Cortex XSOAR Releases - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR Releases

Product
Cortex XSOAR
Creation date
2022-11-23
Last date published
2026-05-24

Cortex XSOAR has introduced the following releases.

Date

Version

Details

May 3, 2026

8.14 SaaS

GA

  • Multi-tenant support for child tenant name changes: Simplify tenant management by renaming child tenants from within the Cortex Gateway. You now have the flexibility to ensure tenant names consistently reflect current business requirements, maintaining operational clarity across large-scale SOC deployments.

  • Organized content management: Easily distinguish between your custom work and content pack items with a dedicated workspace for each. To ensure a cleaner view, we moved all content pack items to the Content Pack Items page, while the Content Items page is now reserved exclusively for your custom creations.

  • Enhanced audit logs: Gain full visibility and meet compliance requirements with expanded auditing for notification forwarding and content management. You can now track configuration changes for notifications and high-stakes content lifecycle events, such as pushing content to production, directly within the Management Audit log.

January 25, 2026

8.13 SaaS

GA

  • Contextual playbook documentation: We have introduced Info Mode to the playbook editor, allowing you to view detailed task and section descriptions directly within your workflow.

  • New Rapid Response Playbook: Automate the detection and mitigation of CVE-2025-59287, a critical remote code execution vulnerability in Microsoft Windows Server Update Services (WSUS) caused by insecure deserialization.

  • Improve playbook unlocking: Ensure your team can edit their automation workflows with automatic or manual playbook unlocking. The system now clears locks immediately when a user logs out or when a session expires

November 9, 2025

8.12 SaaS

GA

  • Conflict-free playbook: Prevent concurrent playbook editing with this enhancement, ensuring your team can build and modify automation workflows without conflicts.

  • Unique task logos: Boost clarity, quickly distinguish between integration commands, custom scripts, and system actions with playbook tasks that display unique logos and content pack indicators.

  • Unit 42 Threat Intelligence content pack: A new Unit 42 content pack provides high-value integrations that leverage Unit 42’s world-class threat intelligence, research, and analysis, replacing several deprecated packs (like AutoFocus and Unit 42 ATOMs Feed). To complete this migration, configure the new Unit 42 Feed and Enrichment integrations, update all related playbooks, and disable the old integrations.

July 20, 2025

8.11 SaaS

GA

  • Advanced search for playbooks and scripts: Easily find and use existing scripts and playbooks by searching for specific text within scripts or by searching the names of scripts, tasks, and third-party integrations within playbooks.

  • Clear incidents waiting in the ingestion queue: Regain control during incident floods and ensure critical playbooks run smoothly, preventing bottlenecks and facilitating rapid self-recovery.

  • Generic Webhook integration enhancements: Easily ingest external data without an API integration and connect with diverse services with support for header-based authentication and a simplified setup experience.

April 27, 2025

8.10 SaaS

GA

  • Automatically export incidents: For customers who need to store incidents beyond their retention period, XSOAR can automatically export incidents to external storage, enabling indefinite retention and continued access to historical incident data.

  • Support for additional Cortex XSOAR APIs: The expanded API support enables organizations to reset the ROI widget, update existing lists, get a list, upload files, and clone playbooks so they can better fine-tune automated incident workflows and integrations.

February 2, 2025

8.9 SaaS

GA

  • A new look and feel for playbooks: The latest enhancements in user experience improve playbook readability and clarity through an updated look and feel.

  • Collapsible playbook sections: The updated collapsible playbook sections enable users to stay focused on the relevant playbook details without distractions, allowing for easier navigation through complex playbooks and increased productivity.

  • Unlimited user license for development tenants: With no license limit for users on development tenants, you can build, test, and refine automations at scale. This drives faster innovation, more reliable workflows, and scalable solutions as your organization grows.

  • Notifications for deprecated content: New automated user notifications about deprecated playbooks, sub-playbooks, and scripts ensure updated, effective, and accurate security workflows.

September 22, 2024

8.8 SaaS

GA

  • Canvas -Multilayer indicator/incident relationship graph: SOC analysts can now create and share dynamic attack diagrams or static snapshots with incident response, forensics, and threat-hunting teams.

