Loading
  • Public
  • Broadcast OnlyThis group is for broadcast messages. Only group managers can post content.

Software Vulnerability Manager

Skip Feed
  1. The SVM August 2026 update is now live.

     

    Following improvements are now available in SVM Cloud.

     

    Duplicate Subscription Warning for SPS and VPM Patches

    This feature is available for both SVM UI and Patch Publisher.

    Continuing with the previous release which shows visibility on duplicate subscription, now when users subscribe to a patch that has already been subscribed to, SVM/Patch Publisher displays a Duplicate Subscription warning identifying the existing subscriber, and prompts users to continue or cancel the subscription.

    • If the new subscription request exactly matches an existing subscription, the duplicate subscription is prevented.
    • If the package has assigned groups that partially overlap with an existing subscription, the conflicting groups are automatically removed from the new subscription, and the subscription proceeds for the remaining non-conflicting groups.

    This enhancement improves subscription management by reducing duplicate subscriptions while allowing valid group-based subscriptions to continue.

     

    Updated Administrator-Initiated Password Reset Workflow

    Password reset email notifications will guide users to complete the password reset process through the Set Your Password page, providing a more streamlined and secure password resetting experience.

     

    New Database View for Device Application State Reporting

    A new database view,

    vw_csi_device_application_state

     

    , has been added to the Database Console to simplify application state reporting across managed devices. The view consolidates application inventory, version, security status, criticality, and installation path information into a single queryable source, enabling easier reporting and integration with external business intelligence and compliance processes.

     

    User Interface Improvements

    Software Vulnerability Manager (SVM) includes minor user interface styling updates to improve visual consistency across the application. The overall layout, menu options, and their placement in the user interface remain the same.

     

    For release notes, refer here.

    Expand Post

  2. The SVR August update is now live.

     

    The update includes addition of CISA KEV and EPSS scores in UI and API.

     

    The vulnerability database page feature a CISA KEV filter to quickly identify which CVEs are present in the CISA catalog. CVE details page include CISA KEV (Yes/No), EPSS score and EPSS percentile. All the three attributes are available in the API as well.

     

    For details, click here.

    Expand Post

  3. The SVR July 2026 update v 260701 is now live.

    The update includes important feature enhancements as mentioned below –

    New API Usage Dashboard

    Software Vulnerability Research (SVR) now includes a new API Usage option under Settings > API that provides administrators with visibility into API consumption metrics across the organization such as volume stats, throttle rates, usage data, etc. with flexible filtering options for administrators to slice and dice the data in varied ways.

    In addition, API rate limiting has been enhanced to return consistent HTTP 429 responses with a Retry-After header when configured thresholds are exceeded. Throttle events are logged with account and stored information is available through account log exports for auditing and troubleshooting purposes.

    Enhanced API Token Management, Lifecycle Auditing, and Anomaly Detection

    A new Expiration option has been added when creating or editing API tokens. It allows administrators to specify or modify expiration date of the token, providing greater control of API access and improved enforcement of token lifecycle policies.

    In addition, an API Token option has been added in the Settings > logs. This page contains two audit views:

    Lifecycle Events - Tracks token management activities such as expiration date changes and other token lifecycle updates.

    Anomalies - Records suspicious or unusual token activity, including token usage from previously unseen source IP addresses.

     Enhanced Two-Factor Authentication Security Notifications

    With this enhancement, standard users must enter their login password before disabling either SMS-based or token-based two-factor authentication (2FA). This additional verification step helps prevent unauthorized changes to account security settings. Whenever a two-factor authentication method is disabled, SVR automatically sends a security notification email to both the affected user and the root account user associated with the account.

     Improved messaging during login

     When an invalid authentication token is entered, the login page displays the number of remaining attempts before account lockout. Users are allowed a maximum of five unsuccessful 2FA attempts. After the fifth failed attempt, the account is locked to help protect against unauthorized access and brute-force attacks.

    For release notes, click here.

