> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2026/may-2026.md).

# May 2026

This section describes the new features and updates of the Cortex XSOAR 8.14 SaaS release.

## Release Highlights

The following are the key highlights for this release.

| FEATURE                                            | DESCRIPTION                                                                                                                                                                                                                                                                                                           |
| -------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Multi-tenant support for child tenant name changes | Simplify tenant management by renaming child tenants from within the Cortex Gateway. You now have the flexibility to ensure tenant names consistently reflect current business requirements, maintaining operational clarity across large-scale SOC deployments. *For MSSP/Enterprise Multi-tenant customers.*        |
| Organized content management                       | Easily distinguish between your custom work and content pack items with a dedicated workspace for each. To ensure a cleaner view, we moved all content pack items to the Content Pack Items page, while the Content Items page is now reserved exclusively for your custom creations.                                 |
| Enhanced audit logs                                | Gain full visibility and meet compliance requirements with expanded auditing for notification forwarding and content management. You can now track configuration changes for notifications and high-stakes content lifecycle events, such as pushing content to production, directly within the Management Audit log. |
| Identity and privilege-based SOC response          | Instantly disrupt the kill chain with minimal user impact by validating identity and dynamically limiting privileges via CyberArk Endpoint Privilege Manager. Available via Cortex Marketplace. Requires a CyberArk EPM license.                                                                                      |

## Marketplace Content Changes

The following marketplace content updates have been made in this release.

| FEATURE                        | DESCRIPTION                                                                                                                                                                                                                                                  |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Crowdstrike Falcon integration | Deepen your security insights by consolidating a wider range of security data into a single view for more comprehensive threat analysis. We expanded the CrowdStrike integration by adding a new data collection type to capture additional security events. |
| AzureWAF integration           | Strengthen your cloud defense and gain full visibility into web traffic threats by centralizing security events from your Azure Front Door deployments. We added support for ingesting and analyzing WAF policy data to help you respond to attacks faster.  |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas-release-notes/features-introduced-in-previous-releases/features-introduced-in-2026/may-2026.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
