Prioritize endpoint vulnerability findings with asset, package, severity, and remediation context.
XDRShield Vulnerabilities helps teams review vulnerability evidence, understand affected endpoints and software context, prioritize by severity and exposure, and move remediation decisions into accountable operational workflows.
Vulnerability lists only help when teams can turn them into prioritized action.
Security teams need to know what is affected, how severe it is, whether endpoint evidence is current, and which remediation path should be followed. Vulnerabilities connects findings to endpoint, package, tenant, and operational context so teams can reduce risk without losing traceability.
Turn vulnerability evidence into scoped remediation work.
The Vulnerabilities workflow helps teams move from a finding to affected assets, software context, prioritization, remediation planning, and follow-up validation. It should be used with installed package inventory, agent health, software deployment, cases, and activity logs when decisions need evidence.
- Review vulnerability severity, affected endpoints, package/version context, and tenant scope.
- Use filters and search to narrow findings by endpoint, software, severity, or customer.
- Validate evidence freshness before remediation decisions or reporting.
- Track remediation outcomes through package changes, deployment activity, cases, and audit logs.

What XDRShield Vulnerabilities helps teams do.
Each capability supports the operating workflow for vulnerabilities, from review and prioritization to action, governance, and follow-up.
Severity-based review
Prioritize critical and high findings while preserving context for medium and low items.
Affected asset scoping
Find endpoints, packages, versions, or tenants connected to a vulnerability.
Package evidence
Use installed package data to understand which software versions may be affected.
Freshness check
Confirm agent and inventory reporting recency before treating vulnerability evidence as current.
Remediation planning
Use software deployment, patching, or upgrade workflows to reduce exposure.
Case handoff
Move important or disputed findings into case workflows for ownership and tracking.
Risk reduction evidence
Validate that affected packages or endpoints changed after remediation.
Tenant-scoped vulnerability operations
Review customer vulnerability evidence without mixing tenant scope.
From vulnerability finding to verified risk reduction.
A clear workflow keeps vulnerability review practical and evidence-backed.
Select tenant and asset scope
Work from the correct customer, endpoint group, or operating environment.
Prioritize by severity and exposure
Start with high-impact findings, affected count, and business context.
Validate affected software
Use installed packages and version evidence to confirm likely exposure.
Check freshness
Confirm agent and package telemetry recency before reporting or remediation.
Plan remediation
Coordinate upgrade, patch, deployment, exception, or case ownership.
Verify closure
Recheck package and vulnerability evidence after remediation activity.
Where Vulnerabilities helps most.
Use Vulnerabilities when endpoint exposure needs prioritization, tracking, and customer-ready evidence.
Critical vulnerability triage
Prioritize urgent findings by severity and affected endpoint scope.
Exposure scoping
Find systems affected by a specific CVE, package, or version.
Patch and upgrade planning
Connect findings to software deployment or remediation work.
Freshness validation
Avoid reporting stale exposure by checking endpoint inventory recency.
Service review evidence
Prepare customer-facing vulnerability summaries with supporting context.
MSP risk operations
Manage customer-specific vulnerability queues without mixing tenants.
Use severity with context, not severity alone.
This table helps teams decide which findings need action first.
| Area | What it means | How teams use it |
|---|---|---|
| Critical / High | Potentially high-impact vulnerabilities or exposed endpoint groups. | Prioritize validation, ownership, and remediation planning. |
| Medium / Low | Findings that may still matter based on endpoint role, exposure, or recurrence. | Batch, schedule, or monitor with business context. |
| Affected package/version | Software evidence that supports the finding. | Use installed package inventory to validate scope. |
| Freshness and endpoint health | Whether telemetry is current enough to trust. | Recheck stale endpoints before reporting closure or exposure. |
Vulnerabilities for security, IT, and MSP teams.
Vulnerabilities supports day-to-day operations while keeping endpoint, tenant, and evidence scope clear.
For security and IT teams
Use this feature to make endpoint, risk, deployment, and tenant decisions from current operational evidence.
- Validate scope before broad changes.
- Review endpoint or tenant context before acting.
- Use alerts, events, cases, and activity logs for follow-up evidence.
For MSP and service-provider teams
Use tenant-aware workflows so customer environments remain separated while repeatable operations stay consistent.
- Confirm tenant/customer scope before bulk action.
- Standardize review patterns without mixing customer evidence.
- Preserve accountability for customer-facing service reviews.
Vulnerabilities FAQs.
What is Vulnerabilities in XDRShield?
Vulnerabilities helps teams review vulnerability findings with severity, affected endpoint, package, version, tenant, and remediation context where evidence is available.
How should teams prioritize vulnerabilities?
Start with severity and affected endpoint scope, then consider package evidence, business criticality, exploitability context, freshness, and tenant impact.
Why is installed package data important?
Package names and versions help validate which endpoints may be affected and whether remediation changed the endpoint state.
How should stale vulnerability evidence be handled?
Check agent health, inventory freshness, and recent package reporting before reporting exposure or closure.
How does this support MSPs?
MSPs can manage customer-specific vulnerability evidence, prioritization, and service review reporting while preserving tenant separation.
Use endpoint, package, and severity context to reduce risk.
Use XDRShield Vulnerabilities to scope affected systems, prioritize findings, plan remediation, and verify risk reduction with tenant-aware evidence.













