered via the CLI in Azure DevOps pipelines. Break-build policy evaluation for CLI-triggered scans honors the same exempt-state configuration defined in Policy Management, so previously dispositioned findings no longer trip the build gate regardless of how the scan was triggered.
This gives teams using Azure DevOps CLI pipelines consistent, reliable break-build behavior across UI, API, and CLI workflows.
Added Automated AI Remediation
General Availability: October 4, 2026
Note
This feature is available only to customers with AI Triage & Remediation enabled.
Checkmarx One can now automatically trigger AI Remediation for risks that match your configured criteria, removing the need to request fixes manually. Auto Remediation is configured in Account Settings, under AI Assist, where you define which projects and branches are automatically remediated. You also specify the scanners (currently supported for SAST and SCA) and set the severity thresholds. You can allow or deny project-level overrides for these settings. Once enabled, the system generates AI fix suggestions for matching risks after a scan completes (or after AI Auto Triage completes, if triage is also enabled), and for supported Code Repository Integration projects (GitHub), opens a pull request with the suggested fix automatically. By closing the gap between risk identification and remediation, this feature reduces manual effort and increases the consistency and speed of your remediation workflow.
Internet-Facing Badge in Risk Orchestration
General Availability: October 4, 2026
Risk Orchestration now displays an Internet-Facing badge next to a project's name in the unified project table when that project is identified as publicly accessible. This badge is sourced from data provided by Cloud Insights, and is therefore only available for accounts with a configured Cloud Insights integration. By surfacing internet exposure directly in the table, teams can quickly identify and prioritize publicly accessible projects when assessing risk.
Added Asynchronous CSV Export for Imports Table
General Availability: October 4, 2026
The imports table in Bring Your Own Results now supports asynchronous CSV export, allowing large export requests to be processed in the background instead of blocking the user while the file is generated. Once ready, the exported file can be downloaded from the imports table.
This improves reliability for large data sets and lets users continue working while the export completes.
Extended Exemption Rules to CLI Across All SCM Platforms
General Availability: October 4, 2026
Break-build Exemption Rules now apply consistently to scans evaluated via the CLI, in addition to the existing pull request decoration flow.
With this update, exempted findings are correctly excluded from the break-build result regardless of which SCM platform or evaluation flow is used, ensuring consistent pipeline behavior across all integration methods.
MCP Server - Added Support for Additional Scanners
General Availability: September 27, 2026
The Checkmarx MCP Server now supports API Security, allowing AI coding assistants and chat clients to query and act on API risks directly from tools like Claude Code, Cursor, Windsurf, and Copilot CLI. Developers can ask about exposed APIs, drill into specific risks, and identify undocumented, shadow, or zombie APIs without leaving their coding environment, while security teams can query org-wide API risk posture through any MCP-connected chat client.
In addition, support for IaC Security and Secrets scanners was expanded to include triage tools, bringing these scanners to parity with existing support for SCA and SAST.
Notice
API Security is not yet supported for triage tools.
For additional information about the Checkmarx MCP server, see documentation
SCA
Resolved Private Package Dependency Path Limitation
A previous limitation prevented SCA from showing the full dependency path for transitive dependencies introduced through a Private Package - the segment linking the transitive dependency back to the Private Package was missing, both in the package path view and in the CycloneDX SBOM export.
This limitation has now been resolved: the package path view in SCA Scan Results and the exported CycloneDX SBOM both display the complete path. Users can now fully trace how a transitive dependency entered their project, and exported SBOMs accurately represent all dependency relationships.
IaC
The IaC version included in this release of Checkmarx One is 2.1.21.
IaC updates are documented in the IaC changelog.
DAST
Mozilla Browser Update Requests Suppressed in DAST Scans
General Availability: September 27, 2026
DAST scans no longer send browser update requests to Mozilla domains, so this traffic won't appear in scan reports. The change applies to both Firefox and Chrome-based scans.
