Features Introduced in April 2026
Learn what’s new in the Prisma® Cloud April (26.4.1) 2026 release.
Enhancements
Feature
Description
AWS SDK for Java 2.x Support
Secure the Runtime
Prisma Cloud now supports the AWS SDK for Java 2.x, replacing the older AWS SDK for Java 1.x.This upgrade ensures compatibility with the latest AWS services and features, providing improved performance and security.
Restrict UI access for access key logins
Secure the Runtime
Added ability to block login using an access key via the CWP login UI page under a feature flag, aligning with the way access key based logins are handled by the main Prisma login page.
FIPS configuration via environment variable
Secure the Runtime
Added support for setting the FIPS_ENABLED configuration from an environment variable in twistlock.cfg.
nginx_unit vulnerability detection
Secure the Runtime
Added vulnerability detection support for nginx_unit application server binaries.
Configurable Cap for Per-Image Clusters
Secure the Runtime
You can now configure a cap on the number of clusters stored per image in MongoDB. This prevents excessive document growth for widely-deployed images and improves database performance.
OCI Compartment Support for Agentless Scanning
Secure the Runtime
Agentless scanning configuration now accepts OCI compartments by OCID in addition to compartment name. Use the OCID when you need to reference compartments programmatically or avoid ambiguity with duplicate names.
Package URL Augmentation for Binary Packages
Secure the Runtime
The scanner now augments binary packages with Package URLs (PURLs), improving software composition analysis accuracy and enabling better vulnerability correlation.
Upgrade xmlquery to avoid CVE-2026-32287
Secure the Runtime
Upgraded xmlquery (and xpath) dependencies to remediate CVE-2026-32287.
Remove libnghttp2 from Defender Dockerfile
Secure the Runtime
Removed the libnghttp2 package from the Defender Dockerfile to eliminate a known vulnerability from the container image.
Updated MongoDB to 7.0.31
Secure the Runtime
Updated MongoDB from 7.0.29 to 7.0.31 to address additional security vulnerabilities.
Changes in Existing Behavior
Audit Log Retention Policy
The retention period for audit events stored in the Prisma Cloud database changed from 120 days to 30 days. This update is part of our ongoing efforts to optimize performance and resource usage. The new retention period ensures a more responsive experience and efficient resource utilization across all environments.
Impact: Features that rely on historical audit data will be impacted: * Audit Trail & Investigation: Tracing user actions and general audit log investigations will now be limited to the last 30 days of data. * Alert Details: For alerts triggered by audit events, the associated event details will no longer be available for investigation, when you select Investigate 30 + days after the event occurred. * Policy Evaluation: Evaluation of audit-event-based policies will focus on events within a 30-day window. * General Impact: Other platform features or custom workflows that rely on the retention of audit events beyond 30 days may be impacted.
The following functional areas will continue to operate without change, as they rely on real-time event processing: * Event Assisted Ingestion (EAI): Real-time ingestion triggers remain unaffected. * IAM Security: Real-time IAM analysis and monitoring remain unaffected. * Real-time Alerting: The triggering of alerts based on immediate event matches is not impacted.
No additional action is required. If your compliance or operational requirements necessitate audit log retention beyond 30 days, we recommend ensuring your CSP (AWS, Azure, GCP) is configured to archive these logs in their respective native storage (e.g., S3, GCS, or Azure Blob Storage).
VPC Resource Ingestion
Prisma Cloud will now ingest accepter side VPC connections in addition to requester side VPC connections. This will ensure better coverage of VPC peering endpoints irrespective of whether the given VPC functions as a requester or an accepter for a given connection.
API Ingestions
Service
API Details
Amazon Web Services
Amazon AppStream 2.0
aws-app-stream-app-block-builder
Additional permissions required:
appstream:DescribeAppBlockBuildersappstream:ListTagsForResource
The Security Audit role does not include the permissions. A custom role is required.
Amazon Cognito
aws-cognito-identity-provider
Additional permissions required:
cognito-idp:ListUserPoolscognito-idp:ListIdentityProviderscognito-idp:DescribeIdentityProvider
The Security Audit role includes the permissions.
