 Distribution A: Approved for Public Release (16 Feb 2021) NIWCLANT SPR# 2021-52

 SCAP Compliance Checker Release Notes                   Aug 27, 2026   15:28:21
 Naval Information Warfare Center (NIWC) Atlantic
 https://www.niwcatlantic.navy.mil/scap/


 SCAP Compliance Checker 5.15 Features Added
 ===============================================================================
 Type     IssueID  Summary
 -------------------------------------------------------------------------------
 Feature  33266    Add GUI and CLUI methods to accept all SSH hostkey changes
                   (due to Key Exchange Algorithm update with updated libssh2)

 Feature  33265    Add command line parameter to verify ssh connections
                   --verifySSHHost [HOSTID|ALL]

 Feature  33258    Redesign cscc --help page for easier usage, and examples all
                   at the end

 Feature  33256    Update DISA CCI mappings based on 07-15-2026 release of
                   CCI_List.xml

 Feature  33254    Update command line to not automatically refresh content
                   directories on every launch to speed up get/set options
                   parameters

 Feature  33253    Add new command line parameter '--refreshContent', which
                   forces SCC to rescan content directories

 Feature  33247    Add NIWC developed STIG/SCAP benchmarks for F5 NGINX

 Feature  33244    Update RHEL based app whitelisting to work with new linux
                   remote SSH platforms

 Feature  33233    Update Linux builds to use OS default file viewer
                   (de-escalated) to view SCC's reports, vs custom SCC report
                   viewer  

 Feature  33231    Add Import and Export functionality to Manual Questions form

 Feature  33230    Consolidate Linux builds to a single x86_64 and single
                   aarch64 build

 Feature  33229    Add NWIC created SCAP content for Tomcat Server 9 (RHEL and
                   RHEL variants only)

 Feature  33228    Add NWIC created SCAP content for Microsoft Exchange 2019/SE

 Feature  33227    Add support for Amazon Linux 2023

 Feature  33217    Update windows ntuser test based on OVAL 5.12.3 to add
                   item/state element of 'user_has_signed_into_explorer'

 Feature  33216    Update SCC to save OVAL results in 5.12.3

 Feature  33215    Add support for new OVAL 5.12.3 item creation behavior in
                   XMLFileContent and TextFileConten54 tests

 Feature  33212    Update windows ntuser test based on OVAL 5.12.3 to support
                   new 'item_creation' behavior

 Feature  33211    Add support for OVAL 5.12.3

 Feature  33210    Update independent shellcommand to support new OVAL 5.12.3
                   behaviors of 'error_if_stderr_exists' and
                   'error_if_exit_status_not_0

 Feature  33204    Update SCC's upgrade feature to install existing Deviations
                   files from existing installation to new

 Feature  33199    Update SCC's upgrade feature to install existing Tailoring
                   files from existing installation to new

 Feature  33193    Add option to share Tailoring file across different versions
                   of SCAP benchmarks



 SCAP Compliance Checker 5.15 Defects Resolved
 ===============================================================================
 Type     IssueID  Summary
 -------------------------------------------------------------------------------
 Defect   33269    Fix errors reported with SCAP 1.3 interoperability option to
                   generate results even if content is N/A

 Defect   33264    Update SSH to add support for curve25519-sha256 Key Exchange
                   (KEX) algorithms

 Defect   33261    Patch libssh2 v1.1.1 to resolve CVE-2025-15661, CVE
                   2026-15661, 55199, 55200, 58050, 58051, 66032, 66033, 66034,
                   66035   

 Defect   33236    Update XML schema validation to use non-DOM method to
                   decrease memory usage

 Defect   33234    Update SSH scanning to support new linux Intel/AMD64 and
                   arm/aarch64 based scanning (from OS specific methods)

 Defect   33226    Fix SCC crash on certain Windows 11 systems when gathering
                   local security policy data

 Defect   33223    Fix Deviation import from GUI and CLUI to rename file to
                   match expected format

 Defect   33220    Add error handling to report that most Exchange Server tests
                   cannot be performed remotely due to system constraints

 Defect   33218    Add multiple attempts to save SCC's options.xml due to
                   potential race condition/file lock by Windows Defender

 Defect   33213    Fix issues with CKLB file being imported into eMASS

 Defect   33209    SCC created CKL reports have issues when imported into STIG
                   Viewer 3.x and exporting CSV output

 Defect   33207    Update Remote WMI/SSH scanning form to be more sizable

 Defect   33202    Fix issues with tailoring form and saving refine/set Values

 Defect   33201    Update deviations to be shared across versions of the same
                   benchmarkID

 Defect   33200    Update Tailoring to perform partial matches (ignore DISA's
                   embedded version in the ruleID) when sharing between content
                   versions

 Defect   33198    Add option for windows ntuser to create items when an
                   ntuser.dat file exists vs objects key/name

 Defect   33195    Improve window resizing for remote WMI/SSH scans

 Defect   33191    Fix command line -is, -isr, --checkForContentUpdates,
                   --InstallUpdates to disable/move/del older content (if
                   option is enabled)

 Defect   33137    Update OVAL XML Results schema location to:
                   https://raw.githubusercontent.com/OVAL-Community/OVAL/refs/tags/v5.12.3/oval-schema

 Defect   33115    Update internal version of OpenSSL to version 3.6.3 dated 9
                   Jun 2026

