This release adds collections for secure sharing, OAuth2 support for API scanning, smarter SQLi detection, Comparer enhancements, as well as other improvements, bug fixes, and a browser update. Share
show checksums
SHA256: {SHA FROM OPTION GOES HERE} MD5: {MD5 FROM OPTION GOES HERE}
This release adds collections for secure sharing, OAuth2 support for API scanning, smarter SQLi detection, Comparer enhancements, as well as other improvements, bug fixes, and a browser update.
Share messages securely using collectionsWe've introduced collections to Burp Suite Professional, enabling you to share one or more HTTP messages with other Pro users via a single secure Burp link. This provides an easy, secure way to pass on findings, reproduction steps, or proof-of-concept requests without copy-pasting or exporting files.
Collections are created using Burp Organizer and support traffic from across your tools. The data is encrypted end-to-end and never visible to PortSwigger.
To create a collection, highlight messages in Organizer and use the Create collection link context menu item. To import a collection, open the link in your browser or paste it into the command palette.
OAuth2 support for API scanningBurp now supports OAuth2 Client Credentials flow authentication for API scanning. If your OpenAPI definition or Postman Collection specifies this flow, Burp automatically detects it and fills in the details for you, helping you get your scan running more quickly with less manual setup. Burp then uses this information to obtain and refresh your access tokens during the scan, so you do not need to manage tokens manually.
You can also configure OAuth2 yourself by entering the token URL, client ID, client secret, and optional scope.
Burp can also detect other types of OAuth2, but does not currently support them.
Quick actions for URLs in the command paletteThe command palette now recognizes when you enter a URL and offers quick actions for it. You can:
Extension hotkeys now enable you to apply actions to multiple selected items at once. This makes it possible to trigger extensions or repeat actions across large sets of requests.
Comparer enhancementsWe've made a number of enhancements to Comparer in this release:
Burp Scanner now filters out false positives caused by web application firewalls (WAFs) delaying suspicious payloads. This improves accuracy in detecting genuine time-based SQL injection in these scenarios.
Quality of life improvementsCtrl+Click to copy a column in Intruder results would also sort the column.Host header ending in a : caused UI issues in Repeater.We've upgraded Burp's browser to Chromium 143.0.7499.193 for Windows & Mac and 143.0.7499.192 for Linux. For more information, see the Chromium release notes.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Professional / Community Edition 2026.2.3 | 0 | 11.63 | 04-03-2026 |
| 2 | Professional / Community 2026.2 | 0 | 11.67 | 13-02-2026 |
| 3 | DAST 2025.12 | 0 | 19.28 | 16-12-2025 |
| 4 | Professional / Community 2026.1.3 | 0 | 12.41 | 13-02-2026 |
| 5 | Professional / Community 2026.1 | 0 | 12.41 | 16-01-2026 |
| 6 | Professional / Community 2026.3 | 0 | 13.77 | 12-03-2026 |
| 7 | Professional / Community 2026.3.2 | 0 | 13.77 | 08-04-2026 |
| 8 | Professional / Community 2026.4 | 0 | 12.45 | 23-04-2026 |
| 9 | Professional / Community 2026.4.2 | 0 | 12.45 | 08-05-2026 |
| 10 | DAST 2026.5 | 0 | 12.29 | 12-05-2026 |