    Expand Post

  4. The SVM July 2026 update is live now.

     SVM cloud version 260701 is live now. This new version of the cloud edition is compatible with the latest version of the Patch Publisher v 7.34.2271

    Improved Zombie File Reporting

    Exclude Windows System Files from Zombie File Detection

    You can now choose to exclude files located in the Windows System32 and SysWOW64 folders from zombie file detection. This helps reduce unnecessary results and ensures reports focus on files that are more likely to require attention, making zombie file insights more accurate and actionable.

    Management of Intune Scope Tags

    Assign Intune Scope Tags During Package Publishing

    You can now assign one or more Intune Scope Tags directly from the Manage Assignments / Scope Tags screen when publishing a package. Scope Tags help organizations delegate administration, control visibility, and ensure that IT teams only manage the resources relevant to their responsibilities.

    By making Scope Tag assignment available within the publishing workflow, it is easier to apply the right administrative controls from the start, helping support more organized, secure, and scalable Intune environments.

     For release notes, refer here.

    Expand Post

  5. The SVM March 2026 update is live now.

     SVM cloud version 260301 is live now. This new version of the cloud edition is compatible with the latest version of the Patch Publisher v 7.31.2212

    The update includes important feature enhancements as mentioned below –

     

    Software Vulnerability Manager User Interface Enhancements

    The following enhancements have been added to the Software Vulnerability Manager user interface to expand platform support and improve endpoint deployment flexibility.

    Support for Jamf Pro Unified Endpoint Management System

    A new Jamf Pro platform has been introduced, enabling seamless configuration and management of Jamf Pro within Software Vulnerability Manager.

    With this enhancement:

    • macOS packages, such as .dmg and .pkg, can now be published successfully to Jamf Pro
    • Packages can be deployed to endpoint systems using SVM
    • This provides greater flexibility and improved support for macOS deployments

     

    Patch Publisher Enhancements

    The following improvements have been added to the Software Vulnerability Manager (SVM) Patch Publisher to enhance patch security and signing flexibility.

    Digital Signing Support for SPS and VPM Patches

    A new Digital Signing option is now available in the Settings menu, enabling secure digital signing of SPS and VPM patches, with added flexibility to support different signing requirements.

    You can choose from the following signing options:

    Standard Signing

    • Uses a pre‑configured certificate to digitally sign patches. This option is suitable for most common patch‑signing scenarios and requires minimal configuration.

    Custom Signing

    • Allows you to configure and use a custom signing solution, including HSM‑based custom signing, for digitally signing SPS and VPM packages. This option is ideal for advanced or automated environments where standard signing does not meet specific security or compliance requirements.

     

    For the release notes, please click here.

    Expand Post

  6. The SVM January 2026 update is live now.

    SVM cloud version 260101 is live now. This new version of the cloud edition is compatible with the latest version of the Patch Publisher v 7.30.2191.

     The update includes important feature enhancements as mentioned below –

    Patch Publisher Enhancements -

    Streamlined Patch Publisher & AdminStudio Integration

    This release enables tighter automation between Patch Publisher and AdminStudio. Patches published through Patch Publisher can now be auto‑assigned to a default AdminStudio workflow (Import + Customization) and automatically marked as Subscribed. Additionally, custom packages placed in a designated shared directory can be imported on a schedule. With AdminStudio REST API access configured, Patch Publisher—through automation or the publishing wizard—can seamlessly push custom packages into AdminStudio for repackaging and distribution with minimal manual effort.

     

    Software Vulnerability Manager Enhancements

    Expanded Intune Deployment Support for SVM Cloud

    SVM Cloud now supports Intune publishing/deployments for both MSI and EXE-based Vendor Patch Module (VPM) packages. Previously restricted to MSI patches, this enhancement significantly broadens application coverage and offers greater flexibility in modern endpoint patch management.

    Network Appliance Groups Now Available in the New SVM UI

    Feature parity with the legacy UI is improved as the new SVM UI now supports the creation of Target Groups within Network Appliance Groups. These groups can be scanned directly using a Network Appliance Agent, simplifying asset segmentation and scanning workflows within the updated interface.

