September 21, 2026

Summary

Platform

An IPv4 observable in ServiceNow TISC that has been enriched with Censys data.

  • Use the new ServiceNow TISC integration to:
    • Automatically or manually enrich IPs, web properties, and certificates in ServiceNow TISC with Censys Platform data.
    • Initiate a Censys rescan of a host or web property.
    • Retrieve scan history for an IP address
    • Initiate a CensEye automated pivoting job to find assets related to an IP, web property, or certificate.

New fingerprints and risks

Added 16 new fingerprints to the Platform and two new risk fingerprints to ASM.

Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.

New fingerprints

TypeNameDescriptionQuery
softwareCheck Point Security Management and Log ServerCheck Point security tools used to control security policies and manage network traffic logs.Platform query
softwareApache CloudStackAn open-source software platform designed to deploy and manage large networks of virtual machines.Platform query
softwareApache CocoonAn open-source Java web development framework.Platform query
softwareCisco Secure Email GatewayAn email security product that inspects inbound and outbound email traffic for threats.Platform query
softwareCitrix XenMobile ServerAn on-premises enterprise mobility management solution used to manage and secure mobile devices, apps, and data from a single central console.Platform query
softwareDocker Registry BrowserA web-based GUI or plugin designed to help users browse, view, and manage the contents of a private Docker Registry.Platform query
softwareGeoVision GeoWebServerA software component used for web-based access and remote monitoring in video surveillance and security management systems.Platform query
softwareIBM WebSphere LibertyA lightweight Java application server for modern cloud apps and microservices.Platform query
softwareLuceeA free, open-source ColdFusion Markup Language (CFML) application server that compiles code into Java bytecode to run on the Java Virtual Machine (JVM).Platform query
softwareOpenMetadataAn open-source metadata management and data collaboration platform used for data cataloging, discovery, governance, and AI context.Platform query
softwarephpListAn open-source mailing list and email marketing software used to send newsletters, announcements, and marketing campaigns to large numbers of subscribers.Platform query
softwarePloneAn open-source enterprise content management system (CMS) used to build and manage secure websites and intranets.Platform query
softwarePrivateBinAn open-source, zero-knowledge online pastebin where data is encrypted and decrypted directly in a user's web browser.Platform query
softwarepypiserverA Python Package Index (PyPI)-compatible server used to host and privately distribute Python packages.Platform query
softwareRoadiz CMSAn open-source CMS built on top of the Symfony framework.Platform query
softwareTYPO3An open-source CMS built with PHP.Platform query

New risks

NameDescriptionQuery
Exposed Check Point Security Management and Log ServerThis host runs a Check Point Security Management Server and/or Log Server (including Multi-Domain variants) reachable from the internet. This is the management plane for an entire Check Point firewall estate and is not intended to be internet-facing. Management interfaces of this kind have a history of unauthenticated remote code execution vulnerabilities in their Gaia WebUI login process.
risks.name: "Exposed Check Point Security Management and Log Server"
Vulnerable Cisco Secure Email Gateway [CVE-2026-76461]This is a Cisco Secure Email Gateway (AsyncOS) running a version affected by CVE-2026-76461, a SQL injection in the device's email parsing logic. An unauthenticated, remote attacker can send a crafted email containing malicious SQL statements through the affected device, leading to arbitrary SQL execution and, ultimately, command execution with root privileges on the underlying operating system. Actively exploited in the wild; added to the CISA Known Exploited Vulnerabilities catalog on 2026-09-14.
risks.name: "Vulnerable Cisco Secure Email Gateway [CVE-2026-76461]"

Censys ARC Rapid Response

The Censys ARC team published information about the following issue.