> For the complete documentation index, see [llms.txt](https://docs.cybaops.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cybaops.com/modules/vulnerability-management.md).

# Vulnerability Management

### <mark style="color:$primary;">Managing your Vulnerabilities with CybaOps</mark>&#x20;

CybaOps has a powerful vulnerability manager that can help businesses manage their vulnerabilities efficiently. With false positive tracking, continuous scanning and easy-to-follow remediation advice, it’s the perfect tool for SMEs to level up their cyber security. &#x20;

### <mark style="color:$primary;">What is Vulnerability Management?</mark>&#x20;

Vulnerability management is the ongoing process of identifying, assessing, prioritising, and remediating security weaknesses across your organisation’s systems, applications, and assets. For SMEs, it provides a structured, repeatable approach to reducing cyber risk by ensuring that the most impactful vulnerabilities are addressed quickly and consistently.&#x20;

### <mark style="color:$primary;">Key Elements of the Vulnerability Manager in CybaOps</mark>&#x20;

You can find a link to the Vulnerability Manager in the main navigation under Identify & Protect.

<figure><picture><source srcset="/files/3aLszjlcLxc29ZEU2Mtg" media="(prefers-color-scheme: dark)"><img src="/files/NvY15EXzl0tQeynFPmaB" alt=""></picture><figcaption></figcaption></figure>

The vulnerability manager is filtered to show vulnerabilities with the status of “Open”.&#x20;

<figure><picture><source srcset="/files/rHxaexl6rRNj9c8SJHK3" media="(prefers-color-scheme: dark)"><img src="/files/PNl2n1mdLhi7R9vxNgqd" alt=""></picture><figcaption></figcaption></figure>

You can also view vulnerabilities with the following status: Pending, Closed and False Positive vulnerabilities by selecting the relevant option in this filter.&#x20;

### <mark style="color:$primary;">Filtering your Vulnerabilities</mark>&#x20;

The Vulnerability Manager table supports persistent filters and scroll position (filters and scroll position is retained when navigating away and back to the table), allowing you to maintain your view as you navigate the platform.&#x20;

Filters can be applied using the filter pills at the top of the table. To reset all applied filters, select the Reset button located next to the filters.&#x20;

Once the vulnerability table has loaded, a timestamp is displayed in the top-right corner showing when the data was last refreshed. This indicates the last time the table was loaded, not when the most recent scan was performed.&#x20;

<figure><picture><source srcset="/files/KKINDneD8PX80813m5RN" media="(prefers-color-scheme: dark)"><img src="/files/EZlIvLOp2O5UcyPzHVXh" alt=""></picture><figcaption></figcaption></figure>

The Refresh button updates the vulnerability data in the table while preserving any active filters. This is particularly useful when working through a filtered list and marking vulnerabilities as fixed. As the table does not automatically update, clicking refresh will update the table data, and in turn the status of the vulnerabilities.

{% hint style="info" %}
If you want to see when your vulnerability scans were last run, visit the schedules page.&#x20;
{% endhint %}

***

### <mark style="color:$primary;">Vulnerability Status</mark>&#x20;

Vulnerability status outlines the current state of the vulnerability. CybaOps allows customers to filter vulnerabilities by status. Do this by selecting the relevant status in the pill filter.&#x20;

#### Vulnerabilities with the status: Open&#x20;

An Open vulnerability is an active vulnerability that is currently present on one or more assets.&#x20;

#### Vulnerabilities with the status: Pending&#x20;

Vulnerabilities with the status Pending are currently being verified by a scan to see if the vulnerability exists. This status is automatically applied when a vulnerability is marked as fixed. It is also automatically updated when the scan has completed and the vulnerability has been verified or not.&#x20;

#### Vulnerabilities with the status: Closed&#x20;

A vulnerability with the status of Closed is no longer present within the tenancy. &#x20;