CLI and Plugins Releases of September 2026
CLI Version 2.3.66
Status | Item | Description |
|---|---|---|
NEW | Optional Flags Parameter | The |
NEW | Exclude Git Folder Flag | Added the |
NEW | Generated Files | When scanning a local directory, the CLI generates |
CLI Version 2.3.65
Status | Item | Description |
|---|---|---|
NEW | Default Filters | We have standardized the behavior for all scanners, so that the default filters are now applied for all scans so that only supported files are included in the ,zip archive. To provide an option to bypass these filters, we added a new flag |
NEW | Supported Files | Added the following file extensions to the list of supported files that are included in the .zip archive that is scanned.*.tfvars, *.tfbacken, |
IDE Plugins
In September we released the following IDE plugin versions:
Improvements and Bug Fixes
Status | Item | Platform | Description |
|---|---|---|---|
NEW | General | Eclipse, VS Code | General improvements and bug fixes |
Get Latest Version from Marketplace | Changelog | Documentation |
|---|---|---|
Resolved Issues
Item | Description |
|---|---|
AST-164943 | API latency affecting |
AST-178874 | The Azure DevOps token cache intermittently lost its account reference, causing "Cannot find account in token cache" 500 errors on scans and PRs. |
AST-177424 | Azure PR decoration failed with a |
AST-177134 | Scans got stuck and were eventually canceled because the "Allocate SAST Worker" Camunda job never completed despite retries remaining. |
SCA-28183 | Auto scans stopped working. |
SCA-27834 | Auto scans were triggered too frequently. |
AST-178704 | Typo corrected: "automaticaly" was misspelled in the Assign Projects criteria panel (now reads "automatically"). |
AST-178483 | The link-access-client's |
AST-176838 | SAST query editor search opened a query's parent group instead of the query itself. |
AST-171891 | The Scorecard scan option was not available in the UI. |
AST-164591 | Adding a note to a finding for a specific project returned a 504 Gateway Timeout error from POST /api/kics-results-predicates. |
AST-164164 | SCA scans failed due to the SAST path filter. |
AST-159004 | An idle browser tab silently created a new audit session approximately every 30 minutes instead of timing out. |
AST-179432 | Creating a new Apex session in the Query Editor failed with a "no languages detected" error. |
AST-172008 | FIS scans were failing. |
AST-167047 | The Global API Inventory was empty. |
AST-164509 | Checkmarx IAM's |
AST-151640 | The Application Name column on the Applications page could not be manually resized or expanded. |
AST-140305 | The same vulnerability appearing in different scans was incorrectly marked as new. |
SCA-28021 | SCA: Missing certificate configuration for the CxLink connection. |
AST-18156 | Documentation on the legacy plugins page listed the wrong download version. |
AST-179433 | AI Remediation for multiple risks failed to perform full credit deductions. |
AST-179422 | The Plugins tab in Global Settings showed a "No Data" error. |
AST-179362 | AI Triage GitHub PR status remained stuck at "In progress" indefinitely because no |
AST-178382 | SCA Triages often failed to perform credit deductions in Metronome for AI Triage consumption. |
AST-178353 | The AST-CLI's Go-keyring integration was failing on Linux. |
AST-177143 | A command injection vulnerability was found in the Checkmarx MCP Trigger Scan. |
AST-168241 | The Feedback App API silently accepted the unsupported "secretdetection" engine. |
AST-165558 | The users list CSV export feature was documented in the 3.62 release notes but was not actually delivered. |
AST-165036 | In sast-rm, redelivered "already allocated" scan jobs were silently dropped, causing scans to hang until the 24-hour platform timeout. |
AST-164230 | Unreleased Access Management Phase 2 endpoints were reachable by customers and returned misleading 400/500 errors. |
AST-159385 | Possible false positives on Red Hat images due to backported fixes. |
AST-156521 | Scans became stuck in a running state. |
AST-151863 | Database intervention was needed to fix project data. |
AST-142604 | In single-tenant environments, API project search failed when a name filter was added to the call. |
AST-140573 | DAST API scans failed with a |
AST-138540 | DAST authentication failed when using Basic HTTP Auth. |
AST-136339 | sast-rm crashed in a single-tenant environment. |
AST-136091 | Patched packages were incorrectly reported as vulnerable in Checkmarx One. |
AST-135369 | ASCA failed to detect the "Broken Encryption Algorithm" finding (false negative). |
AST-134142 | The |
AST-101049 | Scans failed due to signal termination. |
AST-84390 | In single-tenant environments, scans failed with a "worker allocation timeout" error. |
AST-179828 | Global Settings documentation links returned 404/500 errors because the old docs page was retired during a docs-site restructuring. |
AST-177212 | The Global Settings Save button was globally disabled when the Header Banner was enabled with empty text. |
AST-177154 | AI Triage and Remediation introduced new issues for SCA. |
AST-169212 | AI Remediation introduced additional SAST findings after applying the generated fix. |