
SSahu_E (Flexera Software)
The SVR July 2026 update v 260701 is now live.
The update includes important feature enhancements as mentioned below –
New API Usage Dashboard
Software Vulnerability Research (SVR) now includes a new API Usage option under Settings > API that provides administrators with visibility into API consumption metrics across the organization such as volume stats, throttle rates, usage data, etc. with flexible filtering options for administrators to slice and dice the data in varied ways.
In addition, API rate limiting has been enhanced to return consistent HTTP 429 responses with a Retry-After header when configured thresholds are exceeded. Throttle events are logged with account and stored information is available through account log exports for auditing and troubleshooting purposes.
Enhanced API Token Management, Lifecycle Auditing, and Anomaly Detection
A new Expiration option has been added when creating or editing API tokens. It allows administrators to specify or modify expiration date of the token, providing greater control of API access and improved enforcement of token lifecycle policies.
In addition, an API Token option has been added in the Settings > logs. This page contains two audit views:
Lifecycle Events - Tracks token management activities such as expiration date changes and other token lifecycle updates.
Anomalies - Records suspicious or unusual token activity, including token usage from previously unseen source IP addresses.
Enhanced Two-Factor Authentication Security Notifications
With this enhancement, standard users must enter their login password before disabling either SMS-based or token-based two-factor authentication (2FA). This additional verification step helps prevent unauthorized changes to account security settings. Whenever a two-factor authentication method is disabled, SVR automatically sends a security notification email to both the affected user and the root account user associated with the account.
Improved messaging during login
When an invalid authentication token is entered, the login page displays the number of remaining attempts before account lockout. Users are allowed a maximum of five unsuccessful 2FA attempts. After the fifth failed attempt, the account is locked to help protect against unauthorized access and brute-force attacks.
For release notes, click here.