Current Versions

Version Lifecycle-Status Patch-Level
OPENVAS SECURITY INTELLIGENCE 1.5 New 1.5.2 (2026-08-24)
OPENVAS SCAN 25.0 Mature 25.0.7 (2026-08-17)
OPENVAS SCAN 24.10 Mature 24.10.11 (2026-02-19)
OPENVAS OS 2.0 New 2.0.1 (2026-07-30)
OPENVAS OS 1.0 New 1.0.7 (2026-02-04)

Stay one step ahead with OPENVAS.

Receive the most important innovations, improvements and updates from Greenbone at a glance in your inbox. Sign up for our product newsletter and simply select the topics that interest you in the form.

Changelog

Here you can find the latest release notes.

2026-07-28: OPENVAS SECURITY INTELLIGENCE 1.5

Current Patch Level: 1.5.2 (2026-08-24)

Lifecycle Status: New

1.5.2 (2026-08-24):

  • Feature: Security Advisories from ENISA are now available (tech preview).
  • Feature: An “About” page with contact, version, and license information is now available.
  • Feature: The behavior of the “Cancel” button has been unified and improved.
  • Bug fix: Notifications with deleted channels are now highlighted.
  • Bug fix: New messages are now immediately available in notifications.
  • Bug fix: Tags are now removed from the asset when it is deleted from tag management.
  • Bug fix: The asset name is now always displayed on the “Assets” page.
  • Bug fix: The logic for updating tags skipped the wrong index when updating OpenSearch.
  • Bug fix: The display of badges now works as expected when data is transferred to OSI.
  • Miscellaneous: The UI library was updated to React 19.

1.5.1 (2026-08-11):

  • CycloneDx v1.7 support: SBOMs in the CycloneDx v1.7 format can be uploaded and analyzed
  • Dynamic tables: Users can now decide which columns they want to see for each table (completed)
  • SCAN Reports: User now sees a progress bar and is able to cancel the upload
  • SBOM: User now sees a progress bar and is able to cancel the upload
  • Bug fix: Import Reports Incorrect handling of container image reports with vulnerability results
  • Bug fix: Import Reports  – Missing system tag mapping on old OpenSearch indexes
  • Bug fix: SBOMUpload and scanning now works as expected
  • Bug fix: LogoutLogout after inactivity now works as expected
  • Bug fix: Tagging – Rule options are now visible after saving
  • Cosmetics: “Host name” → “Asset Name”

1.5.0 (2026-07-28):

  • Tag permissions: Administrators can now control access to resources based on assigned tags.
  • SCAN can send report data to OSI: OSI can now receive data from OPENVAS SCAN. (Requirement: OPENVAS SCAN 25.06 – still behind a feature flag).
  • Dynamic tables: Apart from the pages of the former REPORT-component users can now decide which columns they want to see for each table.
  • Bug fix: Action menu is now updated after bulk actions.
  • Bug fix: Exporting reports is now possible again.
  • Bug fix: Already deleted Assets are not shown any more in the respective overviews.
  • Bug fix: Missing or incomplete feed data of the appliances is not blocking the import of reports any more.

1.4.0 (2026-06-29):

  • Feature: The address of the web interface must be specified explicitly to increase security.
  • Feature: Table width on communication page has been increased.
  • Feature: On the page “Feed” we now display if a feed update is currently running and when the last feed update has been executed.
  • Feature: The progress of a support package download is now displayed using the browser’s standard mechanisms.
  • Feature: The SBOM features are now located on two pages. One for displaying the reports and one for managing the SBOMs itself.
  • Bug: Changed SSO Session idle time so that the display of the remaining time and the automatic logout work as intended.
  • Bug: Encrypted support package has now “.zip.gpg” file extension when downloaded.
  • Bug: Spaces in compound words were fixed.
  • Bug: Users were shown pages with no content that they did not have permission to view.

1.3.0 (2026-05-18):

  • Feature: Restructred side navigstion
  • Feature: Integration of keycloak as system for user management.
  • Enhancement: Tagging rules can be executed immediately.
  • Enhancement: The deletion of a tagging rule has to be confirmed now.
  • Bug fix: The behaviour of the logout counter has been fixed on certain pages.
  • Bug fix: All CVE’s are enriched with EPSS data.
  • Bug fix: Various translations were fixed.

1.2.0 (2026-04-07):

  • Enhancement: Administrators can now freely define which system events should trigger the publication of corresponding messages on configurable communication channels (#ARTOSI-104, #ARTOSI-105, #ARTOSI-108)
  • Enhancement: EPSS metrics are now also displayed in CSAF advisories (#ARTOSI-109)
  • Enhancement: Created support packages can now be deleted either individually or via a bulk action. Downloaded support packages are automatically deleted after 30 days (#ARTOSI-96, #ARTOSI-97, #ARTOSI-128)
  • Enhancement: You can now create tagging rules for assets based on their filter criteria. These automatically assign tags to assets as soon as the filter criteria are met. Administrators can also assign “system tags”: These can be used in the next version of OPENVAS SECURITY INTELLIGENCE to control permissions with fine granularity (#ARTOSI-159)
  • Improvement: If you have defined a filter in the dashboard and then select an entry in the “Top 10 Most Vulnerable Assets” list, the filter criteria are carried over to the asset’s detail view, allowing you to further refine them (#ARTOSI-62)
  • Bugfix: Several translation errors have been fixed.

1.1.0 (2026-03-03):

  • Enhancement: If there is an EUVD entry for a CVE, the corresponding reference to the EUVD is also displayed (#VTI-731), (#VTI-729)
  • Enhancement: Original CSAF data is enriched with the information if a related CVE is currently exploited. Information is provided by the “Known Exploited Vulnerabilities Catalog” (#VTI-637)
  • Enhancement: Enhancement: The CVE information has been enriched with daily updated EPSS metrics (#VTI-686), (#VTI-688)
  • Enhancement: In “System Control” a self-check can now be initiated on a connected appliance (#T5-1165)
  • Enhancement: In “System Control” a support package can now be initiated and downloaded on a connected appliance(#T5-1786), (#T5-1202)
  • Improvement: In “System Control” appliances can now also be easily added by host name or IP address (#T5-1717)
  • Bug fix: Fixed an issue that prevented critical vulnerabilities from being imported when the connected appliance runs a GOS-version equal/ greater than 24.10.7 (#AT-2943)
    Note: After installing the latest version of OPENVAS SECURITY INTELLIGENCE, you may need to reconnect the appliances from which you import data so that critical vulnerabilities are taken into account again during the next import.
  • Bug fix: Fixed an issue that caused an error when the PDF-report “Management summary with details” was exported (#AT-2932)