Stay up-to-date with enhancements, bug fixes, and other changes to AMP, AMP Spider (Crawler), Access Assistant, and Testing SDKs.
Check out the latest updates below!
On this page:
Version 9.71
Released on September 10, 2026.
We made the following improvements:
Upgraded Access Engine to Version 2.30.
Support link is now functional as expected.
This release includes usability and accessibility fixes, and CVE remediation. We resolved issues pertaining to:
CVE-2026-69246
CVE-2026-69245
Version 9.70
Released on July 30, 2026
This release includes usability and accessibility fixes, and CVE remediation.
Access Continuum token rotation message is now announced by Assistive Technology.
We added the Last Updated timestamp column to reports.
PDF rules with zero BPs mapped now show as 100% in the compliance table.
Resolved SQL security flaw in the Move Report function.
Resolved SQL security flaw in the XML report module export function.
System admin users can no longer clone media types and break AMP to Level Access Platform (LAP) data transfers.
Compliance calculations now correctly account for 508 reference rules.
Cloudsmith token rotation now reflected in AMP user interface.
We provided CVE remediation for:
CVE-2026-46644
CVE-2026-49283
CVE-2026-49289
CVE-2026-55766
CVE-2026-55568
CVE-2026-55767
CVE-2026-48998
CVE-2026-49214
CVE-2026-55766
CVE-2025-13462
CVE-2025-69534
CVE-2026-1299
CVE-2026-1502
CVE-2026-2297
CVE-2026-3276
CVE-2026-3644
CVE-2026-4224
CVE-2026-4519
CVE-2026-4786
CVE-2026-6019
CVE-2026-6100
CVE-2026-7774
CVE-2026-8328
CVE-2026-9669
CVE-2025-7425
CVE-2026-45065
CVE-2026-48736
CVE-2026-24425
CVE-2026-46629
CVE-2026-46633
CVE-2026-46635
CVE-2026-46638
CVE-2026-48806
CVE-2014-5459
We've provided fixes for the following packages:
GHSA-2jx3-65f3-xr8r
GHSA-g7m4-839x-ch6v
Version 9.69
Released on June 11th, 2026.
This release includes usability and accessibility fixes in AMP plus several FedRAMP-focused security package patches (CVE remediation). There are no new new end-user features.
We've added these improvements:
The Organization Usage Statistics report now includes additional user metadata (including email) to support monthly client reporting needs.
We fixed these issues:
Fixed a contrast/accessibility issue in the Best Practice (BP) view to better meet contrast requirements.
Users can now be created/added even when the email address contains an apostrophe.
Prevented circular parent relationships in Media Types by clarifying the Parent Media Type label and adding validation to block self-parenting (this avoids UI breakage/infinite-loop scenarios).
Resolved an error shown after the user clicked the Logout link.
Additionally, we patched a number of dependencies to address security vulnerabilities.
Version 9.68
Released on May 7th, 2026.
This security-focused release upgrades SimpleSAMLphp and patched high-severity FedRAMP vulnerabilities in SAML/XML security dependencies. There were no new features in this release.
We've added these improvements:
Upgraded SimpleSAMLphp to Version 2.4.5
We fixed these issues that caused an error message to be displayed:
The user clicked the Logout link.
The user clicked the Support link.
We patched a number of dependencies to address security vulnerabilities.
Version 9.67
Released on April 9th, 2026.
This release includes the following changes:
- Access Engine upgrade: Assistant has been updated to use Access Engine Version 2.29.
- New default screen resolution: We've updated the screen resolution of the AMP Spider creation screen to 1920X1080. This change results in significant improvements to page discovery.
Configurable visibility of the Severity, Noticeability, and Tractability (SNT) ratings: Administrators can now toggle the visibility of SNT ratings from the Instance Configuration screen. When the setting (
SHOW_SNT) is enabled (default), the SNT values are displayed as usual. When the setting is disabled, SNT values are hidden across all violation views and the Guidance section. This gives organizations greater flexibility in tailoring the information displayed to their users.
AMP Spider
Version 9.65
Released on September 10, 2026.
Upgraded Access Continuum to Version 7.11 release (Access Engine 2.30)
Upgraded Google Chrome to Version 151.0.7922.169.
