> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/may-2026/feature-enhancements.md).

# Feature Enhancements

These enhancements provide new and improved capabilities.

## General

| FEATURE                                                    | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ---------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Associate cloud security rules with custom controls        | You can now associate out-of-the-box config, identity, and AI cloud security rules with custom compliance controls.                                                                                                                                                                                                                                                                                                                 |
| Consolidated CaaS resource visibility                      | Improve security oversight and simplify asset management by viewing CaaS (Containers as a Service) resources within a dedicated section of the Asset Inventory. This update organizes resources from Amazon ECS, Google Cloud Run, and Azure Container Instances into a single, purpose-built view under Compute assets, making it easier to locate, monitor, and assess the security posture of your cross-cloud CaaS deployments. |
| Enhanced notification forwarding                           | To help you prioritize and resolve security issues more effectively, issue notifications sent to Amazon S3, Amazon SQS, Webhook, Splunk, and email now provide additional asset and remediation information. Notification fields have been expanded to include the asset name, cloud resource name, asset tags, account name, region, and evidence.                                                                                 |
| Administrator control for saved views and filters          | Keep your workspace clean and relevant. Administrators can now remove unused or outdated saved views and filters, including those created by other users.                                                                                                                                                                                                                                                                           |
| Autodetect AWS Web Application Firewall                    | Gain deeper visibility and insights into your internet-exposed cloud assets with new automatic detection of AWS Web Application Firewall (AWS WAF) instances.                                                                                                                                                                                                                                                                       |
| Event-based Asset Ingestion (EAI) parity with Prisma Cloud | Monitor your cloud environment in real-time with improved data processing speeds. Cortex Cloud now has Event-Assisted Ingestion parity with Prisma Cloud.                                                                                                                                                                                                                                                                           |

## Access Management

| FEATURE                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                      |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Granular per-object access       | Strengthen least-privilege access with granular permissions for user groups across report templates, playbooks, scripts, and saved queries.                                                                                                                                                                                      |
| Expanding SBAC with Account Name | Scope-Based Access Control (SBAC) has been enhanced to provide more granular control over your access policies. You can now define Asset Groups that include the **Account Name** attribute for scope-based access control. Continue to use the existing **Realm** attribute whenever you need to scope based on the Account ID. |

## AI Security

| FEATURE                              | DESCRIPTION                                                                                                                                                                                                                                                                       |
| ------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Locate AI workloads instantly        | Locate AI-related workloads instantly. You can now identify compute assets that deploy AI models or contain AI software in their software bill of materials (SBOM). We introduced the "AI associated" insight to help you filter and manage these assets across your environment. |
| Enhanced open-source model detection | All types of models from "Hugging Face" when found on virtual machines are now identified as self-managed and open-source models, helping you get a full AI-BOM of your environment.                                                                                              |

## API

| FEATURE                  | DESCRIPTION                                                                                                                                                                              |
| ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Billing Contributors API | A new public API endpoint is introduced to retrieve a list of unique active contributors factored into your billing. This allows you to gain full transparency into your billable seats. |

## Application Security, Cloud Workflow Protection, API Security

| FEATURE                 | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced CLI experience | <p>Reduce onboarding friction, standardize scan controls, and deliver structured results across code and image scans.</p><ul><li><strong>Install directly from the terminal</strong>: Install the Cortex CLI directly from your command line using Homebrew (macOS) or Scoop (Windows)</li><li><strong>Consistent scan output</strong>: The Cortex CLI now delivers a unified output experience across code and image scans. Results are presented in a standardized structure with a real-time progress indicator, findings grouped by scanner, CVE tables, secrets validation status, and a clear scan summary</li><li><strong>Unified global flags</strong> (AppSec and CWP): The Cortex CLI introduces new global flags that work across both scan types</li><li><strong>Improved error handling</strong>: Troubleshoot faster with clear, categorized error messages instead of raw stack traces</li></ul> |

