ZAP by Checkmarx

@zaproxy.org

The Worlds Most Popular Web App Scanner.

An Insecure Java Deserialization vulnerability has been reported in a ZAP add-on via Neo by ProjectDiscovery. Update your ZAP add-ons now, and definitely update from older versions of ZAP. For more details see: www.zaproxy.org/blog/2026-06...

Java Deserialization Vulnerability in ZAP Viewstate Add-on

A Java Deserialization Vulnerability has been found in the ZAP Viewstate Add-on. Update your ZAP add-ons now, and if you are on an older version of ZAP then update that ASAP.

zaproxy.org

New ZAP Blog Post: www.zaproxy.org/blog/2026-03... This post describes an approach that uses static analysis findings to guide ZAP’s active scans toward the most relevant endpoints. The result is a faster scanning mode suited for CI/CD pipelines. Thanks to the Seqra Team! #zaproxy #appsec

Guided ZAP Scans: Faster CI/CD Feedback Using Static Analysis

This post describes an approach that uses static analysis findings to guide ZAP’s active scans toward the most relevant endpoints. The result is a faster scanning mode suited for CI/CD pipelines, buil...

zaproxy.org