Product updates
What has changed in StackFlag. Newest first.
August 2026
Vulnerability pages show a plain-English name alongside every CWE weakness classification. Previously most of them appeared as a bare code with no explanation.
The "What to do" box no longer suggests a version number when a vulnerability affects many vendors and the underlying record does not actually name a fix. In those cases it now points you to the vendor advisories instead of guessing.
Alert emails also stop re-sending for older vulnerabilities when only background scoring data changed, and any alert that is an update to something you have already seen is now labelled as an update rather than as new.
Some advisories from feeds that publish little detail had summaries that described the wrong software. Every affected record has been rebuilt from the underlying advisory data, and the summaries now stay blank rather than guess when there is genuinely nothing to describe.
The "What to do" section now reads fix versions directly from the advisory record, so pages no longer say a fix is unavailable when the advisory names one. Where no fix version is published, the page says so plainly instead of implying none exists.
The vulnerability index and detail pages have a new fact-sheet layout: severity, exploitation status, affected software, and what to do are easier to scan at a glance.
Fixed slow page loads on your stack and alert pages, which could stall when several pages were open at once. The vulnerability index no longer shows outdated titles for very recently published CVEs, and logged-in visitors are always served their own view of a page.
July 2026
Vulnerabilities listed in the CISA Known Exploited catalogue no longer show the date they were added to that catalogue as their publication date. Affected records now show their real publication date.
StackFlag now posts critical vulnerabilities to Bluesky as they are published, with a plain-English summary and a link to the full detail page. Follow along at the account linked in the footer.
Homepage and vulnerability index load faster. URLs with a trailing slash now redirect to the correct page instead of returning a not-found error.
Added a new feed covering advisories from all CVE numbering authorities, so vendor-assigned CVEs now appear the same day rather than waiting for them to reach other sources. Also fixed two feeds that had been quietly collecting less than they should, which means noticeably more complete coverage.
May 2026
Added the groundwork for a weekly summary of vulnerability activity: headline counts, week-on-week trend, newly exploited entries, and the most significant items of the week.
April 2026
Simplified the site's colour scheme so that colour consistently signals severity and nothing else. The wordmark has a new two-tone treatment.
Improved page titles, descriptions, and structured data across the site, so vulnerability pages surface more accurately in search results.
March 2026
Backfilled vulnerability records going back to 1999, so searches and monitors now cover the full published history rather than recent years only.
Feedback submissions now have threading and acknowledgement. This public changelog now appears on the FAQ page.
Updated copy and legals.
Significantly reduced database queries during digest notifications. Poll cycle optimised for large numbers of trackers.
Flag detail and vulnerability detail are now a single page, so everything about a vulnerability you are monitoring is in one place.
Your stack list now supports sorting, filtering, pagination, and bulk assignment, with vulnerability and severity counts per entry. Navigation labels are clearer throughout.
CSRF, CSP and other security improvements.
Want to suggest a change and help us improve?
Tell us what is missing, confusing, or broken. If you tick the credit box we will acknowledge you here when your suggestion ships.