Amazon Elasticsearch Service
aws-es-serverless-access-policy
Additional permissions required:
aoss:ListAccessPoliciesaoss:GetAccessPolicy
The Security Audit role does not include the permissions. You must add a custom role that includes these permissions.
Amazon Elasticsearch Service
aws-es-serverless-security-policy
Additional permissions required:
aoss:ListSecurityPoliciesaoss:GetSecurityPolicy
The Security Audit role does not include the permissions. You must add a custom role that includes these permissions.
Amazon Neptune
aws-neptune-analytics-graph
Additional permissions required:
neptune-graph:ListGraphsneptune-graph:GetGraphneptune-graph:ListTagsForResource
The Security Audit role does not include the permissions. A custom role is required.
Amazon Q Business
aws-qbusiness-index
Additional permissions required:
qbusiness:ListIndicesqbusiness:GetIndexqbusiness:ListApplicationsqbusiness:GetApplicationqbusiness:ListDataSourcesqbusiness:GetDataSource
The Security Audit role includes the permissions.
Amazon Q Business
aws-qbusiness-application
Additional permissions required:
qbusiness:ListApplicationsqbusiness:GetApplicationqbusiness:GetPolicyqbusiness:GetChatControlsConfigurationqbusiness:ListTagsForResource
The Security Audit role includes the permissions.
Amazon Route53
aws-route53-profile
Additional permissions required:
route53profiles:ListProfilesroute53profiles:GetProfileroute53profiles:ListTagsForResource
The Security Audit role does not include the permissions. A custom role is required.
Amazon Route53
aws-route53-domains-operation
Additional permission required:
route53domains:ListOperations
The Security Audit role includes the permission.
AWS Database Migration Service
aws-dms-data-provider
Additional permissions required:
dms:DescribeDataProvidersdms:ListTagsForResource
The Security Audit role includes the permissions.
AWS Database Migration Service
aws-dms-replication-config
Additional permissions required:
dms:DescribeReplicationConfigsdms:ListTagsForResource
The Security Audit role includes the permissions.
AWS Database Migration Service
aws-dms-replication-subnet-group
Additional permissions required:
dms:DescribeReplicationSubnetGroupsdms:ListTagsForResource
The Security Audit role includes the permissions.
AWS Database Migration Service
aws-dms-instance-profile
Additional permissions required:
dms:ListInstanceProfilesdms:ListTagsForResource
dms:ListTagsForResource is included in the Security Audit role. dms:ListInstanceProfiles is not included in the Security Audit role.
AWS Service Quotas
aws-servicequotas-service-quota
Additional permissions required:
servicequotas:ListServiceQuotasservicequotas:ListTagsForResource
The Security Audit role includes the permissions.
This API only supports AWS service 'VPC' quota details.
Microsoft Azure
Azure Power BI Embedded
azure-powerbi-dedicated-capacities-diagnostic-settings
Additional permissions required:
Microsoft.PowerBIDedicated/servers/readMicrosoft.PowerBIDedicated/capacities/read
The Reader role includes the permissions.
Google Cloud Platform
Google Backup For GKE
gcloud-gke-backup-backup-plan
Additional permissions required:
gkebackup.backupPlans.listgkebackup.backupPlans.getIamPolicy
The Viewer role includes the permissions.
Google Backup For GKE
gcloud-gke-backup-restore-plan
Additional permissions required:
gkebackup.restorePlans.listgkebackup.restorePlans.getIamPolicy
The Viewer role includes the permissions.
Google Cloud SQL
gcloud-sql-instance-user
Additional permission required:
cloudsql.users.list
The Viewer role includes the permission.
Google Network Security
gcloud-network-security-project-address-group
Additional permission required:
networksecurity.addressGroups.list
The Viewer role includes the permission.
Google Network Security
gcloud-network-security-organization-address-group
Additional permission required:
networksecurity.addressGroups.list
The Viewer role includes the permission.
Google Private Service Connect
gcloud-psc-service-attachment
Additional permissions required:
compute.serviceAttachments.listcompute.serviceAttachments.getIamPolicy
The Viewer role includes the permissions.
