releases.shpreview

Application Security Changelog

Mon
Wed
Fri
JulAugSepOctNovDecJanFebMarAprMayJunJul
Less
More
Releases31Avg9/mo

Precursor, a client-side JavaScript that enables session-based bot detection, is rolling out to all customers. It continuously evaluates behavioral signals across a session, re-validates challenge clearance as behavior changes, and updates bot scores with session context.

Read more →

This week's release introduces new managed protection to address a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) and a new generic rule designed to identify and block sophisticated SQL Injection (SQLi) bypass attempts leveraging obfuscated boolean logic.…

Read more →

This release introduces new detections for a critical SQL injection vulnerability in Drupal installations utilizing PostgreSQL (CVE-2026-9082), alongside targeted protection for an unsafe deserialization flaw in the Mirasvit Cache Warmer extension (CVE-2026-45247). Additionally,…

Read more →
Last Checked
1h ago
Latest
Jul 17, 2026
Tracking since Jan 6, 2025