## ASPM

| FEATURE                           | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced Urgency scoring coverage | <p>Prioritize remediation and eliminate developer noise with context-aware Urgency scoring across a broader set of runtime environments and risk signals.</p><ul><li><strong>Expanded runtime coverage</strong>: Extend Urgency calculations to active VM images and instances</li><li><strong>Compensating control evaluation</strong>: Automatically lower scores when compensating controls, such as XDR Agent coverage or manual security controls, are detected</li><li><strong>AWS API key identity correlation</strong>: Detected AWS API keys are now correlated with their associated identity to improve impact assessment and prioritize urgency</li></ul> |
| ASPM Command Center               | <p>Accelerate cases and issues triage and remediation delegation by drilling down from posture metrics directly into the relevant views.</p><ul><li><strong>Improved application and time filtering</strong>: You can now filter the Command Center by one or more applications and a time range to better focus your view and prioritize efforts</li><li><strong>Prioritization funnel</strong>: You can now drill down into each funnel insight to view supporting evidence, such as blocked findings and prioritized issues</li></ul>                                                                                                                              |

## Asset Inventory

| FEATURE                                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Drift detection highlight in Container Instances | Container Instances asset cards in Asset Inventory now include a Security Drift Detected highlight and a dedicated Security Drift tab, making it easy to identify containers that have deviated from their base image. These drifts expose vulnerabilities, misconfigurations, compliance violations, and other security risks introduced at runtime that were not part of the base image.                                                                                                                                                                                                        |
| Base Image Visibility for Container Images       | You can now identify the base image for any Build, Registry, or Runtime container image directly from its asset details page. With the **new has base reference** and **is base reference for** relationships in Security Graph, you can trace image lineage and assess vulnerability impact in a single query. Define custom Base Image Rules to mark foundational Registry Images, create targeted asset groups and policies, and quickly determine whether vulnerabilities originate from a base image layer. This streamlines your security investigations and accelerates incident response. |

## Attack Surface Management

| FEATURE                  | DESCRIPTION                                                                                                                                                                                                     |
| ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Website data in CloudASM | Continuously discover and monitor your website inventory and web technologies, identify your insecure and misconfigured websites, and identify sites failing security best practices and putting users at risk. |

## Automation

| FEATURE                                            | DESCRIPTION                                                                                                                                                                                                                |
| -------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Performance improvements for scripts and playbooks | Enhance the user experience when managing security workflows with modernized interface improvements and optimized memory usage across the Scripts and Playbooks pages to maintain a seamless and cohesive user experience. |

## Broker VM

**Version 31.0.57 (reboot required)**

For more information on maintenance releases, see [Maintenance Releases](/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/maintenance-releases.md).

| FEATURE                                | DESCRIPTION                                                                                                                                                                                                                                                                                                   |
| -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Legacy server connectivity             | You can now easily configure OpenSSL compatibility settings directly from the Broker VM web interface to ensure uninterrupted communication with legacy servers. We added **Advanced Settings** options to allow legacy SSL renegotiation and accept certificates without an Authority Key Identifier (AKID). |
| Import Configuration tool enhancements | The **Import Configuration** tool has been enhanced to streamline the Broker VM migration process to the new Broker VM image. You can now migrate your current Broker VMs to the new Debian 13 based image. **Note**: Both source and target brokers should be running the latest Broker VM 31.x version.     |

## Compliance

| FEATURE                              | DESCRIPTION                                                                                                                                                                       |
| ------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Compliance Overview Dashboard        | The Compliance Overview Dashboard presents a centralized view of your organization's compliance performance against industry standards and your own internal security frameworks. |
| Updated compliance score calculation | We updated the compliance score calculation to ensure it reflects the status of all assessed controls for all assessed assets.                                                    |

## Cortex Agentic Assistant

| FEATURE                                           | DESCRIPTION                                                                                                                                                                                                     |
| ------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Chat with the Agentic Assistant directly in Slack | Access Agentic Assistant more easily across your daily applications. You can now trigger the Agentic Assistant from your Slack, give it tasks, interact with it and get the results on your existing workspace. |
| Natural language visualizations                   | Turn questions into charts in seconds, identify security trends, and build custom widgets without writing a line of code using the Cortex Agentic Assistant.                                                    |
| Enhanced AI product support                       | The upgraded Help Center agent delivers instant how-to support and helps you navigate in-product support cases. It stays aware of your support issues to provide more relevant guidance in context.             |

