Mondoo Release Highlights August 2026
Introduction
Your databases hold the data every other control exists to protect, and they are where security tooling across the industry goes quiet. Nearly every scanner stops at the host and never asks the database itself who it authenticates, what it grants, or which network paths it opens. This month you can. August brings 14 new database providers, 13 new CIS database benchmarks, and twelve new Mondoo database security policies.
Databases are only the start. Every other part of Mondoo got better this month too. Nearly 30 new CIS and STIG policies landed, the largest benchmark release we have ever shipped, and 2,000+ new security checks arrived across the policy library. Despite all that new coverage, your cloud scans now run up to 5x faster, and Mondoo detects 600+ new applications from 15 new advisory sources. Let's dive in.
Your Databases Are Now First-Class Assets
Everything that makes a database secure lives inside the database itself, out of reach of any host scan. This month Mondoo reaches inside.
14 new database providers ship this month, and each one connects over a read-only connection and models the running server:
- PostgreSQL: roles, databases, schemas, tables, privileges, host-based authentication rules, extensions, replication state, and every runtime parameter, with pgvector detected per database so you know exactly where your embeddings live.
- MySQL and MariaDB: users, privileges, schemas, tables, routines, plugins, replication channels, and server variables.
- Microsoft SQL Server: logins, server and database roles, permissions, audits, backups, credentials, encryption keys, linked servers, and server configuration.
- Oracle Database: users, roles, profiles, and every initialization parameter, so the password policy a profile actually enforces is directly checkable.
- IBM Db2: database authorities, roles, privileges on tables, table spaces, and routines, audit policies, configuration parameters, and registry variables.
- MongoDB: users, roles and their privileges, databases, and server parameters.
- Apache Cassandra: the cluster and its nodes, keyspaces, roles and their permissions, and security settings.
- Redis and Valkey: ACL users, configuration, and the running instance.
- Elasticsearch and OpenSearch: cluster security settings, users, roles and their index privileges, role mappings, and API keys.
- ClickHouse: users, roles, quotas, settings profiles, and server settings. ClickHouse Cloud adds organizations, members, services, endpoints, IP access lists, and API keys.
- Weaviate: collections, nodes, users, and roles and their permissions.
- Neon: organizations and members, projects, branches, databases, roles, endpoints, VPC endpoints, and API keys.
Twelve new Mondoo database security policies ship with them: MySQL (39 checks), MariaDB (37), PostgreSQL (33), Neon (11), and ClickHouse Cloud (10), plus starter policies for Microsoft SQL Server, MongoDB, Cassandra, Elasticsearch, OpenSearch, Redis, and ClickHouse.
And because a database is only as safe as the benchmark you hold it to, the same month brings the CIS coverage to match.
28 New CIS and STIG Benchmarks
This is the largest benchmark release we have ever shipped: 28 new benchmarks carrying 1,368 checks, plus 30 more checks added to benchmarks you already run.
Databases (13 benchmarks, 515 checks)
| Benchmark | Checks |
|---|---|
| CIS Oracle Database 23ai v1.1.0 | 51 |
| CIS Oracle Database 26ai v1.0.0 | 51 |
| CIS Oracle MySQL Enterprise Edition 8.4 and 9.7 v1.0.0 | 48 each |
| CIS Oracle MySQL Community Server 8.0 v1.1.0 | 47 |
| CIS Oracle MySQL Community Server 8.4 v1.1.0 and 9.7 v1.0.0 | 45 each |
| CIS PostgreSQL 17 v1.1.0 and 18 v1.0.0 | 40 each |
| CIS Microsoft SQL Server 2019 v1.5.0 | 37 |
| CIS MongoDB 8 v1.0.0 | 33 |
| CIS Snowflake Foundations v2.0.0 | 22 |
| CIS Apache Cassandra 5.0 v1.1.0 | 8 |
Application servers and services (6 benchmarks, 285 checks)
- CIS Apache Tomcat Application Server 9 STIG v1.1.0 (64 checks)
- CIS Apache Tomcat 10.1 v1.2.0 (55) and Tomcat 11 v1.1.0 (53)
- CIS JBoss Enterprise Application Platform 6.3 STIG v1.0.0 (52)
- CIS Apache Server 2.4 UNIX Server STIG v1.0.0 (31)
- CIS BIND 9.x STIG v1.0.0 (30)
Desktop and endpoint (5 benchmarks, 441 checks)
- CIS Microsoft Edge v4.0.0 (139 checks) and CIS Microsoft Intune for Edge v1.0.0 (138)
- CIS Microsoft Office 365 ProPlus STIG v1.1.0 (128)
- CIS Mozilla Firefox STIG v1.1.0 (31)
- CIS Visual Studio Code GPO v1.0.0 (5)
Cloud and network (4 benchmarks, 127 checks)
- CIS Alibaba Cloud Foundation v2.0.0 (44 checks)
- CIS Microsoft Azure Storage Services v2.0.0 (37)
- CIS Arista EOS v1.0.0 (33)
- CIS DigitalOcean Services v1.0.0 (13)
25 new CIS certifications accompany them, taking our certified benchmark count from 82 to 107. Certification means CIS themselves validated that our implementation matches the benchmark, so the report you hand an auditor carries their sign-off, not just ours.