  • The Guard Rails page: Cortex XSOAR 8 now includes the Guard Rails page, which shows performance-related errors and warnings that can be used as a guide to detect and prevent actions that may cause a decline in performance or instability.

  • Exclude enrichment of indicators: Indicators can now be marked as Enrichment Excluded in Cortex XSOAR, ensuring they will not be enriched. This gives you better control over your Indicators and the ability to optimize system performance by managing the indicator enrichment process.

  • Audit logs: Audit log coverage is expanded to capture detailed records of incident edits, including the modified fields. This improvement ensures a comprehensive record of all changes, significantly enhancing the ability to trace the incident's history and evolution.

June 30, 2024

8.7 SaaS

GA

  • Seamlessly migrate all your data, configurations, and settings, including indicators and incidents from Cortex XSOAR 6.13 On-prem to Cortex XSOAR 8 Cloud using a built-in wizard streamlining the migration process.

  • To effectively investigate an incident and analyze associated indicators, the SOC analyst must have access to up-to-date data and a clear view of the most recent changes made to the relevant indicators, as well as the initial entries of indicator changes.

  • When generating a report, you can choose the timezone to ensure accurate and localized reporting for users working in multiple geographical locations.

  • Admin users can manage notification distribution by adding or removing tenant’s stakeholders' email addresses on the Server Settings page without the need to add them first on the tenant. This feature streamlines communication and simplifies administration.

April 14, 2024

8.6 SaaS

GA

  • You can create API keys with multiple roles to improve operational efficiency and allow dynamic RBAC management of API keys.

  • The Administrator can restrict designated users' access to specific dashboards through role assignment.

  • Cortex XSOAR has an API endpoint for GET, CREATE, UPDATE, and DELETE for API keys.

  • You can change the color of the favicon for each tenant, which allows you to identify which tenant is being used in each tab at a glance.

February 11, 2024

8.5 SaaS

GA

  • Enable communication between SOC analysts (MT/MSSP)

  • Keep Retained Incidents

  • Assign retention licenses for MT deployments

  • Content repository improvements

  • Customize system emails

  • Use an authenticated Docker image

October 29, 2023

8.4 SaaS

GA

  • In-app documentation

  • Private repository support in a dev/prod environment

  • Export incidents to Excel

  • Authenticated communication tasks

  • Define credentials for long-running integrations

  • SSO improvements

July 9, 2023

8.3 SaaS

GAJuly 2023

  • Improved Auditing

  • Manage User Groups in the Cortex Gateway

  • Manage RBAC settings in the Cortex Gateway

  • Improved Navigation

  • Improved Indicator Verdict Calculation

April 23, 2023

8.2 SaaS

GAApril 2023

  • XSOAR 8 now offers Cortex XSOAR multi-tenant, designed for managed security service providers and enterprises requiring strict data segregation with the flexibility to share and manage critical security practices across tenant accounts.

  • Role permissions have been updated to separate some administration permissions.

  • You can now subscribe to content pack updates in Marketplace.

  • Improved UI for Data Collection and Ask tasks in Playbooks, and a simplified search for playbooks with free text search.

  • Improvements to the Default Playbook.

January 1, 2023

8.1 SaaS

GAJanuary 2023

  • Integration into the Cortex platform:

    • Unified look and feel

    • Uses the platform's storage engines

    • Simplified deployment and onboarding

    • Consistent user management

  • Improved performance and reliability

  • High scalability based on a revamped architecture that utilizes cloud features

  • Built-in Git Repository for sharing data between development and production instances

Cortex XSOAR 8.13

Date

Version

Details

May 22, 2026

8.13.0

GA

  • Contextual playbook documentation: We have introduced Info mode to the playbook editor, allowing you to view detailed task and section descriptions directly within your workflow. This update provides essential context and guidance at a glance, helping you understand and navigate complex automated processes without leaving the editor view.

  • Maintain uptime with automatic storage expansion: Maintain continuous application uptime by preventing service interruptions caused by full disks. We added an "Auto Expand" feature in the TUI that automatically increases storage capacity when usage hits 85%.

