

The Application Vulnerability Report is an SAP BTP service that continuously detects vulnerabilities in Cloud Foundry applications. It automatically identifies known CVEs in container images and build artifacts—no agents or extra configuration required—and delivers findings via a REST API for CI/CD pipelines as well as a self-service overview in the BTP Cockpit. Application-level findings and status reports help demonstrate compliance with frameworks such as DORA, NIS2, ISO 27001, SOC 2, and PCI DSS. The service has been available in beta since December 2025, and the BTP Cockpit UI was released in April 2026.