We also converted previously manual checks to automated ones across benchmarks you already run: 13 in CIS Microsoft Azure Foundations, 10 in CIS AWS Database Services, and 3 each in CIS Azure AKS and CIS AWS End User Compute Services. Every one of those is a row in an audit spreadsheet that somebody used to fill in by hand.
The Application Server and Middleware Layer
New benchmarks are only worth as much as the data behind them, so the resources that make those Tomcat, JBoss, BIND, and Firefox checks real landed in the same month. The layer between your operating system and your application is now assessable end to end:
tomcatandjboss, backing the four new application server benchmarks.bind9, readingnamed.confand reaching the key files a BIND server depends on.firefox.policies, for enterprise policy audits on managed browsers.java.keystore, so trust store contents are auditable.podman, for container workload audits on hosts that are not running Docker.systemd.unit, for service confinement audits: which units run privileged, which have their capabilities dropped, which are sandboxed.aidefor file integrity monitoring andpolkitfor authorization policy.cassandra.conf,cassandra.env, andcassandra.rackdc, for auditing an Apache Cassandra node's configuration straight from the files on disk.ovs, for Open vSwitch topology.sriov, for physical and virtual function state.
Eight New Identity, SaaS, and DevOps Platforms
Your identity provider decides who gets into everything else, and your artifact repository decides what reaches production. Both are now in scope:
- Auth0 and Keycloak, the two identity platforms most likely to be sitting in front of your own applications.
- JumpCloud, covering directory and device management together.
- JFrog Artifactory, the largest of the new providers: repositories and their replication, Xray watches, policies and ignore rules, projects and their members, identity integrations, and backups.
- Netlify for sites and deploys, with a Mondoo Netlify Security policy.
- Bitwarden, Zoom, and Dropbox Business, so the SaaS your staff use every day is inventoried rather than assumed.
A new Mondoo HashiCorp Cloud Platform Security policy joins them, and Mondoo Neon Security covers the serverless Postgres platform.
Every one of them is scannable from the command line with cnspec; see everything cnspec can scan for the full list.
Altogether, MQL gained 777 new resources and 5,661 new fields this month, taking it past 5,300 total resources.
600+ New Applications in the Mondoo Vulnerability Database
The software your staff install is where a large share of real exposure lives, and it is the part of the fleet most vulnerability tools ignore entirely. In July we added coverage for over 100 applications. This month we added 600+ more, several times last month's pace.
The new coverage runs from the exposed web and proxy tier to the tools your staff run every day: Apache HTTP Server, NGINX, and HAProxy, plus VirtualBox, Elasticsearch, DBeaver, XAMPP, MobaXterm, Cerberus FTP Server, Delinea Secret Server, SAP GUI for Windows, Palo Alto GlobalProtect, Cortex XDR Agent, Tenable Nessus Agent, Veeam Backup & Replication, VMware Horizon Client, RealVNC Server and Viewer, Commvault, Netwrix Auditor, SolidWorks, Wazuh Agent, and many more. Each one resolves an installed copy to a vendor, a product, its known vulnerabilities, and an upgrade path, so software that used to appear in your inventory as an unattributed string now has an identity and a fix. Printers, cameras, NAS appliances, and network gear got their own coverage too, described further below.