## CSP Onboarding

| FEATURE                          | DESCRIPTION                                                                                                                                                                                                                                                                                                                                    |
| -------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Alibaba Cloud support            | Secure your Alibaba Cloud environments directly from Cortex Cloud. You can now onboard your Alibaba Cloud accounts and gain unified security visibility alongside your AWS, Azure, GCP, and OCI environments. Cortex Cloud automatically discovers your Alibaba Cloud assets and evaluates your security posture with out-of-the-box policies. |
| Bring your own Azure EventHub    | Reduce cloud audit log collection costs and improve operational efficiency by routing cloud data through your own Azure EventHub. You can now connect your own Azure EventHub for cloud audit log collection, eliminating redundant data transfer overhead and giving you direct control over your data pipeline.                              |
| Manual AWS account onboarding    | Gain full control over AWS onboarding with a manual setup flow. Provision the required resources and IAM permissions yourself, allowing you to meet strict security, compliance, and infrastructure requirements without dependency on vendor templates.                                                                                       |
| Manual GCP project onboarding    | Gain full control over GCP onboarding with a manual setup flow. Provision resources, service accounts, and permissions yourself to meet strict security, compliance, and governance requirements without dependency on vendor templates.                                                                                                       |
| Onboard Microsoft Entra ID only  | Connect Microsoft Entra ID independently of tenant-level onboarding to unlock identity-based capabilities, including CIEM, identity posture, and Entra ID sign-in logs. When onboarding Azure subscriptions or Management Groups, you can now enable Entra ID to achieve full identity visibility without requiring tenant-level scope.        |
| OCI audit log normalization      | Query Oracle Cloud Infrastructure (OCI) audit logs alongside AWS, Azure, and GCP activity using a unified schema. OCI audit logs collected through the cloud onboarding flow are now normalized into the cloud\_audit\_logs dataset, enabling consistent cross-cloud investigation and alerting through XQL.                                   |
| Least-privilege cloud onboarding | Reduce your exposure to cloud threats with least-privilege access. We now provide least-privilege access across all supported cloud providers, helping you minimize unnecessary permissions and tighten your security.                                                                                                                         |

## CWP Compliance

| FEATURE                        | DESCRIPTION                                                                                                                                                                                                                                                                                             |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Enhanced evidence for findings | Improve remediation efficiency with detailed evidence for every security finding. The update includes visibility into the exact configuration values, such as bind address or file size parameters, that triggered the issue, providing the necessary context to resolve misconfigurations effectively. |

## Data Classification

| FEATURE                                                   | DESCRIPTION                                                                                                                                                                                                                                                                                            |
| --------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Improved classification accuracy for semi-structured data | We have refined our engine’s ability to parse the internal hierarchy and element relationships within JSON and similar formats. By more accurately distinguishing between keys, values, and nested structures, the engine now delivers higher detection precision across complex, modern data formats. |

## Data Security

| FEATURE            | DESCRIPTION                                                                                                                                                                                                                                                                                         |
| ------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| OCI object storage | Scale your data security as your cloud environment grows. You now have full visibility into OCI Object Storage with automated discovery and classification to prevent data leaks. This update expands our support for Oracle Cloud Infrastructure (OCI) to ensure your storage is always protected. |

## Data Security Platform

| FEATURE                             | DESCRIPTION                                                                                                                                                                                                                                              |
| ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Data Security Command Center (Beta) | Monitor your data security from a centralized command center. We introduced the Data Security Command Center, providing a unified dashboard for monitoring data discovery, classification status, and all security aspects across connected data stores. |

## External Data Ingestion and Management

| FEATURE                    | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                              |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| New Cloud NGFW data source | Gain complete visibility into your cloud-native network security with the new **CNGFW** (Cloud NGFW) data source. You can now stream traffic and application logs directly to Cortex Cloud with support to cross-region and cross-account connections. We introduced this distinct connector to handle unique cloud-native identifiers, ensuring seamless log ingestion and analysis for your managed security services. |

## Graph Search

| FEATURE                          | DESCRIPTION                                                                                                                                                                                                                                                                                                          |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SBAC enforcement in Graph Search | Safely explore your environment in Graph Search with precise permission management. We introduced Scope-Based Access Control (SBAC) to give you granular control over user scope. You can now assign users to **User Groups** and **Asset Groups**, ensuring they only see authorized graph nodes and relationships. |