Google Private Service Connect
gcloud-psc-connection-policy
Additional permissions required:
networkconnectivity.serviceConnectionPolicies.list
The Viewer role includes the permissions.
Google Private Service Connect
gcloud-psc-network-attachment
Additional permissions required:
compute.networkAttachments.listcompute.networkAttachments.getIamPolicy
The Viewer role includes the permissions.
Oracle Cloud Infrastructure
OCI Regions
Update
Prisma Cloud now supports the following four new Oracle Cloud Infrastructure (OCI) regions:
Indonesia North (Batam) -
ap-batam-1Serbia Central (Jovanovac) -
eu-jovanovac-1Spain Central (Madrid 3) -
eu-madrid-3Italy North (Turin) -
eu-turin-1
API Updates
Amazon EventBridge
Update
aws-events-eventbus
Additional permission required:
events:DescribeEventBus
The API now ingests additional fields related to the eventbus resource.
Amazon Route 53
Update
aws-route53-list-hosted-zones
The API now ingests additional fields related to the hosted zones resource:
DelegationSet →Id CallerReference NameServers
Amazon Route53 Resolver
Update
aws-route53resolver-resolver-endpoint
The API now ingests additional attribute IpAddresses.
Additional permission required:
route53resolver:ListResolverEndpointIpAddresses
The Security Audit role includes the permission.
Amazon S3
Update
aws-s3api-get-bucket-acl
The API now ingests an additional field BucketArn related to the S3 bucket resource.
AWS Secrets Manager
Update
aws-secretsmanager-describe-secret
The API now ingests additional attribute replicationStatus.
Additional permission required:
secretsmanager:DescribeSecret
The Security Audit role includes the permission.
Azure App Service
Update
azure-app-service and azure-app-service-deployment-slots
The APIs have been updated with permission changes for App Service and App Service Deployment Slots ingestion.
Azure Storage Account Access Key
Update
azure-storage-account-access-key
The API now ingests additional parameter allowSharedKeyAccess.
Azure App Service
Update
azure-app-service-deployment-slots
The API now ingests Slot Configuration fields for Azure App Service Deployment Slots. The following additional JSON fields are now available:
config.storageTypeconfig.http20Enabledconfig.loadBalancingconfig.minTlsVersionconfig.ftpsState
The List Slot Configuration response is now stitched into the API response.
API Deprecations
Azure Orbital and Mixed Reality
Deprecation
The following Azure APIs have been deprecated as the underlying Azure services were retired:
azure-orbital-spacecrafts - Azure Orbital Ground Station was retired by Microsoft.
azure-mixed-reality-object-anchors-accounts - Azure Object Anchors (AOA) was retired by Microsoft.
These APIs will no longer ingest data.
GCP Data Catalog
Deprecation
GCP Data Catalog is deprecated and will be discontinued. The following Data Catalog APIs are deprecated on Prisma Cloud:
gcloud-data-catalog-taxonomygcloud-data-catalog-entry-groupgcloud-data-catalog-tag-template
Policy Updates
Policy Name
Details
Azure VM disk configured with overly permissive network access
Severity: Medium
Changes: The policy RQL has been updated to exclude Azure VM disks created for Prisma Cloud Azure agentless scanning (tagged with 'prismacloud-agentless-scan').
Current RQL:
Updated RQL:
Impact: Medium - Previously reported disks tagged with 'prismacloud-agentless-scan' will be resolved as Policy Updated.
Azure VM OS disk is encrypted with the default encryption key instead of ADE/CMK
Severity: Informational
Changes: The policy RQL has been updated to remove the legacy encryptionSettings attribute check.
Current RQL:
Updated RQL:
Impact: Low
GCP Dataproc Cluster on GKE is using default network
Severity: Medium
Changes: Policy RQL has been updated to cover Dataproc clusters using zonal GKE clusters.
Current RQL:
Updated RQL:
Impact: Low - New alerts will be generated as per new RQL.
GCP Dataproc Cluster on Compute Engine is using default network
Severity: Medium
Changes: Policy RQL has been updated to match GCP API.
