Skip to main content

Current Multi-Tenant Version | 3.67

Warning

The /presets API was deprecated a year ago when it was replaced by /preset-manager. We are now announcing EOL for the /presets API. Please ensure that it is no longer used in your workflows as we will soon stop supporting it entirely.

New Features and Enhancements

Improved Repository URL Sync for Code Repository Integration Projects

General Availability: October 4, 2026

Checkmarx One now keeps the repository URL for Code Repository Integration Projects consistently synchronized across project-related APIs. When a project is created or updated, whether through the UI or via API, the repository URL is automatically reflected in both the Project and Project Settings API responses, so no manual synchronization is needed afterward.

This ensures accurate, up-to-date repository information is always available to any service or integration that relies on project data.

Bulk Triage in Risk Orchestration

General Availability: October 4, 2026

Risk Orchestration now supports bulk triage, letting you apply severity, state, and change log updates to multiple risks at once instead of triaging them one by one. Select the risks you want to update using checkboxes in the risk table, then use the Triage action in the bulk action toolbar to apply changes across all selected risks, including risks from different scanners in the same selection.

When the selection includes SCA risks, the triage editor also lets you adjust VEX parameters for those risks as part of the same bulk update. Because each update is processed independently, successfully applied changes are preserved even if others fail, and any failures can be reviewed and retried without re-applying risks that already succeeded.

This significantly reduces the time needed to clear large triage backlogs and lets you act on entire risk clusters in a single step.

Added Events to Audit Trail

General Availability: October 4, 2026

Project deletion (projects.delete) is now logged in the Audit Trail API.

Expanded Scheduled Scans for Code Repository Integration Projects

General Availability: October 4, 2026

Scheduled scans now support all Code Repository Integration projects.

With this update, teams can rely on consistent, automated scan coverage across their full project portfolio, regardless of how the project was imported.

Improved Accessibility for Presets and Side Navigation

General Availability: October 4, 2026

Checkmarx One now provides improved reflow support in the Presets and side navigation areas, ensuring content adapts properly to different screen sizes and zoom levels without loss of information or functionality.

These enhancements make navigation clearer and more reliable for users relying on assistive technologies or working with enlarged text and layouts.

Extended Exemption Rules to Azure DevOps CLI

General Availability: October 4, 2026

Checkmarx One now extends Exemption Rules support to scans triggered via the CLI in Azure DevOps pipelines. Break-build policy evaluation for CLI-triggered scans honors the same exempt-state configuration defined in Policy Management, so previously dispositioned findings no longer trip the build gate regardless of how the scan was triggered.

This gives teams using Azure DevOps CLI pipelines consistent, reliable break-build behavior across UI, API, and CLI workflows.

Added Automated AI Remediation

General Availability: October 4, 2026

Note

This feature is available only to customers with AI Triage & Remediation enabled.

Checkmarx One can now automatically trigger AI Remediation for risks that match your configured criteria, removing the need to request fixes manually. Auto Remediation is configured in Account Settings, under AI Assist, where you define which projects and branches are automatically remediated. You also specify the scanners (currently supported for SAST and SCA) and set the severity thresholds. You can allow or deny project-level overrides for these settings. Once enabled, the system generates AI fix suggestions for matching risks after a scan completes (or after AI Auto Triage completes, if triage is also enabled), and for supported Code Repository Integration projects (GitHub), opens a pull request with the suggested fix automatically. By closing the gap between risk identification and remediation, this feature reduces manual effort and increases the consistency and speed of your remediation workflow.

Internet-Facing Badge in Risk Orchestration

General Availability: October 4, 2026

Risk Orchestration now displays an Internet-Facing badge next to a project's name in the unified project table when that project is identified as publicly accessible. This badge is sourced from data provided by Cloud Insights, and is therefore only available for accounts with a configured Cloud Insights integration. By surfacing internet exposure directly in the table, teams can quickly identify and prioritize publicly accessible projects when assessing risk.

