User guideVulnerabilities

Understand vulnerabilities

PatchPilot compares what each host has installed with public vulnerability data: the operating system vendors' advisories, OSV, the US National Vulnerability Database (NVD), CISA's list of known exploited vulnerabilities, and the EPSS likelihood of exploitation. Every host is checked again every 12 hours.

See them for one host on its Vulnerabilities tab, or for the whole estate on Vulnerabilities.

Why more vulnerabilities than updates?

A vulnerability is one CVE in one package. An update is one package. One update usually closes several CVEs (a single curl or Python update can close ten), so a host with 22 updates can have 60 vulnerabilities. Patching the updates removes most of them at once.

Labels

Label Means
Fix available An update that fixes it is offered to this host now: patch it
Not offered yet A fixed version exists, but the host's package source does not offer it yet; it turns into an update when it does
Restart to apply The fix is installed but the host has not restarted (a kernel, for example)
Known exploited Attackers are using it now (CISA's list): patch these first
Third-party Software that does not come from the operating system's vendor

By default the lists show what you can act on. Fix available narrows to findings with an update now, and Known exploited only to the urgent ones.

Third-party software coverage

The Third-party software panel says, for instance, "2 of 9 third-party packages have CVE coverage". It means PatchPilot found the other seven programs installed but the public vulnerability data has no entry it can match them to, so it cannot judge them either way. Browser shortcuts (web apps such as Gmail or Docs) and hardware drivers are typical. It is not a finding; it tells you where PatchPilot cannot see.

Risk score

Each host also gets a risk score from its findings, how critical the host is (set its business context under Asset details), whether it faces the internet, and how likely its vulnerabilities are to be exploited.