AppSentinels API Security Platform - July 2026 Release Notes

AppSentinels API Security Platform - July 2026 Release Notes

AppSentinels API Security Platform Release Notes
July 2026 (26.07.R1)

API Security Testing Enhancements 
    • Smarter AI-assisted alert triaging — ActiveScan now evaluates an alert's full context, including evidence and request/response payloads, consolidating results from the new Generic Analyzer and the existing Response Analyzer into a final verdict. Administrators can enable and configure AI-assisted analysis under App Settings → Vulnerability Configuration → ActiveScan.
    • Improved false-positive auditability — Record a reason when marking a vulnerability as a false positive, saved automatically to the event notes and optionally made mandatory for your team. Remediation actions, such as excluding an API or parameter from tests, prevent the same false positive from recurring.
    • New TLS security test suite — Expands ActiveScan coverage to identify weaknesses in host-level TLS configurations, including weak protocols, insecure ciphers, and certificate problems.
    • Postman collection support for standalone CLI tests — Run standalone ActiveScan tests from the CLI using Postman collections as the API data source, with support for environment, global-variable, and configuration files.
    • Faster HAR imports with No Replay mode — Import HAR files directly from captured request/response data without replaying traffic, cutting import time from minutes to seconds and improving compatibility with Burp Suite exports. Replay-based imports remain available when current API behavior needs revalidation.
    Threat Actor Blocking — Expanded WAF & Gateway Integrations

    Threat Actor Blocking now supports three additional enforcement points, extending automated blocking to more of the WAFs and gateways you already run — with both IP-based and JWT user ID-based enforcement.

    • FortiWeb (on-prem) — Supports both pre-created and auto-created blocking modes, allowing you to onboard an existing IP list and custom policy or have them created automatically.
    • Barracuda WAF — Enables automated threat actor blocking through native Barracuda WAF enforcement profiles, while preserving your existing blocking workflows and logging.
    • F5 Gateway — Supports IP and JWT header-based blocking through iRule-based enforcement, with block and unblock actions managed via F5 iRules.
    Risk & Vulnerability Management
    • Configurable risk scoring for internal APIs — A new Private API Vulnerability risk factor (enabled by default) lets you decide whether findings on internal APIs contribute to risk scores. When disabled, internal API findings contribute zero, reflected consistently across views and dashboards.
    • Hostname filtering for Vulnerability Events — Filter Vulnerability Events by one or more hostnames alongside existing criteria; exported CSV reports honor the selected hostnames.
    • New "Fixed Elsewhere" vulnerability status — Mark a vulnerability as Fixed Elsewhere when remediation occurs outside the monitored application, such as at an API gateway. These events are not raised again, and the status is available across filters, dashboards, and reports.
    Platform Configuration
    • Organization-level session & user attribution — Define reusable session, auth-session, user ID, and user-role attribution rules once at the organization level and apply them across applications. Application-specific configuration can take precedence where needed, and all changes are audit-logged.
    • SMTP email integration for on-premises deployments — On-premises deployments can now use a customer-managed SMTP server for email delivery. Administrators can configure SMTP through the email tool and service settings, enabling the platform to send alerts using your organization's existing mail infrastructure.
      • Related Articles

      • AppSentinels API Security Platform - April 2026 Release Notes

        AppSentinels API Security Platform Release Notes April 2026 (26.04.R1) Risk Factors & Risk Acceptance • New Risk Score tab displays risk factors, contributing events, severity details, and downloadable data for each API. • Configure risk score ...
      • AppSentinels API Security Platform - May 2026 Release Notes

        AppSentinels API Security Platform Release Notes May 2026 (26.05.R1) Retrospective Risk Realignment & Governance Risk Realignment (Org Settings → Security & Governance) reconciles historical vulnerability and governance events with your current ...