Vulnerability Management
In-depth guides and analysis on vulnerability management from the Safeguard engineering team.
100 articles
What to Do With a Critical Vulnerability That Has No Fix
Every remediation process assumes a patch exists. When the maintainer is gone and the package sits three levels deep in a tree you do not control, you need a different workflow: narrow the exposure, then decide, document, control and expire.
A Clean Scan Usually Means the Scanner Did Not Look
Analysed your code and found nothing, or failed to analyse your code and therefore found nothing. Most tools report both as success. Seven reasons coverage collapses, and the canary dependency that proves a scan still works.
Changing Scanners Means Migrating Three Years of Triage Decisions
Findings regenerate. Suppressions, risk acceptances, severity overrides and exclusion scope do not. The composite key that matches most of them, what should not carry over, and the sequence that keeps the review queue before cutover.
Five Places Reachability Analysis Says Unreachable and Is Wrong
Reachability is the best noise filter in dependency scanning and its failure mode is silence, not an error. The five cases where the call graph is incomplete, and what to do about each.
2026 Q1 CVE Trend Analysis
A data-driven look at CVE trends from Q1 2026: publication volume, severity distribution, exploitation patterns, and what the shifts mean for defenders.
66,000 CVEs: The Year Enumeration Stopped Being a Strategy
2026 is forecast to close near 66,000 CVEs, driven partly by AI-assisted discovery. At that volume reading the list is not a job anyone can do — and most programmes are still built around reading it.
Your 30-Day Patch SLA Meets a 48-Hour Exploitation Window
88% of exploitation against vulnerabilities with a public PoC now happens within 48 hours. No organisation patches everything that fast. The fix is a smaller fast lane, selected automatically.
The ROI of Vulnerability Remediation Automation: Numbers That Justify the Investment
Manual vulnerability remediation costs more than most organizations realize. Breaking down the real costs, time savings, and risk reduction that automation delivers.
Best vulnerability management platforms
A practical comparison of leading vulnerability management platforms — Tenable, Qualys, Rapid7, CrowdStrike, Wiz, and Microsoft — plus how Safeguard closes the supply-chain gap.
When CVSS Scoring Misleads Severity Context
Only 2-6% of published CVEs are ever exploited in the wild, yet a much larger share carry CVSS 7.0+ scores — a gap that quietly wrecks patch prioritization.
CVE-2021-45105: the Log4j denial-of-service flaw recursion built
CVE-2021-45105 scored CVSS 5.9 and let a single crafted lookup string crash a JVM with a StackOverflowError — no RCE required, just uncontrolled recursion.
CVE-2022-31692: how a forward dispatch bypassed Spring Security authorization
A CVSS 9.8 flaw let a single internal forward skip Spring Security's URL-based access checks entirely — here's the root cause and the exact config fix.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.