start portlet menu bar

HCLSoftware: Fueling the Digital+ Economy

Display portlet menu
end portlet menu bar
Close
Select Page

Today's applications rely on AI-powered workflows, complex authentication mechanisms, API-first architectures, and evolving regulatory requirements. As these environments become more dynamic and intelligent, security tools must evolve just as quickly to keep pace with change. 

To help organizations address these challenges, HCL AppScan 10.12 introduces enhancements across HCL AppScan Standard, HCL AppScan Enterprise, and HCL AppScan Source, delivering improved capabilities to secure the way modern applications are built, connected, and governed. 

What's New in HCL AppScan 10.12

Securing AI Workflows with Model Context Protocol (MCP) Support

Securing AI applications and workflows remains a strategic investment area for HCL AppScan. Building on our existing LLM security capabilities, this release marks our first step toward securing MCP-based interactions. 

Model Context Protocol (MCP) is emerging as a widely adopted approach for enabling AI systems to interact with external data sources and tools. HCL AppScan Standard (dynamic application security testing tool) now supports testing applications that use MCP through manual exploration. It can capture MCP traffic, analyze MCP tool calls, and perform targeted security analysis to help identify potential risks in MCP-enabled applications.

Faster, More Focused Security Scans 

Multi-step operations (MSO) such as moving through application workflows and performing a sequence of actions to reach a target function, can become resource-intensive when they include unnecessary dependencies. This release enhances MSO intelligence by validating dependencies, identifying only the required steps to reach the target function, and removing redundant actions, resulting in faster scans, optimized resource usage, and security scan optimization. 

The release also improves automatic crawling by eliminating redundant paths and skipping non-essential file types, allowing the scanner to focus on relevant applications and further reduce scan duration. 

Expanded OpenAPI Support for Modern APIs

The latest version adds full parsing and model support for OpenAPI Specifications 3.1 and 3.2, helping AppScan more accurately understand newer API definitions. It also improves reference handling, allowing AppScan to better process relationships between different parts of an API specification, and enhances automatic exploration heuristics to improve API discovery and testing. Together, these improvements help AppScan handle more complex API scenarios, improve handling of references and missing scenarios, and improve testing coverage and performance.  

Simplified Login

Modern authentication shouldn't slow down security testing. In HCL AppScan 10.12, login workflows have been streamlined to reduce manual intervention and minimize authentication-related interruptions. 

CAPTCHA login: AppScan Multi-Factor Authentication (MFA) now uses AI to recognize and process image- and text-based CAPTCHA during dynamic scanning. This eliminates manual CAPTCHA entry by automatically populating values and completing authentication without user intervention. 

Automated Login Detection: Structural improvements have been made to AppScan’s automated login detection and authentication workflows, improving compatibility with Microsoft Entra ID and Okta SSO. These enhancements help AppScan more reliably identify and handle modern SSO authentication flows, reducing authentication issues during security testing. 

Enterprise Platform Enhancements

Behind every security scan is an infrastructure that must scale with modern applications. HCL AppScan continues to modernize its scanning infrastructure to improve performance, compatibility and scalability. The Dynamic Analysis Scanner Agent Host has been migrated to .NET 8, providing a modern foundation for supporting new engine capabilities and optimized performance.

In addition to the Chromium browser engine upgrade, AppScan now supports Microsoft SQL Server 2025 and Microsoft OLE DB Driver 19, enabling secure, encrypted database connectivity and ensuring compatibility with the latest Microsoft technologies. 

Compliance and Risk Reporting Updates 

Application security and compliance go hand in hand. HCL AppScan keeps compliance reporting aligned with evolving industry standards, helping organizations spend less time adapting to changing requirements and more time addressing critical security risks. 

Latest Standards Alignment: Security reports now align with the latest OWASP Application Security Verification Standard (ASVS) 5.0 and CWE Top 25 Most Dangerous Software Weaknesses (2025), helping organizations stay current with evolving security benchmarks.

Enriched compliance insights: CVSS 4.0 vectors can now be viewed directly within Industry Standard and Regulatory Compliance reports, including ISO 27001, NIST SP 800-53, PCI DSS, and GDPR, providing greater vulnerability context and risk visibility.

Architecture and Technology Advancements 

Modern application environments are growing in size and complexity, requiring security testing that can scale without sacrificing performance. 

Foundational improvements have been introduced in HCL AppScan Source (static application security testing tool) to strengthen scanning performance, support modern application environments, and extend security coverage. The platform has been modernized by transitioning from 32-bit to 64-bit architecture for Linux, enabling more efficient analysis of larger and more complex codebases. Support has also been added for Delphi, a language commonly used for Windows-based applications, and MuleSoft, a platform for connecting applications and APIs, expanding security analysis across a wider range of business-critical technologies. 

Join Us as an MCP Design Partner

We are inviting customers to participate as early design partners to help shape and refine our automated AI security workflows. If you are exploring MCP or AI agent architectures within your organization and want to influence the product roadmap, please reach out through your account team. We’d like to collaborate with you and incorporate your feedback as we continue enhancing these capabilities. 

Read the deep-dive technical release notes for HCL AppScan 10.12: AppScan Standard, AppScan Enterprise, and AppScan Source

End of Support Notice

As part of our ongoing lifecycle updates, version 10.7.0 of HCL AppScan Standard, Source, and Enterprise is no longer available for download through My HCLSoftware. The version will reach its End of Support (EOS) on March 30, 2027. We encourage customers to upgrade to the latest version to access new enhancements, maintain support coverage, and strengthen their security posture. Learn more

Contact Support for assistance.

Start a Conversation with Us

We’re here to help you find the right solutions and support you in achieving your business goals.

The Pre-Audit Checklist: Ensuring Your Web Applications Are Compliance-Ready
  |  July 3, 2026
The Pre-Audit Checklist: Ensuring Your Web Applications Are Compliance-Ready
Application Security Audit preparation starts with continuous testing, remediation, and security validation to stay compliant and audit-ready year-round.