15 new advisory sources landed as well, taking us from 47 to 62:
- National CERTs and government: CISA advisories, BSI CERT-Bund (Germany), NCSC-NL (Netherlands), JVN iPedia (Japan), the EU Vulnerability Database, and CERT@VDE for industrial systems.
- Vendor PSIRTs: Siemens ProductCERT, HPE, Brother, Konica Minolta, Lexmark, Ricoh, and curl.se.
- CSAF and ROLIE feed listers, so onboarding the next vendor PSIRT is cheap rather than bespoke.
We also added the EU KEV as a source of exploited-in-the-wild intelligence, joining CISA KEV, VulnCheck KEV, Google Project Zero, Metasploit, and inthewild.io.
Scans Got Dramatically Faster
Speed is a correctness feature when your API throttles. A scan that spends its budget on calls it did not need is a scan that gets rate-limited, backs off, and finishes late or not at all. This month we went looking for those calls with a request trace rather than a code review, and found a great many.
| Provider | Before | After | Change |
|---|---|---|---|
| GitLab | 149 calls | 5 | 96.6% fewer |
| Azure, per reference query | 67 ARM calls | 9 | 87% fewer |
| ms365, registration details | 58 calls | 10 | 83% fewer |
| AWS | 9,558 calls | 1,833 | 80.8% fewer |
| ms365, worst-path query | 123 seconds | 24 seconds | 80% faster |
| GCP | 2,651 calls | 1,113 | 58.0% fewer |
| Okta | 7 calls | 3 | 57% fewer |
| GitHub | 1,291 calls | 1,049 | 18.7% fewer |
One approach produced all of it: advanced caching and precise fetching that ask each API only for what a check actually needs and never pay twice for the same answer. Coupled with parallelism, now on by default for hosted AWS, GCP, Azure, host, and GitLab scans and configurable per integration, that efficiency turns directly into faster scans.
Your Printers, Cameras, and Network Gear Are Now Assessed
Every office has a hundred devices nobody patches, running firmware nobody inventories, on the same network as everything else. This month they became assets.
26 new device and firmware families now match CVEs:
- Printers and MFPs from Brother, Canon, Dell, Epson, FUJIFILM, HP, Konica Minolta, Kyocera, Lexmark, OKI, Ricoh, Samsung, Sharp, Xerox, and Zebra.
- Cameras from Axis and Hikvision.
- NAS appliances from QNAP and Synology.
- Network devices from AVM, DrayTek, Netgear, TP-Link, Ubiquiti, and Zyxel.
- HPE iLO management controllers.
Making that work took real matching machinery: printer PURLs are matched to CVE data through NVD hardware CPEs, device matching was extended beyond printers to routers, NAS, cameras, and access points, and vendor firmware matrices are read straight from the vendor's own PDF so a fix maps to the specific model it applies to. Brother alone contributed 443 bounded firmware entries.
Windows print drivers became first-class at the same time. A new windows.printerDrivers resource reports what is installed, each driver carries a pkg:windows-driver purl keyed on its hardware ID, drivers ride the SBOM, and print-driver CVEs match through that purl. The driver layer went from invisible to inventoried and assessed.
FortiOS gained 23 new resources in the same window, taking a FortiGate audit well past firmware version checks. Antivirus profiles and their per-protocol settings, application control lists and their entries, and DNS filter profiles are all readable now, as are SNMP communities and users, the password policy, the Security Fabric with its fabric connectors and trusted list entries, automation stitches, automatic update schedules, and log event filters. Your firewall is no longer a device you scan only for CVEs; its policy surface is assessable too.
Every CVE Finding Now Shows Its Evidence
A CVE reported against an asset where you never installed the package is easy to dismiss. Findings from external attack surface scanning are detected passively, from the outside, so there is no package manifest standing behind them. Until this month the finding page had nothing to show for that: no evidence at all, and an empty "no matching packages" warning that made a real finding look like a defect in the scanner.
