OWASP ZAP

ZAP-Team · current 2.17.0

Are you ZAP-Team? Claim this page

The current version of OWASP ZAP is 2.17.0 (as of 15/12/2025). patchletter checks the official source daily and emails you new releases.

OWASP ZAP at a glance

OWASP ZAP (Zed Attack Proxy) is a widely used open-source web-application security scanner, for finding vulnerabilities in web apps during authorized testing. ZAP ships regular releases plus frequently updated add-ons; keeping both current keeps its detection useful.

For admins (and security testers) ZAP is a dual-use tool: legitimate for authorized testing and CI security checks, and powerful, so use it deliberately. The update driver is detection coverage — the core and the marketplace add-ons update regularly, so keep them current. The critical caveat is authorization: only scan applications you own or are explicitly permitted to test, since active scanning can disrupt targets and unauthorized testing is unlawful. Run it from a controlled environment. It integrates into CI/CD for automated security testing — a good practice worth adopting. After updating, verify that scans run and add-ons load. Patchletter surfaces new ZAP releases so testers stay current.

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
2.17.0STABLE15/12/2025Release notes →
2.16.1STABLE25/03/2025Release notes →
2.16.0STABLE10/01/2025Release notes →

Frequently asked questions

What is the latest version of OWASP ZAP?
OWASP ZAP 2.17.0, released 15/12/2025. patchletter checks the vendor's official source daily for new releases.
Where can I find the OWASP ZAP release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new OWASP ZAP updates?
Tick OWASP ZAP off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new OWASP ZAP version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current OWASP ZAP version and keeps it up to date. Anyone may embed it, no account needed.

OWASP ZAP badge
[![OWASP ZAP](https://patchletter.com/badge/owasp-zap.svg)](https://patchletter.com/en/software/owasp-zap)
https://patchletter.com/badge/owasp-zap.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Firewalls & Security