## Identity Security

| FEATURE                                      | DESCRIPTION                                                                                                                                                                                                                                                                    |
| -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Identity Security navigation and inventories | Navigate identity security faster with a redesigned menu and improved inventories. We reshaped the Identity Security navigation and inventory views, providing a more intuitive layout that aligns with how security teams investigate and manage cloud identities.            |
| GCP inactive identity detection              | Identify dormant GCP identities that increase your attack surface. We added detection of inactive identities for Google Cloud Platform users, so security teams can revoke unnecessary access and reduce risk.                                                                 |
| OCI effective permissions                    | Strengthen your Oracle Cloud identity security with expanded permission analysis. We enhanced OCI effective permission calculations, adding Identity Domain support, additional dynamic group sources, and pseudo-resource handling for comprehensive OCI identity governance. |

## Investigation and Response

| FEATURE                                              | DESCRIPTION                                                                                                                                                                                                                                                                      |
| ---------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Case Timeline view                                   | Streamline the entire investigation lifecycle with an automatically generated, end-to-end case timeline that captures every action, artifact, and piece of evidence in one place, saving time and eliminating manual work.                                                       |
| Integrated asset context for investigations          | Provides richer investigation context by connecting asset data directly to cases and issues.                                                                                                                                                                                     |
| Centralized issue resolution                         | Simplified issue-level remediation by centralizing all remediation actions in one place. From the Resolution tab, you can access recommended and pending actions, run playbooks, and perform manual tasks like CLI commands, with seamless sync to the case's Resolution Center. |
| Service Level Agreements (SLAs) for issue resolution | Reduce security risk and ensure accountability with SLAs for issue resolution. These SLAs ensure teams resolve critical issues within a consistent, predictable timeframe.                                                                                                       |
| Issue Exceptions                                     | Formalize risk deferrals and align security alerts with operational constraints using Exception Management for Issues. This feature allows you to "snooze" or exempt specific issues while maintaining oversight through documented justifications and an approval workflow.     |

## Kubernetes Security

| FEATURE                                                    | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ---------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Unified Kubernetes cluster management                      | Manage your infrastructure from a single, streamlined interface. You can now access all controls directly from the Kubernetes Clusters page instead of navigating legacy connectivity screens. We consolidated these tools into a unified view to simplify your workflow and remove unnecessary navigation steps.                                                                                                                                                                                                                                                                                                                                    |
| Enhanced security and deployment for Kubernetes Connectors | <p>Minimize your attack surface by applying stricter security controls to your Kubernetes connectors.<br>Recent updates include:</p><ul><li><strong>Private registry support</strong>: You can now pull images directly from private container registries.</li><li><strong>GitOps integration</strong>: The standalone installer now fully supports GitOps workflows.</li><li><strong>Least privilege enforcement</strong>: Restrict connector management to specific namespaces rather than the entire cluster. We have narrowed the access scope and removed unnecessary secret creation permissions to better protect your environment.</li></ul> |
| Tag Kubernetes endpoints instantly                         | Automate your security deployment. Our new tag support for Kubernetes lets you seamlessly associate XDR security profiles with specific connectors during configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Enhanced KSPM Graph                                        | We've introduced several design improvements to the KSPM Graph focused on streamlining your user experience. You can now more intuitively explore the relationships between your workloads, nodes, and cloud resources to seamlessly map and manage your cluster topology and security posture.                                                                                                                                                                                                                                                                                                                                                      |
| Maintain system availability                               | Maintain system availability during unexpected disruptions. You can now choose whether to allow or block requests if the admission controller is unreachable. We added a Failure Policy setting to give you full control over your environment's stability.                                                                                                                                                                                                                                                                                                                                                                                          |
| On-demand Kubernetes cluster scans                         | Secure your environment instantly. You no longer have to wait for scheduled cycles to evaluate newly deployed resources, including your inventory, containers, and nodes. We added a Request Scan button and API support so you can trigger on-demand cluster scans and see results in minutes.                                                                                                                                                                                                                                                                                                                                                      |
| Optimized resource usage                                   | Optimize system performance by eliminating redundant security scans. Your devices run more efficiently because the XDR agent automatically disables Adaptive Vulnerability Assessment (AVA) when a KSPM connector is deployed. The KSPM posture module now handles the AVA scan directly to save local resources.                                                                                                                                                                                                                                                                                                                                    |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cloud-posture-management-rn/cortex-cloud-posture-management-release-information/features-introduced-in-2026-cloud/may-2026/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