-
This release includes usability and accessibility fixes, and CVE remediation. Resolved issues pertaining to the following CVE packages:
CVE-2026-59949
CVE-2026-54428
CVE-2026-54399
CVE-2026-50645
CVE-2026-40983
CVE-2026-40984
CVE-2026-43910
CVE-2026-56819
CVE-2026-59900
CVE-2026-56820
CVE-2026-56821
CVE-2026-56822
CVE-2026-44891
CVE-2026-59920
CVE-2026-55851
CVE-2026-59919
CVE-2026-55831
CVE-2026-55833
CVE-2026-56745
CVE-2026-59898
CVE-2026-59899
CVE-2026-56746
CVE-2026-59921
CVE-2026-59901
CVE-2026-56817
CVE-2026-73507
CVE-2026-40914
CVE-2026-45292
Version 9.64
Released on July 30, 2026
We provided fixes for the following CVE packages:
CVE-2026-50020
CVE-2026-45536
CVE-2026-45292
CVE-2026-54512
CVE-2026-54513
CVE-2026-54514
CVE-2026-54515
CVE-2026-54516
CVE-2026-54517
CVE-2026-54518
CVE-2026-44249
CVE-2026-45416
CVE-2026-50010
CVE-2025-69534
CVE-2026-1299
CVE-2026-1502
CVE-2026-2297
CVE-2026-3276
CVE-2026-3644
CVE-2026-4224
CVE-2026-4519
CVE-2026-4786
CVE-2026-6019
CVE-2026-6100
CVE-2026-7774
CVE-2026-8328
CVE-2026-9669
CVE-2026-13462
CVE-2026-45674
CVE-2026-47691
CVE-2026-42578
CVE-2026-44250
CVE-2026-44890
CVE-2026-50011
CVE-2026-46340
CVE-2026-41417
CVE-2026-42584
CVE-2026-42587
CVE-2026-48059
Provided fix for the following package:
GHSA-72hv-8253-57qq
Version 9.63
Released on June 11th, 2026.
SPI 9.63 delivers a WildFly platform upgrade and multiple dependency patches to address FedRAMP/security CVEs across Spidering Services. There are no new product features in this release.
We added these improvements:
Platform runtime upgraded to WildFly 40 Final to resolve security findings and modernize the underlying application server.
We implemented multiple security/FedRAMP vulnerability patches.
Multiple CVE findings were addressed via the WildFly 40 Final upgrade, reducing the need for risky manual module/JAR replacements (noted across the FedRAMP tickets).
Multiple dependency/library upgrades were performed to remove vulnerable versions (e.g., log4j-core, kafka-clients, bc* libraries).
Version 9.62
Released on May 7th, 2026.
This release focused on critical security patching for FedRAMP compliance, and addressed vulnerabilities in system packages and dependencies.
We patched these FedRamp packages:
libcairo-gobject2, libcairo2 packages
log4j-core-2.17.2.jar (2.17.2) package
Version 9.61
Released on May 6th, 2026.
Spiders can test sites with untrusted certificates: A new optional parameter testUnverifiedSites has been added for spidering-services.json.
Default value:
falseBehavior: When set to
true, the Chrome browser used by the Spider to load and test pages will ignore certificate errors, allowing testing of sites with unverified or untrusted certificates.Configuration: This parameter does not appear in
spidering-services.jsonby default. If you need to test sites with unverified/untrusted certificates you must manually add the parameter to thespidering-services.json, and set it totrue.
Access Assistant
Version 9.18
Released on September 10th, 2026.
Access Engine upgrade: Assistant has been updated to use Access Engine 2.30.
Version 9.17
Released on April 9th, 2026.
Access Engine upgrade: Assistant has been updated to use Access Engine Version 2.29.
Testing SDKs
Version 7.11
Released on August 4th, 2026.
Support for pushing locator-based scan results to the Level Access Platform
You can now submit results from runAllTestsOnNode() scans directly to the Level Access Platform. A new method, runAllTestsOnNodeForAssertions() is available in both the Java and JavaScript SDKs, enabling node-scoped scans to produce assertion-formatted results compatible with platform submission.
This release also includes:
- Iframe scanning support via the
includeIframeContentparameter, with a maximum depth of 10 to prevent recursion issues. -
xpathExclusionsfiltering for both parent and iframe scans, allowing you to exclude specific elements from results.
Version 7.10
Released on June 11, 2026.
Improved Playwright scanning and network support
You can now scan multiple pages within a single Playwright test run. This release also improves support for self-signed certificates and proxy network environments, and resolves MaxListenersExceededWarning messages to provide a more reliable testing experience.
Version 7.9
Released on May 13, 2026.
Improved proxy and Node.js compatibility
You can now run accessibility tests in environments that use proxy-generated SSL certificates. This release also updates the Cucumber sample project for compatibility with Node.js 22.
Version 7.8
- DCA has been upgraded to SDK 7.8, enabling support for Access Engine 2.29 improvements and fixes.
- ll non-mobile SDKs have been upgraded to use Engine 2.29, ensuring consistent accessibility testing behavior across supported environments.
Comments
0 comments
Please sign in to leave a comment.