Version 3.66
Version 3.66.1
This minor release introduces Hybrid SAST Scans, a new feature in Checkmarx One.
Hybrid SAST Scans in Checkmarx One
SAST automatically routes your code to a traditional, query-based SAST scan or an LLM-based scan depending on the language and framework it's written in, so you get broader language coverage without changing how you trigger a scan.
If your codebase uses only languages SAST already supports, it's scanned exclusively by the traditional SAST. If it includes languages SAST doesn't support, those files are analyzed by the LLM-based engine instead.
For mixed codebases, each engine scans the parts it supports, and you see the combined results as one unified set. You can opt in or out of LLM-based scanning, and the feature follows the AI Usage toggle in your Global Settings.
New Features and Enhancements
SAST Engine Upgrade to Version 9.7.7
The SAST engine in Checkmarx One has been upgraded to version 9.7.7 and will be rolled out gradualy over the following weeks. To discover all the new features and updates in the latest version, refer to this page.
Expanded AI Triage and Remediation for SCA
Note
This feature is available only to customers with AI Triage & Remediation enabled, and applies to SCA findings only.
Running AI Triage and Remediation from the Risk Orchestration screen is now supported for SCA risks, bringing parity with the AI T&R experience already available for SAST. This gives AppSec and security teams a consistent, scalable way to triage and remediate risk across scan engines, improving traceability and reducing dependency on developer workflows for risk understanding.
Added Triggering User and Insight Link to AI Triage Changelog
Note
This feature is available only to customers with AI Triage & Remediation enabled, and applies to SAST and SCA findings only.
The Changelog now shows the user who triggered Triage Assist and includes a link to the AI Triage insight for every AI-driven state change in SAST and SCA findings. This gives AppSec teams full auditability of AI-assisted triage decisions - reviewers can see who initiated the action and follow the link to understand the reasoning behind the state change.
This applies to both manual and automated (auto-triage) executions. For auto-triage rules, the triggering user reflects the user who configured the rule. For bulk triage actions, each finding's changelog entry links to its own individual insight.
Improved Accuracy of AI Triage and Remediation for SAST Risks
Note
This feature is available only to customers with AI Triage & Remediation enabled, and applies to SAST findings only..
We have fundamentally upgraded the AI Triage and AI Remediation agents to improve accuracy and performance. This upgrade is applied automatically with no action required by the end user.
Added Results Distribution Tables to Scan Report
The Scan Report now includes two new tables - Results Distribution by Status and Results Distribution by State - giving a tabular breakdown of vulnerabilities alongside the existing pie charts. These tables appear in the Scan Results Overview section of the report and are included in both PDF and JSON exports.
This addition brings the Scan Report in Checkmarx One to parity with the equivalent reports for SAST on-premises customers, providing a consistent user experience for migrating customers.
Included API Security Data in Analytics
API Security engine data is now included in Analytics. Vulnerability data from API Security scans is ingested alongside other engines and reflected in dashboard KPIs, charts, and summary counters. Severity and state changes to API Security findings are also captured and reflected in Analytics.
Added Tools for Risk Triage via MCP Server
You can now change a risk's state and severity directly through the MCP Server, without opening Checkmarx One. This lets developers and AppSec engineers act on a risk — for example, marking it Not Exploitable or Confirmed — directly from their AI assistant using natural language. Support spans all major scan engines, so the same workflow applies regardless of where the risk originated. By keeping triage inside the tools developers already use, this reduces context switching and speeds up remediation decisions.
For more information, see documentation
SCA
Simplified Global Inventory Navigation
Global Inventory now uses simple Next and Previous controls to move through results, replacing page-number navigation on the Packages, Risks, and Licenses tabs. This aligns with how the feature is typically used - applying filters to answer specific questions rather than browsing sequentially - and eliminates cases where page numbers pointed to results beyond what could be displayed. The result is a more consistent and reliable way to move through filtered inventory data.
This improvement also speeds up data export and removes the previous limitation of the number of results that can be exported.
New Native Reachability Analysis Engine in SCA
SCA now performs reachability analysis natively as part of the scan, removing the need for a separate SAST scan to determine Package Usage and Exploitable Path results. Reachability results appear in the same manner as before, with no additional configuration required. A new Reachability column adds visibility into how the analysis ran for each risk, showing one of the following statuses: Exp.Path Found, Not Detected, Not Supported, Pending Analysis, or Calculation Failed. By running independently of the SAST engine, this change removes prior connectivity requirements and scan-method restrictions, delivering faster and more accurate exploitable path results.
Feature scope
Languages: Python, Java, JavaScript, and C#.
Dependency scope: Direct dependencies — packages called directly by the application.
Vulnerability scope: Vulnerabilities where the vulnerable method is contained in the directly called package.