Cortex XSOAR 8.12

Date

Version

Details

March 22, 2026

8.12.0

Maintenance Release: Fixed an issue where the system syslog sender failed to connect to syslog servers using private IP addresses.

January 25, 2026

8.12

GA

  • Conflict-free playbook editing: Prevent concurrent playbook editing with this enhancement, ensuring your team can build and modify automation workflows without conflicts.

  • Unique task logos: Boost clarity, quickly distinguish between integration commands, custom scripts, and system actions with playbook tasks that display unique logos and content pack indicators.

  • Forward logs to your syslog server: Enable centralized monitoring and satisfy log retention requirements by forwarding Management Audit, Integration, and Guard Rails logs to your preferred syslog server.

Cortex XSOAR 8.11

Date

Version

Details

December 26, 2025

8.11.0

Maintenance Release: bug fixes, including security and upgrade issues.

November 25, 2025

8.11.0

Maintenance Release: bug fix, which included an issue where some custom dashboards failed to load after an upgrade.

November 13, 2025

8.11

GA

  • Advanced search for playbooks and scripts: Easily find and use existing scripts and playbooks by searching for specific text within scripts or by searching the names of scripts, tasks, and third-party integrations within playbooks.

  • Clear incidents waiting in the ingestion queue: Regain control during incident floods and ensure critical playbooks run smoothly, preventing bottlenecks and facilitating rapid self-recovery.

  • Generic Webhook integration enhancements: Easily ingest external data without an API integration and connect with diverse services with support for header-based authentication and a simplified setup experience.

Cortex XSOAR 8.10

Date

Version

Details

January 7, 2026

8.10.0

Maintenance Release: bug fixes, including security and upgrade issues.

November 5, 2025

8.10.0

Maintenance release: bug fixes, including upgrades, security, and system performance and login issues.

Build: master-8.10.0-8.10.0.18-d6bd62a5

August 25, 2025

8.10.0

Maintenance release: bug fixes, including some security issues.

Build: master-8.10.0-8.10.0.15-7716e2dc

July 30, 2025

8.10

GA

  • The expanded API enables organizations to reset the ROI widget, update existing lists, get a list, upload files, and clone playbooks to better fine-tune automated incident workflows and integrations.

  • The Cortex XSOAR 8.10 release also includes the following bug fix highlights:

    • On-prem backups were not restored correctly when using NFS for external storage.

    • The On-prem gateway reset to the US region when changing the proxy configuration.

    • The log bundle did not contain output from Elasticsearch endpoints.

Cortex XSOAR 8.9

Date

Version

Details

January 15, 2026

8.9.0

Maintenance release: bug fix for system performance.

Build: master-8.9.0-8.9.0.175-47550265

November 5, 2025

8.9.0

Maintenance release: bug fixes, including system performance, system login, and security issues.

Build: master-8.9.0-8.9.0.173-318d829c

April 7, 2025

8.9

GA

  • A new look and feel for playbooks: The latest enhancements in user experience improve playbook readability and clarity through an updated look and feel.

  • Collapsible playbook sections: The updated collapsible playbook sections enable users to stay focused on the relevant playbook details without distractions, allowing for easier navigation through complex playbooks and increased productivity.

  • Unlimited user license for development tenants: With no license limit for users on development tenants, you can build, test, and refine automations at scale. This drives faster innovation, more reliable workflows, and scalable solutions as your organization grows.

  • Notifications for deprecated content: New automated user notifications about deprecated playbooks, sub-playbooks, and scripts ensure updated, effective, and accurate security workflows.

  • Export and delete incidents: Enhance incident data management by enabling administrators to export and delete incidents for regulatory and storage requirements. This helps minimize data exposure, ensures efficient and secure management of incident data retention, and helps free up disk space to optimize system performance.

  • Use an authenticated Docker image repository: Use a custom container registry with your authentication credentials to apply custom images created on a private machine. Using your registry enables you to manage access permissions, ensuring only authorized users can pull and use the custom images. This protects sensitive information and enables more secure and controlled deployment of custom images within the Cortex XSOAR environment.