    New IP-Based User Access Restrictions

    Under User Management > Create New User, two new options—Restrict On IP Range and Restrict On IP Network—allow administrators to define the specific IP ranges or networks a user can access. These controls ensure users can only view or manage assets within authorized network boundaries, enhancing overall security and compliance.

     

    Enhanced Visibility & Warnings for Digitally Signed Packages

    Improvements across both Patch Publisher and the SVM User Interface now offer clearer identification and security guidance regarding digitally signed Vendor Patch Module (VPM) packages. In Patch Publisher, you can filter items using a new Digitally Signed option in Configure View, see a dedicated Digitally Signed property in the Patch Information dialog, and receive a security warning when subscribing to unsigned packages. Similarly, in the SVM UI, a new warning popup appears during the Create Update Package workflow if the selected package is not digitally signed, alerting administrators to potential security risks before they proceed.

    For the release notes, please click here.

    Expand Post

  7. SVM On-prem v7.6.1.35 R4 is now available for download.

    SVM On-prem January 2026 Updates are live now!

     SVM On-prem 7.6.1.35 R4 is now available for download. This new version of the on-prem edition is compatible with the latest version of the Patch Publisher v7.29.2188. All the recent updates made to the SVM Cloud and Patch Publisher will now be available to our SVM on-prem customers through this update.

    Patch Publisher Enhancements -

    Support for Config Manager Unified Endpoint Management System

    This release introduces the ability to configure and publish SPS and VPM patches directly to the Config Manager Unified Endpoint Management System through Patch Publisher. Once the Config Manager connection is set up, you can publish patches using either Patch Automation or the Create Patch Wizard, allowing for a streamlined and integrated publishing experience across your endpoint management environment.

    Enhanced Patch Publisher and AdminStudio Integration

    Patch Publisher now integrates more tightly with AdminStudio to reduce manual effort across packaging workflows. SVM packages are automatically assigned to the default AdminStudio workflow (Import + Customization) and marked as Subscribed for automation. Additionally, non‑VPM packages placed in a monitored shared directory can be automatically imported into AdminStudio. After AdminStudio REST access and shared directory paths are configured, both VPM and non‑VPM packages can flow seamlessly into AdminStudio for repackaging and distribution, creating a smoother and more automated pipeline.

    Software Vulnerability Manager Enhancements -

    Disable Standard Login for Root Accounts When SSO Is Enabled

    A new security enhancement allows root users to disable standard login when Single Sign-On (SSO) is active. Enabling this option removes the password‑change functionality, blocks standard login for the root account, and retains the Forgot Password option only if password recovery was already enabled. If password recovery is unavailable or the account becomes locked, access must be restored through a support request. The system also prompts for confirmation before enabling the feature and notifies the user that a temporary password will be emailed, ensuring a secure fallback when switching between SSO and standard authentication.

    New “API Access” Permission in User Management

    A dedicated API Access permission has been added to User Management under the User Roles & Permissions section. When assigned with Read/Write rights, this permission grants API‑level capabilities while disabling standard API access for the account to ensure secure and controlled integration. Administrators can configure this permission alongside others such as Scanning, Reporting, and Patching, enabling more granular and secure role management.

     

    For the release notes, please click here.

    Expand Post

  8. The SVR December 2025 update 2 is live now.

    The update includes important feature enhancements as mentioned below –

    Multi-Factor Authentication (MFA) is enforced for all Administrator level accounts and above. This enhancement adds an extra layer of security to protect critical user accounts across the platform. During login, administrators must provide a second form of verification such as a one-time pass code or authentication app confirmation in addition to their regular credentials. Users will be prompted to choose a two-factor authentication method (Token or SMS) during setup. If incorrect or incomplete information is entered, a validation error message will guide the user to correct the input. This enhancement prevents unauthorized access even if passwords are compromised, aligns with industry’s best practices, and ensures compliance with organizational security standards.

    For the release notes, please click here.

    Expand Post

End of Feed
8 Chatter Feed Items

Group Details

Details

Description
Information
Member Count
123 Members
Loading
Group: Software Vulnerability Manager