Patch Management
Patch management is the systematic process of identifying, acquiring, testing, and deploying software updates (patches) to fix security vulnerabilities and bugs. EPSS scores and CISA KEV membership help security teams prioritize which patches to apply first when resources are limited.
Frequently Asked Questions
What is Patch Management?
Patch management is the systematic process of identifying, acquiring, testing, and deploying software updates (patches) to fix security vulnerabilities and bugs. EPSS scores and CISA KEV membership help security teams prioritize which patches to apply first when resources are limited.
How is Patch Management related to CVE (Common Vulnerabilities and Exposures)?
Patch Management and CVE (Common Vulnerabilities and Exposures) are both key concepts in threat intelligence. CVE is a public catalogue of known cybersecurity vulnerabilities, maintained by MITRE and sponsored by CISA. Each entry has a unique CVE ID (e.g., CVE-2024-12345), a description, and references. CVE IDs are the universal language for tracking and patching specific vulnerabilities.
Related Terms
CVE (Common Vulnerabilities and Exposures)
CVE is a public catalogue of known cybersecurity vulnerabilities, maintained by MITRE and sponsored by CISA. Each entry has a unique CVE ID (e.g., CVE-2024-12345), a description, and references. CVE IDs are the universal language for tracking and patching specific vulnerabilities.
KEV (CISA Known Exploited Vulnerabilities)
The CISA KEV catalog lists CVEs that have been confirmed as actively exploited in the wild. US federal agencies are required to patch KEV vulnerabilities by mandated due dates. KEV status is the highest-urgency signal for vulnerability prioritization.
EPSS (Exploit Prediction Scoring System)
EPSS is a data-driven model from FIRST.org that estimates the probability a CVE will be exploited in the wild within the next 30 days. Scores range from 0 to 1 (0%–100%). EPSS helps prioritize patching by combining NVD data with real-world exploitation observations.
SBOM (Software Bill of Materials)
An SBOM is a formal inventory of all software components and dependencies in an application — similar to an ingredient list. SBOMs are used to rapidly identify which systems are affected when a vulnerability (like Log4Shell) is discovered in a common dependency.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.