Every CVE and advisory finding now renders its full evidence. The network connection that produced the detection, with host, port, and protocol. The HTTP request behind it. Process, file, and registry evidence where the detection came from inside the asset. Each piece carries its confidence level and the source that produced it, presented in the same evidence cards the rest of the product already uses, so a passively detected CVE becomes something you can verify instead of something you have to take on faith.
The empty package warning went away with it. A network-detected finding legitimately has no package linkage, and the evidence is what carries the verification instead.
Official Mondoo Apps on Splunkbase
Splunk gets its own answer this month. Two Mondoo apps are now published on Splunkbase, so a team that runs Splunk no longer has to write a collector and rebuild the same handful of dashboards before Mondoo data is useful.
Mondoo Add-On (TA) for Splunk does the collecting. A modular input polls your space through the Mondoo API on a schedule for audit events, security advisories, and registered agents, and a file monitor ingests JSONL exports from the Mondoo ETL runner, routing assets, vulnerabilities, checks, controls, packages, and queries to their own sourcetypes by filename. Events are tagged and field-aliased for the Splunk Common Information Model, so they populate the Vulnerabilities, Change, Inventory, and Alerts data models and work with the CIM-based apps and correlation searches you already run. Pagination is checkpointed and resumable, so a restart neither duplicates nor loses events. Rate limits and transient errors retry with exponential backoff, outbound proxies and custom CA bundles are supported, and bearer tokens are scrubbed from every log line, so diagnostic output is safe to attach to a support ticket. Requires Splunk Enterprise 9.0 or later.
Mondoo App for Splunk Enterprise ships the dashboards: Assets, Vulnerabilities, Checks, Queries, Audit, and a Data Information view that tells you whether your data is actually landing. Five saved searches come with it, all disabled by default so installing the app never starts scheduled work you didn't ask for: critical open vulnerabilities by asset, stale assets, failed checks by severity, recent audit activity, and an alert on new critical CVE findings. Every dashboard resolves its index through a single mondoo_index macro, so pointing the whole app at a different index is a one-line edit, and further macros ship as building blocks for your own searches. Requires Splunk Enterprise 9.3 or later.
Both are Apache-2.0 licensed and Splunk Cloud compatible. Install the add-on in exactly one place, a heavy forwarder or your search head, and the dashboard app on your search heads.
500+ New Cloud and SaaS Security Checks
Beyond the new platforms, the policies you already run got substantially deeper. 500+ new checks landed in existing Mondoo security policies:
- AWS Security: 122 new checks
- STACKIT Security: 103 new checks, nearly doubling the policy
- Databricks Security: 101 new checks, taking it from 25 to 126
- Alibaba Cloud Security: 94 new checks
- OCI Security: 46 new checks
- Vercel Security: 43 new checks
- GCP Security: 16 new checks
- DigitalOcean, NextDNS, Windows, Azure, vSphere, Grafana, FreeBSD, and GitHub: 20 more between them
A New Windows Update Readiness Policy
A host that has stopped patching does not announce it. When the Windows Update Agent cannot start or cannot finish a detection scan, it returns an empty result set rather than an error, so Get-WindowsUpdate, the Settings app, and the management tooling that drives the agent all agree there is nothing to install. The host reads as compliant right up until an audit counts its build number.
The new Mondoo Windows Update Readiness Policy closes that blind spot with 16 checks grouped by failure mode:
- Update agent and service health:
wuauservis installed and startable, its svchost registration is intact, and the supporting services that download and commit packages are not disabled. - Update agent liveness: the host installed updates recently, the agent can enumerate its catalog, and it reports no detection error.
- Update policy and configuration: automatic updates are not turned off, updates are not paused, deferral windows stay bounded, and a reachable catalog source is configured.
- Servicing stack capacity: no pending reboot blocks the next package, the datastore directories exist, the component store is healthy, and the system drive has room for a cumulative update.
Because these checks target the update mechanism rather than the update inventory, they surface the hosts whose patch level has silently frozen. Pair the policy with a vulnerability scan and a host that fails here explains a host that is behind there.
Expanded Linux Distribution Support
Mondoo now identifies 13 more Linux distributions by name: Talos, openSUSE MicroOS, Container-Optimized OS, Bottlerocket, Clear Linux, Void Linux, Manjaro ARM, ALT Linux, CloudLinux, Anolis OS, OpenCloudOS, deepin, and openKylin, and eLxr now resolves inside the Debian family. Each reports its own name and version, and the ones with a lineage inherit it, so CloudLinux picks up the Red Hat checks and advisories you already run with no further work.
