PortSwigger has leveled up Burp Suite’s scanning arsenal with the latest Active Scan++ extension, version 2.0.9, released on December 16, 2025.
This free BApp, authored by Director of Research James Kettle, now detects React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478), alongside a suite of other high-impact flaws.
Designed for penetration testers, it boosts both active and passive scanning while keeping network overhead low, making it ideal for thorough web app assessments without crashing targets.
Active Scan++ shines by spotting subtle application behaviors that evade basic scanners.
It runs automatically during standard Burp active scans, flagging issues in real time for quick review in the scan results.
Testers can download it directly from the BApp Store or GitHub for offline installation.
The extension packs a punch with targeted checks:
These features help pentesters chain findings, such as using host header modifications to pivot attacks though caution is advised in shared hosting to avoid routing requests astray.
Getting started is straightforward: Launch a standard active scan in Burp Suite, and Active Scan++ handles the rest.
No extra config needed for core checks. It boasts low system impact minimal CPU, memory, and network use earning high ratings and popularity on the App Store.
This update equips security pros to counter evolving threats like React2Shell, ensuring Burp stays ahead in the cat-and-mouse game of web app testing.
Follow us on Google News , LinkedIn and X to Get More Instant Updates, Set Cyberpress as a Preferred Source in Google. Unit 42 researchers at Palo Alto Networks exposed serious flaws in the Model Context Protocol…
Polish police have arrested three Ukrainian men traveling through Europe and seized a cache of…
Google has launched its most significant Chrome update ever, embedding Gemini AI across the browser…
Attackers exploit this vulnerability through the router's web interface components, specifically "cgibin" and "hnap_main," by…
Security researchers have uncovered a severe flaw in Apache Tika, a popular open-source toolkit for…
Attackers can keep access to AWS accounts even after admins delete compromised keys. New research…