Added Asynchronous CSV Export for Imports Table

General Availability: October 4, 2026

The imports table in Bring Your Own Results now supports asynchronous CSV export, allowing large export requests to be processed in the background instead of blocking the user while the file is generated. Once ready, the exported file can be downloaded from the imports table.

This improves reliability for large data sets and lets users continue working while the export completes.

Extended Exemption Rules to CLI Across All SCM Platforms

General Availability: October 4, 2026

Break-build Exemption Rules now apply consistently to scans evaluated via the CLI, in addition to the existing pull request decoration flow.

With this update, exempted findings are correctly excluded from the break-build result regardless of which SCM platform or evaluation flow is used, ensuring consistent pipeline behavior across all integration methods.

MCP Server - Added Support for Additional Scanners

General Availability: September 27, 2026

The Checkmarx MCP Server now supports API Security, allowing AI coding assistants and chat clients to query and act on API risks directly from tools like Claude Code, Cursor, Windsurf, and Copilot CLI. Developers can ask about exposed APIs, drill into specific risks, and identify undocumented, shadow, or zombie APIs without leaving their coding environment, while security teams can query org-wide API risk posture through any MCP-connected chat client.

In addition, support for IaC Security and Secrets scanners was expanded to include triage tools, bringing these scanners to parity with existing support for SCA and SAST.

Notice

API Security is not yet supported for triage tools.

For additional information about the Checkmarx MCP server, see documentation

SCA

Resolved Private Package Dependency Path Limitation

A previous limitation prevented SCA from showing the full dependency path for transitive dependencies introduced through a Private Package - the segment linking the transitive dependency back to the Private Package was missing, both in the package path view and in the CycloneDX SBOM export.

This limitation has now been resolved: the package path view in SCA Scan Results and the exported CycloneDX SBOM both display the complete path. Users can now fully trace how a transitive dependency entered their project, and exported SBOMs accurately represent all dependency relationships.

IaC

The IaC version included in this release of Checkmarx One is 2.1.21.

IaC updates are documented in the IaC changelog.

DAST

Mozilla Browser Update Requests Suppressed in DAST Scans

General Availability: September 27, 2026

DAST scans no longer send browser update requests to Mozilla domains, so this traffic won't appear in scan reports. The change applies to both Firefox and Chrome-based scans.

CLI and Plugins Releases of September 2026

CLI Version 2.3.66

Status

Item

Description

NEW

Optional Flags Parameter

The use-gitignore option can now be passed using the global --optional-flags parameter to exclude files and folders specified in the .gitignore file from the scan.

NEW

Exclude Git Folder Flag

Added the --exclude-git-folder flag to the cx scan create command. When enabled, the .git folder is excluded from the scan source upload ZIP.

NEW

Generated Files

When scanning a local directory, the CLI generates contributors.csv and metadata.json files in the .checkmarx folder. These files are automatically deleted after the scan is successfully created.

CLI Version 2.3.65

Status

Item

Description

NEW

Default Filters

We have standardized the behavior for all scanners, so that the default filters are now applied for all scans so that only supported files are included in the ,zip archive. To provide an option to bypass these filters, we added a new flag --skip-default-filter. When this flag is passed, all files in the source location are included in the .zip that is scanned.

NEW

Supported Files

Added the following file extensions to the list of supported files that are included in the .zip archive that is scanned.*.tfvars, *.tfbacken,

IDE Plugins

In September we released the following IDE plugin versions:

  • Eclipse - 2.1.18 (uses CLI v2.3.66)

  • VS Code - 2.73.0 (uses CLI v2.3.66)

Improvements and Bug Fixes

Status

Item

Platform

Description

NEW

General

Eclipse, VS Code

General improvements and bug fixes

Resolved Issues

Item

Description

AST-164943

API latency affecting /api/results in the EU2 region.

AST-178874

The Azure DevOps token cache intermittently lost its account reference, causing "Cannot find account in token cache" 500 errors on scans and PRs.

