Attack Surface Management - Release Notes - 2 - Cortex XPANSE

Cortex Xpanse Expander Release Notes

Product
Cortex XPANSE
Version
2
Last date published
2026-05-12
Category
Release Notes
Solution
SaaS
FEATURE DESCRIPTION

Improved asset attribution evidence

See exactly why assets link to your organization. We expanded attribution logic to expose determinations made by analysts and machine learning models, helping you validate assets faster.

CPE information in Services API

Accelerate vulnerability workflows. You can now ingest Common Platform Enumeration (CPE) data via the Services API to directly correlate services with CVEs and track versions accurately.

RADAR service classifications

RADAR service classifications have moved from 2.12 to a future release.

Scan data is now enriched with RADAR details, including port, protocol, product, and version information. This enhanced data can be searched and filtered and provides better visibility into more services.

Cloud observation processing logic update

Reduce false positives. Expander decreases the threshold for new observations to limit attribution after a cloud resource is released or modified. Applies to Prisma Cloud, AWS, GCP, and Azure.

Dangerous API misconfiguration validation testing

Newly added, more intrusive Attack Surface Tests (AST) offer the ability to validate dangerous misconfigurations in API frameworks such as Spring Boot.