Find and fix vulnerabilities: To fix, KEV, EPSS and a weekly patch routine
Understand NetBlade's signed vulnerability feed, KEV and EPSS in plain words, how To fix is prioritised, and a weekly routine to patch what matters first.
A first read of an ordinary office produces a long list of problems, and a long list sorted by severity sends you to patch a theoretical 9.8 while the flaw actually being used to break in sits further down. NetBlade sorts differently: first what attackers are exploiting now, then what they are likely to exploit, then how bad it would be. This article explains where the data comes from, what the pages show, and a routine that fits in an hour a week.
Before you start
- PCs read in depth (Prepare your Windows PCs). Vulnerabilities in programs show only on devices whose programs were read.
- Devices identified or port-scanned, for the network checks (Identify every device in Sites).
- An internet connection on the NetBlade PC, for the daily feed download.
1. Know where the vulnerability data comes from
NetBlade checks installed programs against a vulnerability feed built every night and published at feed.netblade.app. The feed is a single file, signed with an ECDSA P-256 key; the app verifies the signature before using it. A feed with an invalid signature is discarded and the last good one stays in use.
What this means for you and your customers:
- The download happens at most once a day, by itself. The comparison with installed programs happens locally: program names and versions never leave the PC.
- Settings, Vulnerability feed shows the date and age of the feed, for example «Built …, 2 days ago.», and Check now looks for a newer one straight away.
- If the feed is more than a week old, the app says so everywhere it matters. Checks still run against it, but a vulnerability published since then is not in it.
The feed is built from the NVD, CISA’s KEV list and FIRST’s EPSS. This product uses the NVD API but is not endorsed or certified by the NVD.
2. Understand KEV, EPSS and CVSS in plain words
Every known vulnerability has a CVE number. For each one NetBlade knows up to three things:
| Signal | Plain meaning | Source |
|---|---|---|
| KEV | Attackers are using this flaw right now | CISA’s Known Exploited Vulnerabilities list |
| EPSS | The chance it will be exploited in the next 30 days | FIRST’s Exploit Prediction Scoring System |
| CVSS | How bad it would be if exploited, from 0 to 10 | The NVD |
Severity says how bad it would be; KEV and EPSS say whether it is happening. That is why NetBlade sorts by KEV first, then EPSS, then CVSS.
3. Know what gets checked, and what does not
Programs are matched to CVEs by exact product and version, through NetBlade’s dictionary of products. Two limits follow:
- Only programs the dictionary can name are checked. On Inventory, Software, tick Only what the dictionary can name to see them; the IN DICTIONARY column says which. Everything else gets no verdict anywhere in the app. Silence about a program is not safety.
- A version that cannot be compared reliably gets no verdict, rather than a guess.
Besides program vulnerabilities, NetBlade runs configuration checks on every device: Telnet, FTP, reachable Remote Desktop, VNC, Android debugging, IPMI, industrial PLC protocols (S7, Modbus), listening databases, UPnP, raw printing on port 9100, SNMP with a factory community, firewall off, no antivirus, shares writable by everyone, no updates for 60 days or more, SMBv1, UAC off, Secure Boot off, pending restart, Guest account enabled, more than three local administrators, PowerShell 2.0, a disk under 8% free. It also flags operating systems out of support, and those whose support ends within 180 days.
4. Read the To fix page
In the menu open Security, then To fix. This is the single list of everything open: program vulnerabilities, systems out of support, configuration checks.
Each entry shows:
- a badge: exploited, critical, high, medium, low or unscored;
- the device and how long it has been open («found today», «open for 12 days»);
- why it ranks where it does, for example «on CISA’s list of vulnerabilities being exploited right now» or «4% chance of exploitation in the next 30 days»;
- what to do, in one sentence.
Press Check now to compare again. An empty list says either «Nothing open» or «nothing has been read deeply yet»; the coverage line on the Dashboard tells you which.
Note: A check only fires on what a machine has shown, never on what it did not say. A device nobody has read cannot report a problem.
5. Read the Vulnerabilities page
In the menu open Vulnerabilities. It covers program CVEs only, in two views:
- By update: one row per program to update, with INSTALLED, UPDATE TO, how many CVEs, how many EXPLOITED, the WORST severity and the DEVICES. This is the view to work from: one update often closes a dozen CVEs.
- By CVE: one row per CVE with SEVERITY, LIKELIHOOD and FOUND ON.
The tiles sum up Exploited now, Critical (severity 9 or more), High (7 to 9) and Devices affected. Tick Exploited only to see just the KEV items. Click a row for the CVE list and the affected devices, with advice such as «Update … to version … or later: it closes all these CVEs on these devices.» When no single version closes them all, the advice is to update to the vendor’s latest version and press Check again afterwards.
6. A weekly patch routine
Pick a fixed slot, for example Monday morning. For each customer site:
- Refresh the data. In Vulnerabilities, press Check again. Make sure the feed is recent (the page says so) and look at the coverage line: «Vulnerabilities in programs show only on devices read in depth: X of Y». If coverage dropped, find out why before trusting the rest (see Credentials).
- Exploited first. Tick Exploited only, stay on By update. Every row here is a job for today.
- Update. Update the program on the listed devices with your usual tools, or from NetBlade with remote actions: on a device card, Remote actions, category Software, use «Search the winget catalog» to find the package ID, then «Update one package (winget)». «Missing Windows updates» lists pending Windows updates. See Remote actions, safely.
- Verify. Press Deep scan on each updated device (or Read selected on the device list), then Check again. Trust the re-read, not the updater’s exit code.
- Then the likely ones. Untick Exploited only and work down To fix: the order already puts high-EPSS items next.
- Configuration items. Restart machines with «An update is waiting for a restart», plan replacements for «Support ends soon», and handle defences that are off.
- Accept what is genuinely acceptable, with Accept / reopen, and write down why (see Compliance and exceptions).
- Report. Send the owner the «Vulnerabilities» or «Summary for the owner» report (Reports).
Tip: Set an alert for New things to fix with Only what is being exploited (Alerts). Your weekly slot then handles the backlog, and a newly exploited flaw reaches you the same day.
7. Let the agent keep it current
With the agent running, each device is re-checked against the feed once a day, a few devices at a time. This uses only what is already known, so it also runs on a laptop that is away from the customer’s network. New programs and versions are learned only by reading the machines again: for that, set IN DEPTH in Sites to Once a day or Every week (the agent reads one device at a time, only while the PC is on that network).
Check that it worked
- After updating and re-reading, the program disappears from By update, and its entries on To fix are gone.
- The Dashboard’s To fix tile goes down, and «none on the exploited list» appears when KEV items are cleared.
If something goes wrong
- «No feed yet». The PC could not download it yet. Check the connection and press Check now in Settings, Vulnerability feed; the last error is shown there.
- «the downloaded feed is not signed by us — it was not used». The file failed verification and was discarded, as designed; the last good feed stays in use. Try again later.
- The feed is older than a week. The daily download is failing. Check the connection and any proxy or filter that blocks
feed.netblade.app. - A program you know is vulnerable is not listed. It is not in the dictionary, or its version cannot be compared. Check the IN DICTIONARY column on Software.
- Updated, but the finding stays. The device was not read again. Press Deep scan, then Check again.
- The list is empty on a new site. Nothing has been read in depth yet. Look at the coverage line.
Next
Next, measure the network against a baseline: Compliance, exceptions and the security score.
← All how-to guides Feature guide → The product: NetBlade Windows →