ZAP by Checkmarx
banner
zaproxy.org
ZAP by Checkmarx
@zaproxy.org
The Worlds Most Popular Web App Scanner.
The latest weekly release does not include the AJAX Spider and DOM XSS add-ons.
You can install them via the Marketplace as usual, but we recommend you using the Client Spider and OWASP PTK add-ons instead.
For more details see www.zaproxy.org/blog/2026-09...
#zaproxy #appsec
ZAP Updates - August 2026
We’re retiring the AJAX Spider and DOM XSS add-ons from the nightly and weekly releases, and the new LLM Support add-on officially launched in August.
www.zaproxy.org
September 15, 2026 at 10:13 AM
ZAP updates for August.
We’re removing 2 add-ons from the nightly and weekly releases, so if you use those then make sure you read it to understand the implications.
www.zaproxy.org/blog/2026-09...
#zaproxy #appsec
ZAP Updates - August 2026
We’re retiring the AJAX Spider and DOM XSS add-ons from the nightly and weekly releases, and the new LLM Support add-on officially launched in August.
www.zaproxy.org
September 8, 2026 at 1:39 PM
Reposted by ZAP by Checkmarx
What's this? @zaproxy.org fuzzer update released this morning, with work from yours truly.

#PenTest #WebAppSec #BugBountyTips
August 7, 2026 at 2:18 PM
Introducing ZAP LLM Support:
www.zaproxy.org/blog/2026-08...
A new optional, opt-in add-on that lets you connect ZAP to an LLM of your choice.
#zaproxy #appsec
The ZAP LLM Support Add-on
A new optional, opt-in add-on that lets you connect ZAP to an LLM of your choice, powering an interactive chat panel and AI-assisted features in the OpenAPI and Alert Filters add-ons.
www.zaproxy.org
August 7, 2026 at 2:40 PM
www.zaproxy.org/blog/2026-08... - a huge increase in the number of times ZAP was started, and we now recommend using the Client Spider instead of the AJAX Spider
#zaproxy #appsec
ZAP Updates - July 2026
ZAP was started more than 13 million times in July, another big jump, and the Client Spider officially became our recommended option for crawling modern web apps.
www.zaproxy.org
August 6, 2026 at 2:27 PM
Big announcement!
We now recommend that you use the Client Spider for crawling modern web apps, instead of the AJAX Spider.
More details in the blog post:
www.zaproxy.org/blog/2026-07...
#zaproxy #appsec
Use the Client Spider for Modern Web Apps
We now recommend the Client Spider over the AJAX Spider for crawling modern web applications. It finds more endpoints, scales much better vs large apps, and unlocks PTK’s passive coverage for free.
www.zaproxy.org
July 6, 2026 at 3:27 PM
ZAP Blog: June Updates
www.zaproxy.org/blog/2026-07...
More PTK integration, lots of Client Spider improvements, and much more..
#zaproxy #appsec
ZAP Updates - June 2026
In June the OWASP PTK add-on graduated to beta with its integration now properly matching ZAP’s architecture, a security advisory was issued and patched for the Viewstate add-on, and the Client Spider...
www.zaproxy.org
July 1, 2026 at 12:01 PM
Blog Post: Even More OWASP PTK Integration with ZAP.
SAST and IAST passive scanning out of the box with the Client Spider, and the active rule is now enabled by default.
www.zaproxy.org/blog/2026-06...
#zaproxy #owaspptk #appsec
Even More OWASP PTK Integration with ZAP
The PTK add-on graduates to beta, the active scan rule is on by default, recommended rule defaults reduce noise by avoiding duplicate findings, and a new Engines tab gives you fine-grained control ove...
www.zaproxy.org
June 29, 2026 at 4:55 PM
An Insecure Java Deserialization vulnerability has been reported in a ZAP add-on via Neo by ProjectDiscovery.

Update your ZAP add-ons now, and definitely update from older versions of ZAP.