#### Vulnerabilities with the status: False Positive&#x20;

A vulnerability with the status of False positive is a vulnerability that has been marked as a false positive by a user. You can view the user who took this action and any notes in the vulnerability detail screen. &#x20;

***

### <mark style="color:$primary;">Vulnerability Severity</mark>&#x20;

Vulnerability severity reflects how dangerous a security weakness is by measuring its potential impact and the ease with which it can be exploited. In SMEs, understanding severity helps teams prioritise limited resources toward fixing the vulnerabilities that pose the highest risk to the business.&#x20;

CybaOps allows customers to filter vulnerabilities by severity. Do this by selecting the relevant severities in the filter. &#x20;

<figure><picture><source srcset="/files/Ec1klRjlbiPhbn9de71S" media="(prefers-color-scheme: dark)"><img src="/files/2IgsnQcMNb9yH4XGeNMB" alt=""></picture><figcaption></figcaption></figure>

#### Vulnerabilities with the severity: Critical&#x20;

Critical vulnerabilities are security weaknesses with the highest potential impact, often allowing attackers to gain full control, disrupt operations, or access sensitive data with minimal effort. For SMEs, addressing critical vulnerabilities immediately is essential to prevent severe breaches that could significantly harm business continuity and trust.&#x20;

#### Vulnerabilities with the severity: High&#x20;

High-severity vulnerabilities pose significant risk because they are impactful and often exploitable, but may require more specific conditions than critical issues. For SMEs, promptly addressing high vulnerabilities helps reduce the likelihood of major security incidents that could disrupt operations or expose important data.&#x20;

#### Vulnerabilities with the severity: Medium&#x20;

Medium-severity vulnerabilities present a moderate risk, typically requiring specific conditions to be exploited and causing limited impact if compromised. For SMEs, managing medium vulnerabilities helps maintain overall security hygiene and prevents them from escalating into more serious threats.&#x20;

#### Vulnerabilities with the severity: Low&#x20;

Low-severity vulnerabilities pose minimal risk, often requiring complex conditions to exploit and resulting in limited impact. For SMEs, tracking and addressing low vulnerabilities helps maintain comprehensive security awareness without diverting resources from higher-priority issues.&#x20;

#### Vulnerabilities with the severity: Informational&#x20;

Informational vulnerabilities do not pose a direct security risk but provide details about systems or configurations that could be useful to an attacker. For SMEs, reviewing informational findings helps improve overall security awareness and supports proactive risk management.&#x20;

***

### <mark style="color:$primary;">Affected Assets</mark>&#x20;

You can filter your vulnerabilities by affected assets. Your assets will be selectable and searchable in the pill filter. This will show you the vulnerabilities against the selected asset/s. &#x20;

<figure><picture><source srcset="/files/JV6vKbfS10ph63SXexok" media="(prefers-color-scheme: dark)"><img src="/files/rnhzCyNRx2JPqJPtOgpc" alt=""></picture><figcaption></figcaption></figure>

***

### <mark style="color:$primary;">Individual Vulnerability View</mark>&#x20;

Each vulnerability has a detailed view where you can access the following information:&#x20;

* Description&#x20;
* Impact&#x20;
* Recommendation&#x20;
* Evidence&#x20;
* Vulnerability details&#x20;

<figure><picture><source srcset="/files/nZvx6nga93uVrke5IDiR" media="(prefers-color-scheme: dark)"><img src="/files/gClttmvuelM21PoQJvud" alt=""></picture><figcaption></figcaption></figure>

#### Vulnerability description&#x20;

This includes an overview of the vulnerability itself. It will contain a top-level description of the vulnerability. &#x20;

#### Impact&#x20;

The impact outlines the potential impact to systems should this vulnerability be exploited.&#x20;

#### Recommendation&#x20;

The recommendation will include remediation advice on how to resolve the vulnerability. It may include links to patches or updates released by vendors. &#x20;