Cortex XSOAR 8.8

Date

Version

Details

January 5, 2025

8.8

GA

  • Cortex XSOAR multi-tenant: Cortex XSOAR 8 On-prem now offers the following:

    • Multi-tenant for Managed Security Service Providers (MSSP)

    • Multi-tenant for Enterprises

  • Backup and restore of configurations and data: Continuous and efficient operation of your Cortex XSOAR tenant by periodically backing up your tenant, which enables you to recover data, configurations, and settings.

  • Canvas - Multilayer Indicator/Incident Relationship Graph: SOC analysts can now create and share dynamic attack diagrams or static snapshots with IR, forensics, and threat-hunting teams. This enables them to visualize and link key security incidents and IOCs for faster and more streamlined investigation.

Cortex XSOAR 8.7

Date

Version

Details

September 17, 2024

8.7

GA

  • Cortex XSOAR On-prem now supports:

    • Deployment on Oracle Cloud Infrastructure (OCI).

    • Deployment on AWS

    • Log in via SSH to the Cortex XSOAR textual UI for admin users.

  • To effectively investigate an incident and analyze associated indicators, the SOC analyst must have access to up-to-date data and a clear view of the most recent changes made to the relevant indicators, as well as the initial entries of indicator changes.

  • Cortex XSOAR now supports teams working in different locations, enabling the user to select the timezone of the report.

  • Cortex XSOAR can now run more playbooks per hour for medium and large-scale deployments

Cortex XSOAR 8.6

Date

Version

Details

July 14, 2024

8.6

GA

  • Cortex XSOAR Cluster High Availability: Cortex XSOAR On-prem cluster, with three or more nodes, includes high availability capabilities to improve reliability for critical security operations.

  • Enhanced role-based access control for dashboards: The Administrator can now restrict access to specific dashboards for designated users through role assignment.

  • Multi-role API keys: You can now create API keys with multiple roles to improve operational efficiency and allow dynamic RBAC management of API keys.

  • New endpoint for managing API keys using the API: Cortex XSOAR now has an API endpoint for GET, CREATE, UPDATE, and DELETE for API keys.

  • Customize the favicon color: You can now change the color of the favicon for each tenant. This allows you to identify which tenant is being used in each tab at a glance.

Cortex XSOAR 8.5

Date

Version

Details

March 31, 2024

8.5

GA

Cortex XSOAR 8.5 On-prem is now released and includes the following features:

  • Integration into the Cortex platform:

    • Unified look and feel

    • Simplified deployment and onboarding

  • Improved performance and reliability

  • High scalability based on a revamped architecture

  • User-friendly installation with an easy-to-follow step-by-step TUI to install and configure Cortex XSOAR:

    • Tenant network and IP settings

    • Proxy settings

    • Cluster settings

    • Scale size

Date

Version

Details

December 7, 2025

Cortex XSOAR 6.14.0 (B6168561)

Maintenance Release: bug fixes, including some security issues.Minor Releases

April 6, 2025

Cortex XSOAR 6.14.0 (B3036535)

Maintenance Release: Cortex XSOAR is now compliant with FIPS 140-3.

February 9, 2025

Cortex XSOAR 6.14 (B2436668)

GA

  • Migration from Cortex XSOAR 6 MSSP/multi-tenant to Cortex XSOAR 8 cloud MSSP/multi-tenant. To start the migration, users need to upgrade to this version. For more information about the migration process, see the Cortex XSOAR Migration Guide.

  • Cortex XSOAR 6.14 now supports:

    • Oracle Linux version 9.4 (for engine and server installation)

    • RHEL 9.5 (for engine and server installation)

    • Amazon Linux 2023 (for engine and server installation)

    • Elasticsearch versions 8.14 and 8.15

    • OpenSearch versions 2.15 and 2.16

August 18, 2024

Cortex XSOAR 6.13 (B1284375)

GA

  • Migration from Cortex XSOAR 6 On-prem to Cortex XSOAR 8 Cloud is now available. To start the migration, users need to upgrade to this version. For more information about the migration process, see the Cortex XSOAR Migration Guide.