Four of them are immutable container hosts: Talos, Bottlerocket, Container-Optimized OS, and openSUSE MicroOS. Those are exactly the systems nobody can shell into and inspect by hand, which is why having them as first-class assets matters more than their share of a fleet suggests.
Your Exceptions Now Have Names
An exception is a decision. Somebody looked at a finding and judged that the risk is accepted, that a workaround is already in place, that it is a false positive, or that the check should be disabled because it breaks something here. That decision is only worth recording if you can find it again six months later, and until this month a long exception list read as a wall of identifiers.
An exception can carry a name. Give it an optional custom name when you create it, and the list reads like a decision log rather than a set of opaque ids.

You can search for one by name. Exception groups filter by name or id, so retrieving the decision your team made last quarter takes a search box rather than a scroll.
Inherited exceptions appear in context. An asset's Exceptions tab now always lists the space-wide exception groups that apply to that asset alongside its own, each marked with a scope badge, so you can see why something is suppressed without leaving the page. Inherited rows stay read-only on the asset, and opening one takes you to the space exceptions page where the decision actually lives.
A Notification Feed for Every User
Being added to an organization, a space, or a team happens directly. There is no invitation to accept, so until this month an email was the only thing that told you it had happened, and email is easy to miss.
Every user now has a notification bell. It sits in the sidebar footer, carries a badge counting what you have not read, and opens a panel listing what has happened to your account, newest first. There is nothing to turn on and nothing to configure.

Each notification names the organization, space, or team you were added to, who added you, and the roles you were granted. If somebody added you by email address before you had a Mondoo account, that membership is waiting in the bell the moment you arrive. The feed keeps 90 days, and membership is where it starts rather than where it stops.
Quality-of-Life Improvements
A number of smaller additions this month that make everyday work smoother:
- Filtering: Asset findings filter by status, an assessment's findings open straight into a filtered findings view, and the Platform filter no longer appears on finding detail pages, where it never did anything.
- Markdown in findings: Finding descriptions render as Markdown instead of flattened text, and so do descriptions imported from Qualys.
- Scoring transparency: Assets expose their scan provenance and a scoring-in-progress signal.
- Jira: The ticket issue type is now configurable.
- Reporting: CVE occurrences and average risk value join the BI measures, EOL metrics roll up to organization scope, and the organization summary carries a seven-day risk band trend.
- Improved IaC content in policies: Extensive new policy testing for infrastructure as code content, so the Terraform, CloudFormation, and Bicep remediations our policies ship keep targeting the latest capabilities each vendor supports.
- Terraform: Variable resolution, introduced last month, now ships enabled rather than gated, so
var.*andlocal.*references resolve to their effective values on every scan. - Kubernetes: Network exposures are attributed to the workloads backing exposed pods, and serving-container image IDs are exported for internet-exposed pods.
Community Spotlight: Maximilian Rink
A lot of what made scans faster this month came from outside Mondoo. Maximilian Rink contributed both features and performance work across the codebase, and it is worth calling out by name.
On the performance side, his work targeted the hot paths that every single scan runs through: sizing tar read buffers from the entry header rather than guessing, sharing one string between the tar file map key and the header name instead of allocating twice, and replacing regular expressions with direct field splitting in both the dpkg and apk database parsers. Package parsing happens thousands of times per scan, so removing a regex from that loop is felt on every Linux and Alpine asset you own.
He also shipped features. The Keycloak provider and the JFrog Artifactory provider, two of this month's new platforms, are both his, along with Artifactory's Xray watches, policies and ignore rules, repository replication, projects and members, identity integrations, and backups. So are the Redfish BMC security posture resources, the Open vSwitch and SR-IOV operating system resources, and Kubernetes dynamic resource allocation objects.
Thank you, Max, for making this an amazing open source experience!
And There's Even More
Beyond the highlights above, August brought a long list of smaller improvements throughout the product, too many to call out individually. And we're already hard at work on what's next, so look for more new functionality next month.