#### Evidence&#x20;

This section will include screenshots or evidence of where this vulnerability has been identified by the scanning tool. If there is more than one affected asset, the evidence will be available in the affected asset tab, under the three dots.&#x20;

<figure><picture><source srcset="/files/riq6W0MIuoAccT56UaAu" media="(prefers-color-scheme: dark)"><img src="/files/FUOmIO91L1Dqw0xkESwM" alt=""></picture><figcaption></figcaption></figure>

#### Vulnerability details&#x20;

Vulnerability details includes key information regarding the vulnerability. Including the Severity, CVSS, CVE, First Found and Last Found. You can mark vulnerabilities as fixed or as false positive. &#x20;

#### CVSS&#x20;

The Common Vulnerability Scoring System (CVSS) provides a standardised method for rating the severity of security vulnerabilities based on their impact and exploitability. In vulnerability management, CVSS scores help teams prioritise remediation efforts by highlighting which issues pose the greatest risk to the organisation.&#x20;

CVSS is rated out of 10, 10 being the highest and most critical vulnerability. &#x20;

#### CVE&#x20;

The Common Vulnerabilities and Exposures (CVE) system provides unique identifiers for publicly disclosed security vulnerabilities, creating a universal reference that security teams can rely on. In vulnerability management, CVE IDs enable consistent tracking, communication, and correlation of vulnerabilities across tools and advisories.&#x20;

#### First found&#x20;

This is when the vulnerability was first discovered on your system on any asset. &#x20;

#### Last found&#x20;

This is when the vulnerability was last detected on any asset.&#x20;

***

### <mark style="color:$primary;">Marking a Vulnerability as False Positive</mark>&#x20;

A vulnerability should be marked as a false positive when you can confidently verify that the reported issue does not actually exist, cannot be reproduced, or poses no real-world security risk under the system’s current configuration. This designation is appropriate only after thorough validation to ensure the finding results from scanner limitations, outdated signatures, or benign conditions rather than a genuine weakness.&#x20;

When marking a vulnerability as a false positive you will be asked for a reason, and this will be logged with the vulnerability.&#x20;

Once marked as false positive, you will have the option to mark is back as a true positive. Marking it as a true positive will set the vulnerability status back to Open.&#x20;

### <mark style="color:$primary;">Marking a Vulnerability as Fixed</mark>&#x20;

Marking a vulnerability as fixed will trigger a verification on that vulnerability against all affected assets. You will be asked to confirm this in the platform before the check is done.  &#x20;

The vulnerability will be verified within 24 hours. If the vulnerability is remediated on all devices, it will be marked as closed. &#x20;

If the vulnerability is resolved on an asset, you will see the asset moved to previous assets. &#x20;

If the verification has not been resolved on any assets, the status will be moved back to open and the affected assets will be listed. &#x20;

***

### <mark style="color:$primary;">Viewing Affected Assets</mark>&#x20;

Each vulnerability has an affected assets tab. In this tab you can see all assets that are currently affected by this vulnerability. You can view the asset detail or specific evidence against the asset by clicking the three dots. &#x20;

<figure><picture><source srcset="/files/riq6W0MIuoAccT56UaAu" media="(prefers-color-scheme: dark)"><img src="/files/FUOmIO91L1Dqw0xkESwM" alt=""></picture><figcaption></figcaption></figure>

If a vulnerability is remediated on some but not all assets, it will remain open, but the assets it no longer exists on it will be moved to previous assets.&#x20;

### <mark style="color:$primary;">Viewing Previously Affected Assets</mark>&#x20;

Each vulnerability has a previously affected assets tab. In this tab you can see all assets that are previously affected by this vulnerability. You can view the asset detail or specific evidence against the asset by clicking the three dots. &#x20;

<figure><picture><source srcset="/files/XrrBvPL0fqwjUBmx69uJ" media="(prefers-color-scheme: dark)"><img src="/files/6HEpKXEpUDYYKIEs6pUU" alt=""></picture><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cybaops.com/modules/vulnerability-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