  • Cortex XSOAR 6.13 now supports:

    • Oracle Linux versions 8.9 and 9.3 (for engine and server installation)

    • RHEL versions 8.10 and 9.4 (for engine and server installation)

    • Elasticsearch versions 8.11, 8.12, and 8.13

    • OpenSearch versions 2.10, 2.11, 2.12, and 2.14

August 18, 2024

Cortex XSOAR 6.12.0 (B1271551)

Maintenance Release: bug fixes, including some security issues.Minor Releases

February 29, 2024

Cortex XSOAR 6.12.0 (B857430)

Maintenance Release: bug fixes, including some security issues.Minor Releases

December 3, 2023

Cortex XSOAR 6.12.0 (B661643)

Maintenance Release: bug fixes, including some security issues.Minor Releases

September 20, 2023

Cortex XSOAR 6.12.0 (B493375)

Maintenance Release: bug fixes, including some security issues.Minor Releases

September 3, 2023

Cortex XSOAR 6.12 (B481081)

GANew Features

  • Migration from Cortex XSOAR 6 to 8 is available for Hosted customers

  • Cortex XSOAR supports RHEL v8.8 and v9.0

  • Edit a list installed from a content pack by detaching it

  • The reputationCalcAsync argument is now available for the addEntries command

  • The list.<listName>.separator and list.separator server configurations now support tabs as list separators, using \t

August 7, 2023

Cortex XSOAR 6.11.0 (B443478)

Maintenance Release: bug fixes and enhancements, including some security issues.Minor Releases

April 23, 2023

Cortex XSOAR 6.11 (B300044)

GANew Features

  • Improved Upgrade Process for Multi-Tenant Deployments

  • After deleting a user, you can now clear the user's data from content, such as active incidents and investigations, automations, etc.

  • Substantial improvements of playbook performance, including context operations, indicator extraction, and playbook execution.

  • New Menu Navigation

  • Role Permissions have been updated for more granular control.

March 6, 2023

Cortex XSOAR 6.10.0 (B255865)

Maintenance release: fixes an issue related to hosts connecting to the main server in a multi-tenant deployment.Minor Releases

February 26, 2023

Cortex XSOAR 6.10.0 (B250144)

Maintenance release: bug fixes and enhancements, including some security issues.Minor Releases

December 5, 2022

Cortex XSOAR 6.10 (B187344)

GARelease Information

  • Communication task links in Context Data: When running an Ask or Data Collection task, links are generated to collect the recipients' responses and are now available in the incident's context data.

  • Content Security Policy: You can now enable Content Security Policy (CSP), which adds a layer of security, including detecting and mitigating certain types of attacks.

  • Quiet Mode for Manual Tasks: You can now turn Quiet mode on or off for individual manual tasks in a playbook.

  • Documentation Portal: Documentation for all Cortex products, including Cortex XSOAR, has moved to https://docs-cortex.paloaltonetworks.com/.

November 18, 2022

Cortex XSOAR 6.9.0 (B177754)

Maintenance release: bug fixes and enhancements, including some security issues.Minor Releases

November 16, 2022

Cortex XSOAR 6.8.0 (B176620)

Maintenance release: bug fixes and enhancements, including some security issues.Minor Releases

August 8, 2022

Cortex XSOAR 6.9 (B3387847)

GANew Features

  • Deployment Wizard: When installing or updating content packs, the DEPLOYMENT WIZARD tab guides you step-by-step to adopt your use case (including Phishing and Malware), significantly reducing the setup time.

  • SAML 2.0 Configuration: You can now let administrators manually enter certain user information fields when configuring SAML 2.0, which persists if those fields are not provided by the SAML third-party provider.

  • Zoom level:  When switching between playbooks, the user's zoom level is now preserved (in = more detail, out = larger view).

  • Added a warning message when viewing comments in incidents: (Multi-Tenant) Added a warning message when handling bulk incidents to prevent customer information from being unintentionally shared with other customers.