# Cursor Security Review: always-on security agents, beta on Teams/Enterprise

> Cursor ships a beta security review product with two always-on agents: a Security Reviewer that comments on every PR, and a scheduled Vulnerability Scanner. Both are customizeable, including plugging in your own scanners via MCP.

| | |
|---|---|
| **Tool** | Cursor |
| **Version** | — |
| **Kind** | announcement |
| **Published** | 2026-04-30 |
| **Observed** | 2026-08-11 |
| **Significance** | 4/5 |
| **Breaking** | no |
| **Categories** | feature, security, capability |

## What changed


- Beta on Teams and Enterprise plans; admins enable it in the dashboard
- **Security Reviewer**: checks every PR for vulnerabilities, auth regressions, privacy/data-handling risks, agent tool auto-approvals, and prompt injection; leaves inline severity+remediation comments at the exact diff location
- **Vulnerability Scanner**: scheduled codebase scans for known vulnerabilities, outdated dependencies, config issues; can post findings to Slack
- Customizable: adjust triggers, add instructions, custom tooling, choose output sharing; can wire in existing SAST/SCA/secrets scanners via MCP servers
- Security agents draw from your existing usage pool


## Sources

- [blog_rss](https://cursor.com/changelog/04-30-26) — retrieved 2026-08-11


## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/cursor/cursor-security-review-always-on-security-agents-beta-on-teams-enterprise
Entity: https://changelogs.info/cursor
Event ID: `evt_2026-04-30_cursor_cursor-security-review`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