For additional details, see documentation
Added Support for Python UV Package Manager
SCA now supports UV as a Python package manager for dependency resolution, in addition to the existing pip-based support. This is available both in Checkmarx One cloud scans and through the SCA Resolver.
You can adjust the UV Resolution setting at the tenant or project level to use UV for resolving Python projects. Pip remains the default selection to preserve existing scan behavior for projects that continue using pip. Scan results, including vulnerabilities, license findings, and SBOM exports, display consistently with other supported Python package managers.
This gives teams that have adopted UV for its speed and deterministic dependency management full SCA visibility, closing a coverage gap for projects using modern Python tooling.
IaC
The IaC version included in this release of Checkmarx One is 2.1.21.
IaC updates are documented in the IaC changelog.
DAST
Specific Permissions for DAST AI Features
You now need specific permissions to use each DAST AI feature. Two new permissions, Dast-to-code-initiator and Dast-AI-attack-initiator, have been added to the dast-admin role.
Without the permission, you will still see the DAST AI features in the menu, but they will appear disabled with a tooltip prompting you to contact your admin. If you have access to the environment but not the new permissions, you can still view existing correlation and AI attack results.
Resolved Issues
Item | Description |
|---|---|
AST-175566 | Repository filter search returned an HTTP 500 error because the GraphQL API rejected installation tokens for EMU organizations. |
AST-174473 | The apisec-kics-runner became stuck in a loop due to timeouts. |
AST-171285 | Dropdowns in Global Settings did not display any SAST presets. |
AST-171063 | DAST Thorough scan mode disabled |
AST-170302 | UI bug in Global Settings related to AI Assist. |
AST-168404 | The SAST Results page failed to load for large-dataset scans (484K results) due to a 400 error, as filtering and sorting were not supported above a certain threshold. |
AST-163960 | The scan link provided by the Checkmarx One CLI did not open scan results directly if they were not on the first page in the UI. |
AST-163883 | Performance issue affecting Analytics and Dashboard filters. |
AST-160626 | Slow synchronization for Analytics in the US2 cluster. |
SCA-27354 | Slow loading times on the Global Inventory page for large tenants. |
AST-175026 | ADO project conversion failed with a "null" project name in the branch validation URL when the org-scoped PAT path was used. |
AST-174016 | The |
AST-170290 | The MCP Tool |
AST-165036 | In sast-rm, redelivered "already allocated" scan jobs were silently dropped, causing scans to hang until the 24-hour platform timeout. |
AST-164082 | The SBOM report using Container Security failed to generate. |
AST-159622 | Investigated and resolved differences in scan results compared to Grype. |
AST-159385 | Possible false positives on Red Hat images due to backported fixes. |
AST-173516 | The Tags modal on the Scans page silently rewrote a user-entered tag to match the casing of an existing tag (e.g., |
SCA-28021 | SCA: Missing certificate configuration for the CxLink connection. |
AST-176974 | Custom States page not loading. |
AST-176972 | SAST defaults/settings did not show the presets options. |
AST-171049 | IaC (KICS) scans stalled for approximately 2 hours while waiting for the iac-runner Zeebe job to be dispatched or resumed; the scan engine itself was not implicated. |
AST-164966 | ast-results.createScan and results loading crashed with a JSON parsing error ("Expected ',' or '}' after property value") when a scan result contained a 15+ digit number inside a string value. |
AST-160641 | DAST authentication failed for a public web application. |
AST-170458 | Changing the predicate for scans of a specific project returned a 504 Gateway Timeout error from api/sast-results-predicates/. |
SCA-27606 | Changing a vulnerability state via API without a projectId updated vulnerabilities across multiple projects and bypassed history tracking. |
Issues resolved in 3.66.1 | |
AST-174460 | Contributing Developers CSV downloads hung or failed in the browser for large tenants (net::ERR_INCOMPLETE_CHUNKED_ENCODING) because the CSV was fetched via JSON/text XHR instead of responseType: 'blob'. |
AST-174448 | The Scans page became unresponsive when editing tags on scans with a large number of tags, in single-tenant environments. |
AST-172029 | Scan triggers for protected branches sometimes did not work. |
AST-170256 | A scan-completed event silently persisted an empty projects_overview row, permanently blanking the Projects list, dashboard, and reports. |
AST-164943 | API latency affecting |
AST-161492 | The Analytics API's allVulnerabilities KPI returned an empty list for valid date ranges. |
AST-151640 | The Application Name column on the Applications page could not be manually resized or expanded. |
SCA-27996 | Package-level mute did not override CVE risk state in |
AST-177134 | Scans got stuck and were eventually canceled because the "Allocate SAST Worker" Camunda job never completed despite retries remaining. |
AST-169231 | The "Supported commands" link in the PR decoration scan summary comment led to a blank page. |
AST-156535 | Investigated possible missing packages and false positives. |