DATE:
AUTHOR:
CyberCloud Team
PentestPortal.io

Release 3 September 2026

DATE:
AUTHOR: CyberCloud Team

This September release contains a bunch of bug-fixes, focuses on clearer workflows, better notifications, and a smoother day-to-day experience. Pentest organizaitons can now setup configurable email notifications when customers change a finding status, newly created findings are automatically assigned to their creator, and absence management in the planning has become easier to use. We’ve also resolved a broad range of issues around waivers, invoicing, contact persons, finding assignments, and retests.

Features & Improvements

PP-693: Clickable leave days

Leave days in the planning are now directly clickable. Instead of searching for the corresponding date manually, users can select an existing absence entry and immediately navigate to the relevant day to review or modify it. This makes managing holidays, research days, and other absences considerably quicker.

PP-758: Email Notifications when customers change a finding status

PentestPortal can now send notifications when a customer changes the status of a finding, for example when a finding is marked as Accepted or Ready for Retest. Administrators can configure at instance level who should receive these notifications. Available recipients include:

  • Scheduled pentesters

  • The system notification email address

  • The account manager

This makes it easier for pentest teams to stay informed when customers take action on reported findings without having to continuously check the portal.

Customer contacts can only change finding statuses when the “May change risk status” permission is enabled for that specific contact person. This keeps control over the workflow with the pentest organization while allowing selected customer users to actively participate in remediation and retesting.

PP-710: Automatically assign new findings to the pentester

When a pentester creates a new finding, PentestPortal now automatically assigns that finding to the user who created it. This removes an extra manual step and makes ownership immediately clear, especially during pentests where multiple pentesters are working simultaneously.

Bug Fixes

  • PP-755: Report download button missing for retests in review - Fixed an interface issue where the report download button could disappear when a retest was in In Review status, particularly when longer project names reduced the available space.

  • PP-751: Reordered reproduction steps not updated immediately - Reordering reproduction steps is now reflected directly in the interface without requiring a hard browser refresh.

  • PP-736: Sent Pentest Waiver not reflected in quality requirements - Fixed an issue where a waiver sent by an account manager was not correctly reflected in the associated quality requirement.

  • PP-764: Download Pentest Waiver for draft assessments - Waivers can now be downloaded while an assessment is still in Draft status. Sending the waiver remains restricted until the assessment is no longer in Concept/Draft, with clearer feedback explaining why sending is unavailable.

  • PP-761: Incorrect billing label on assignment invoice - Fixed a mismatch where the invoice screen could show 100% upfront while the assignment was configured for 100% afterwards.

  • PP-760: Error when adding contact person at Reseller level - Adding customer contacts directly from reseller level works correctly again, including handling of the jobTitle field.

  • PP-759: Contact person quality requirement remained rejected - Fixed an issue where the contact person quality requirement remained rejected when a Customer Functional Manager had automatically been added to the pentest.

  • PP-757: Spelling error on dashboard - Corrected the Dutch dashboard text

  • PP-754: Unable to send finding to contact person - Fixed an error where sending an individual finding could incorrectly report that the selected contact person was not part of the assessment.

  • PP-752: Customer contacts missing from customer overview - Resolved an issue where customer contacts were sometimes missing from the customer-level overview even though they remained visible at pentest level.

  • PP-756: Billing method displayed incorrectly - Corrected frontend labels so the displayed billing method now matches the configured method, such as per pentest - 100% afterwards.

  • PP-753: Finding assignment not displayed immediately - Assigning a finding to yourself or another pentester is now shown correctly without requiring a page refresh.

  • PP-740: Explain why a comment could not be edited - When a comment has already been read and can therefore no longer be edited, PentestPortal now clearly explains why editing is unavailable instead of only showing the copy-link option.

We believe that PentestPortal will greatly enhance the experience of individual penetration testers, penetration testing firms and enterprises conducting their own pentests and that PentestPortal contributes to more efficient and effective penetration testing. Your feedback is invaluable in helping us improve and tailor the software to meet your needs.

Thank you for choosing our software, and we look forward to hearing your thoughts on this exciting new release!

Powered by LaunchNotes