AST-177424

Azure PR decoration failed with a JsonEOFException when the threads response exceeded one TCP chunk while retrieving Azure pull request comments.

AST-177134

Scans got stuck and were eventually canceled because the "Allocate SAST Worker" Camunda job never completed despite retries remaining.

SCA-28183

Auto scans stopped working.

SCA-27834

Auto scans were triggered too frequently.

AST-178704

Typo corrected: "automaticaly" was misspelled in the Assign Projects criteria panel (now reads "automatically").

AST-178483

The link-access-client's /health and /ready checks reported the tunnel as healthy without verifying actual connectivity, so stale connections went undetected and caused silent DAST scan failures.

AST-176838

SAST query editor search opened a query's parent group instead of the query itself.

AST-171891

The Scorecard scan option was not available in the UI.

AST-164591

Adding a note to a finding for a specific project returned a 504 Gateway Timeout error from POST /api/kics-results-predicates.

AST-164164

SCA scans failed due to the SAST path filter.

AST-159004

An idle browser tab silently created a new audit session approximately every 30 minutes instead of timing out.

AST-179432

Creating a new Apex session in the Query Editor failed with a "no languages detected" error.

AST-172008

FIS scans were failing.

AST-167047

The Global API Inventory was empty.

AST-164509

Checkmarx IAM's client_credentials endpoint returned a 500 error due to a duplicate realm-management roles mapper.

AST-151640

The Application Name column on the Applications page could not be manually resized or expanded.

AST-140305

The same vulnerability appearing in different scans was incorrectly marked as new.

SCA-28021

SCA: Missing certificate configuration for the CxLink connection.

AST-18156

Documentation on the legacy plugins page listed the wrong download version.

AST-179433

AI Remediation for multiple risks failed to perform full credit deductions.

AST-179422

The Plugins tab in Global Settings showed a "No Data" error.

AST-179362

AI Triage GitHub PR status remained stuck at "In progress" indefinitely because no TriageCompletedEvent or TriageFailedEvent was ever consumed.

AST-178382

SCA Triages often failed to perform credit deductions in Metronome for AI Triage consumption.

AST-178353

The AST-CLI's Go-keyring integration was failing on Linux.

AST-177143

A command injection vulnerability was found in the Checkmarx MCP Trigger Scan.

AST-168241

The Feedback App API silently accepted the unsupported "secretdetection" engine.

AST-165558

The users list CSV export feature was documented in the 3.62 release notes but was not actually delivered.

AST-165036

In sast-rm, redelivered "already allocated" scan jobs were silently dropped, causing scans to hang until the 24-hour platform timeout.

AST-164230

Unreleased Access Management Phase 2 endpoints were reachable by customers and returned misleading 400/500 errors.

AST-159385

Possible false positives on Red Hat images due to backported fixes.

AST-156521

Scans became stuck in a running state.

AST-151863

Database intervention was needed to fix project data.

AST-142604

In single-tenant environments, API project search failed when a name filter was added to the call.

AST-140573

DAST API scans failed with a StackOverflowError when importing a valid OpenAPI spec, due to recursive schema resolution in swagger-parser.

AST-138540

DAST authentication failed when using Basic HTTP Auth.

AST-136339

sast-rm crashed in a single-tenant environment.

AST-136091

Patched packages were incorrectly reported as vulnerable in Checkmarx One.

AST-135369

ASCA failed to detect the "Broken Encryption Algorithm" finding (false negative).

AST-134142

The collect-logs-ast remote backend was unreachable.

AST-101049

Scans failed due to signal termination.

AST-84390

In single-tenant environments, scans failed with a "worker allocation timeout" error.

AST-179828

Global Settings documentation links returned 404/500 errors because the old docs page was retired during a docs-site restructuring.

AST-177212

The Global Settings Save button was globally disabled when the Header Banner was enabled with empty text.

AST-177154

AI Triage and Remediation introduced new issues for SCA.

AST-169212

AI Remediation introduced additional SAST findings after applying the generated fix.