OpenText SAST 26.2: Why this release matters for enterprise AppSec and software delivery
OpenText documents this version in its OpenText SAST 26.2 release notes.
OpenText SAST 26.2 focuses on a practical requirement for large software organizations: security tools must keep pace with the platforms and languages development teams already use. When security scanners fall behind engineering standards, release pipelines slow down, governance gaps appear, and risk reporting loses credibility.
This release is important because it strengthens three enterprise priorities:
- Coverage across modern and legacy technology stacks
- Consistent policy enforcement in CI/CD
- Better evidence for audits and security reviews
For engineering leaders, these updates affect more than AppSec. They influence delivery velocity, platform modernization, and board-level software supply chain risk reporting.
Why platform compatibility matters to enterprise teams
Enterprise application portfolios rarely run on a single stack. Most organizations operate a mix of cloud-native applications, mobile platforms, and legacy systems. Security tools need to support all of them without forcing exceptions.
OpenText SAST 26.2 adds support for newer operating systems and build environments. This includes support for current Windows Server and macOS environments used in enterprise build farms.
This matters because:
- Security teams can standardize secure build runners
- Platform teams can retire unsupported analysis hosts
- Audit teams can validate that security controls run on approved infrastructure
For regulated industries, unsupported security infrastructure creates governance exposure. A scanner that only runs on older nodes often becomes an audit exception.
Language support directly affects modernization programs
Modernization projects often fail to account for security tool compatibility. When a development team upgrades Kotlin, Swift, or PHP versions, static analysis must continue to run with the same policies and release gates.
OpenText SAST 26.2 expands support for newer language versions including Kotlin, Swift, C++, and PHP. It also expands AI-powered static analysis for older languages such as COBOL and Fortran.
This creates business value in two ways:
- Product teams can adopt newer frameworks without changing security workflows
- Legacy applications can be brought into the same governance model as modern services
For CIOs and CISOs, this closes a common blind spot. Legacy code often supports critical revenue operations but remains outside consistent security testing programs.
AI-powered SAST becomes a governance capability
AI in application security only matters when it improves repeatability and traceability. OpenText SAST 26.2 introduces support for GPT-5 compatible models through both Microsoft Azure and OpenAI, along with AI-agent instruction files.
This matters because enterprises can define controlled AI behavior for analysis workflows.
A mature rollout typically includes:
- Standardized prompt instruction files stored in source control
- Approval workflows for AI-generated findings
- Audit logs tied to security scan decisions
- Enterprise policies mapped to model provider selection
This gives leaders a path to use AI-assisted static analysis while maintaining governance standards.
Signal quality matters more than raw findings volume
Security teams do not need more findings. They need findings that teams trust enough to act on during release windows.
OpenText SAST 26.2 improves default scan policy filtering to reduce low-accuracy buffer overflow findings. It also adds clearer policy comments so teams understand what was filtered and why.
The operational result is measurable:
- AppSec analysts spend less time closing false positives
- Developers focus on exploitable vulnerabilities
- Release managers make go/no-go decisions with stronger evidence
This improves remediation throughput and reduces security-related release delays.
What this means for enterprise delivery leaders
This release reflects a broader trend: static application security testing is becoming part of the delivery platform, not a standalone security tool.
Leaders evaluating AppSec maturity should use releases like this to review:
- Whether current CI/CD pipelines support supported toolchains
- Whether legacy applications are included in static analysis coverage
- Whether AI-assisted scanning has governance controls
- Whether security reporting maps to executive risk metrics
Organizations that treat SAST as infrastructure usually gain better release predictability and stronger audit readiness.
Why enterprises work with Merito for OpenText SAST adoption
Many enterprises buy security tools but struggle to operationalize them across teams. Merito acts as a value-added partner for OpenText solutions by helping organizations implement, optimize, and renew enterprise AppSec programs.
Merito helps customers:
- Deploy OpenText SAST in CI/CD pipelines
- Standardize policy templates across portfolios
- Build audit-ready evidence workflows
- Design upgrade strategies for new language and platform support
- Optimize AI-powered static analysis for governance and scale



