Web Application Scanning Engine Release 10.17

June 15, 2026

Enhanced Cookie Handling

We have implemented comprehensive detection for nameless cookies during application scans. WAS Engine now automatically reports cookie-based security findings, including missing Secure attribute, missing HttpOnly attribute, and cookie configuration vulnerabilities.

This helps you identify insecure cookie configurations and take corrective action to protect user sessions and sensitive data.

Redundancy Rewrite Rules Optimization for URL Processing

We have updated the end-regex patterns in auto-generated redundancy rewrite rules to handle paths that end /. This ensures URLs are accurately matched during scanning, reducing missed detections and improving overall scan coverage.

CMS Detection and Reporting Improvements

We have significantly improved Content Management System (CMS) fingerprinting accuracy in QID 150021, with streamlined reporting and better categorization of multiple CMS detections.

This helps you quickly identify the CMS used in your web application and assess associated security risks more accurately.

Enhanced Network Connection Reporting

We have added comprehensive support for curl response output in QID 530030, with traceroute integration. This provides improved diagnostic information and better error context, helping you troubleshoot connectivity issues between the scanner and your web application more effectively.

QID 150865 Update: Profanity Detection in Crawled Content

QID 150865 is updated to detect profanity or abusive language during the crawl phase. You can use this detection to identify non-compliant content early and reduce the risk of policy violations. You can review and remediate flagged content to ensure compliance with policies and guidelines.

Custom JavaScript Support for False Positive Reduction

We have added support for custom JavaScript URL patterns with special handling for vendor-specific file names. This reduces false positives in JavaScript vulnerability detections, allowing you to focus on genuine security issues rather than spending time investigating inaccurate findings.

Improved Custom Authentication Handling

We have improved login URL handling in custom authentication with post-login response validation and heuristic-based detection of successful authentication states. This ensures more accurate authentication verification during scans, reducing authentication failures and improving scan coverage for protected web applications.

Web Cache Poisoning Detection Improvements

We have enhanced cache control header verification and improved detection of cached server responses. False positives when caching is disabled are reduced, and scan time is optimized using the top 10 crawled links with prerequisite filtering. This helps you accurately identify web cache poisoning vulnerabilities while reducing noise in your scan results.

Enhanced Scan Execution Reporting

We have improved error reporting in QID 150606 and QID 150021 with a notification - Some tests were skipped. This gives you better visibility into scan execution, helping you understand which tests were skipped and why, so you can take appropriate action to ensure comprehensive scan coverage.

Enhancements for API Security 

The following enhancements are available for the API security feature in TotalAppSec.

Enhanced Postman Scan Reporting

We have improved QID 150606 reporting to distinguish between Postman API Security and Postman OpenAPI scans, improving the accuracy of API security assessment categorization.

Improved Client Certificate Authentication Reporting

We have improved authentication status reporting for client certificate authentication in Postman API Security scans, providing better visibility into the authentication state during scans.

Qualys Notification: Application Security Detections Published in April 2026