Current RQL:
Updated RQL:
Impact: Low - New alerts will be generated as per new RQL.
Policy Deletions
Policy Updates
Description
AutoFocus Policy Deletions
Changes– Palo Alto Networks' AutoFocus product has reached its End of Life (EOL) date. As a result, the following AutoFocus Anomaly policies will be removed from Prisma Cloud. Learn more about AutoFocus EOL.
Traffic to a suspicious IP address associated with Loader activity
Traffic from a suspicious IP address associated with File Infector activity
Traffic to a suspicious IP address associated with File Infector activity
Traffic from a suspicious IP address associated with Dropper activity
Traffic to a suspicious IP address associated with Ransomware activity
Traffic to a suspicious IP address associated with Backdoor activity
Traffic to a suspicious IP address associated with Cryptominer activity
Traffic from a suspicious IP address associated with Botnet activity
Traffic from a suspicious IP address associated with Cryptominer activity
Traffic from a suspicious IP address associated with Ransomware activity
Traffic to a suspicious IP address associated with Linux Malware activity
Traffic to a suspicious IP address associated with Botnet activity
Traffic from a suspicious IP address associated with Backdoor activity
Traffic from a suspicious IP address associated with Linux Malware activity
Traffic from a suspicious IP address associated with Remote Access Trojan activity
Traffic to a suspicious IP address associated with Remote Access Trojan activity
Traffic from a suspicious IP address associated with DDoS activity
Traffic from a suspicious IP address associated with InfoStealer activity
Traffic to a suspicious IP address associated with DDoS activity
Traffic to a suspicious IP address associated with InfoStealer activity
Traffic from a suspicious IP address associated with Wiper activity
Traffic to a suspicious IP address associated with Wiper activity
Traffic to a suspicious IP address associated with Dropper activity
Traffic from a suspicious IP address associated with Loader activity
Traffic from a suspicious IP address associated with Rootkit activity
Traffic to a suspicious IP address associated with Webshell activity
Traffic from a suspicious IP address associated with Webshell activity
Traffic to a suspicious IP address associated with Rootkit activity
Traffic to a suspicious IP address associated with Exploit Kit activity
Traffic from a suspicious IP address associated with Exploit Kit activity
Traffic to a suspicious IP address associated with Hacking Tool activity
Traffic from a suspicious IP address associated with Hacking Tool activity
Traffic from a suspicious IP address associated with Worm activity
Traffic to a suspicious IP address associated with Worm activity
Traffic from a suspicious IP address associated with Downloader activity
Traffic to a suspicious IP address associated with Downloader activity
Impact– Keep in mind the following potential effects of this change:
* Existing alerts will be resolved as Policy_Deleted.
* All policies related to AutoFocus will be deprecated.
* Attack Path policies associated with AutoFocus will be deprecated.
* RQL support for AutoFocus suggestions will be removed.
* The ability to add trusted IP addresses to AutoFocus anomaly polices will be deprecated.
* Any custom policies that use AutoFocus attributes will also be impacted.
Compliance Updates
Compliance Standard
Details
CIS Amazon Web Services Foundations Benchmark v6.0.0
Prisma Cloud now supports CIS Amazon Web Services Foundations Benchmark v6.0.0 Level 1 and Level 2.
Level 1 defines a set of fundamental, broadly applicable security best practices that harden core AWS services while minimizing impact on usability and operations for most environments.
Level 2 builds on this with more stringent, defense-in-depth requirements intended for organizations with elevated risk or regulatory needs.
You can view this built-in standard and the associated policies on the Compliance > Standards page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.
CIS Microsoft Azure Foundations Benchmark v5.0.0
Prisma Cloud now supports CIS Microsoft Azure Foundations Benchmark v5.0.0 Level 1 and Level 2.
Level 1 provides baseline, broadly applicable security controls designed to strengthen an Azure environment without causing significant disruption to usability or operations.
Level 2 introduces more stringent, defense-in-depth controls intended for organizations with heightened security or regulatory requirements.
You can view this built-in standard and the associated policies on the Compliance > Standards page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.
Last updated
Was this helpful?