For more details see: www.zaproxy.org/blog/2026-06...
Java Deserialization Vulnerability in ZAP Viewstate Add-on
A Java Deserialization Vulnerability has been found in the ZAP Viewstate Add-on. Update your ZAP add-ons now, and if you are on an older version of ZAP then update that ASAP.
www.zaproxy.org
June 24, 2026 at 2:52 PM
ZAP now has a dedicated PTK active scan rule, so you can run the PTK rules in the ZAP active scanner.
Check out the dramatic improvement in the scores vs Google Firing Range!
www.zaproxy.org/blog/2026-06...
#zaproxy #owaspptk #appsec
Automating OWASP PTK with ZAP (Phase 2)
ZAP now has a dedicated PTK active scan rule, so you can run the PTK rules in the ZAP active scanner. And there are still more changes planned, but the results against Firing Range have been dramatic!
www.zaproxy.org
June 5, 2026 at 10:31 AM
In May ZAP learned to scan MCP servers as a first-class target, OWASP PTK automation reached Phase 1, and the Params extension moved out of the core into its own add-on.
www.zaproxy.org/blog/2026-06...
#zaproxy #appsec
ZAP Updates - May 2026
In May ZAP learned to scan MCP servers as a first-class target, OWASP PTK automation reached Phase 1, and the Params extension moved out of the core into its own add-on.
www.zaproxy.org
June 2, 2026 at 1:19 PM
ZAP can now scan MCP Servers, in the Desktop, Automation Framework and in a new GitHub Action.
Read all about it on the blog:
www.zaproxy.org/blog/2026-05...
#zaproxy #appsec #mcp
Scanning MCP Servers with ZAP
ZAP can now scan MCP (Model Context Protocol) servers as a first-class target. Import an MCP server from the ZAP desktop or the Automation Framework, or run the new action-mcp-scan GitHub Action to sc...
www.zaproxy.org
May 21, 2026 at 4:49 PM
Blog: Automating OWASP PTK with ZAP (Phase 1)
You can now automate OWASP pentestkit using ZAP
www.zaproxy.org/blog/2026-05...
#zaproxy #owasp-ptk #appsec
Automating OWASP PTK with ZAP (Phase 1)
ZAP’s Automation Framework can now drive OWASP PTK scans using the Client Spider. This is an early release - we want you to try it and give us feedback while we work toward deeper integration with ZAP...
www.zaproxy.org
May 6, 2026 at 4:17 PM
Blog: Vibe coding security fixes.
www.zaproxy.org/blog/2026-04...
Learn how ZAP can help you make your vibe coded projects more secure.
#zaproxy #vibecoding #appsec
Vibe Coding Security Fixes
ZAP now has a “Generate Fix Prompt” option that copies everything an LLM needs to fix a vulnerability straight to your clipboard. Also: ZAP was run 9.5 million times in March. Vibe coding, anyone?
www.zaproxy.org
April 15, 2026 at 4:33 PM
Guest Blog: www.zaproxy.org/blog/2026-04...
Learn how to integrate ZAP with KRO in a Kubernetes cluster to scan the security of each new deployment.
℅ Trevor Mountney
#zaproxy #kubernetes #appsec
Use ZAP with KRO in Kubernetes
Learn how to integrate ZAP with KRO in a Kubernetes cluster to scan the security of each new deployment.
www.zaproxy.org
April 14, 2026 at 3:11 PM
Blog: ZAP Updates for March:
www.zaproxy.org/blog/2026-04...
ZAP was started 9.5 MILLION times .. and we announced significant collaborations with other open source projects
#zaproxy #appsec
ZAP Updates - March 2026
ZAP was started nearly 9.5 million times in March, published integrations with 3 other open source projects, and released the first of many AI related features.
www.zaproxy.org
April 3, 2026 at 10:01 AM
This is huge!
www.zaproxy.org/blog/2026-04...
OWASP PTK massively increases ZAP’s browser side testing capabilities .. and automation is up next!
Many thanks to Denis Podgurskii for this great integration.
#zaproxy #owasp #appsec
OWASP PTK Findings as ZAP Alerts (Juice Shop Walkthrough)
OWASP PTK 9.8.0 and the ZAP OWASP PTK add-on 0.3.0 now let ZAP display OWASP PTK findings directly as ZAP Alerts. This post shows how to install the add-on, choose which PTK rules to run (SAST / IAST ...
www.zaproxy.org
April 1, 2026 at 10:03 AM
New ZAP Blog Post: www.zaproxy.org/blog/2026-03...
This post describes an approach that uses static analysis findings to guide ZAP’s active scans toward the most relevant endpoints. The result is a faster scanning mode suited for CI/CD pipelines.
Thanks to the Seqra Team!
#zaproxy #appsec
Guided ZAP Scans: Faster CI/CD Feedback Using Static Analysis
This post describes an approach that uses static analysis findings to guide ZAP’s active scans toward the most relevant endpoints. The result is a faster scanning mode suited for CI/CD pipelines, buil...
www.zaproxy.org
March 27, 2026 at 4:08 PM
New ZAP Blog Post: Introducing DeepViolet: The Engine Behind ZAP’s New TLS Analysis
www.zaproxy.org/blog/2026-03...
Thanks to Milton Smith
#zaproxy #deepviolet #appsec
Introducing DeepViolet
Introducing DeepViolet: The Engine Behind ZAP’s New TLS Analysis
www.zaproxy.org
March 19, 2026 at 11:50 AM
Do you need even more control over the browsers that you can launch from ZAP?
You’ve got it!
www.zaproxy.org/blog/2026-02...
#zaproxy #appsec
Custom Browsers and Preferences
You can now add custom browsers to ZAP and manage any browser preferences.
www.zaproxy.org
February 25, 2026 at 9:49 AM
Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
www.zaproxy.org/blog/2026-02...
#zaproxy #appsec #cyberchef
Using ZAP's Encode/Decode/Hash Add-on with CyberChef via Encode/Decode Scripts
Combine the Encode/Decode/Hash add-on with CyberChef operations in ZAP Encode/Decode Scripts for flexible encoding, decoding, and hashing in your testing workflow.
www.zaproxy.org
February 17, 2026 at 5:06 PM
New Blog Post: Detecting Circular Type References in GraphQL Schemas
www.zaproxy.org/blog/2026-02...
#zaproxy #appsec #graphql
Detecting Circular Type References in GraphQL Schemas
ZAP can now detect cycles in GraphQL schemas that could lead to denial of service attacks.
www.zaproxy.org
February 6, 2026 at 12:27 PM