New vulnerabilities matching algorithm
27 July 2026
The ShadowTrackr internal CVE database has been updated and augmented with new information. This allows us to better track and help you prioritise your risks from vulnerabilities. Check out our new
Vulnerability management documentation to learn more.
A big part of the update is the
ShadowTrackr CVSS Score. It is a CVSS v4 score, but unlike like the MITRE and NVD score we keep the threat group value (Exploit maturity) included in the final score. If a PoC exists or active attacks are known, the score will be higher. If not, it will be lower. We track a lot of sources for exploit status to keep the score accurate.
If you want, you can query our internal cves index for specific fields in the CVSS v4 vectorstring, or you can check our logs of changes to a CVE (when was an exploit found, when did CISA include it in the KEV, etc.). These options are also avaible for your
cves_assets index.
The algorithm matching your software against vulnerabilities has also improved. It can find more complex matches and has less false positives. You might notice a different number of CVEs found in this weeks reports.
Branded PDF reports
06 July 2026
The option to customize all pdf reports that ShadowTrackr sends is now available by default for all multi-tenant accounts. Look under Group settings in the left hand menu, and you'll find
Branding
You can set your own logo instead of the ShadowTrackr logo, and even change the default ShadowTrackr color in the pdf to match your brand. This is especially useful for MSSPs.
Revamped alerts GUI
29 June 2026
The alerts GUI has undergone a major UX upgrade. While working on a query for an alert, you can now see the live results. This will make it easier to fine tune it.
The actions to take (send emails, call webhooks) have moved to a second tab to clear up the screen. You can still send alerts to any email account, even if they are not ShadowTrackr users.
There is also a third tab where you can select the fields you want to include in the results that are sent. The default fields are preselected. It was possible to do this before with advanced query syntax, but seeing which fields are available and ticking the boxes for the ones you want is just much easier.
The email format has changed a bit and should allow you to better interpret the alert context.
Some of these improvements, like the email format and third tab to select output fields, have been added to the reports GUI as well.