patch-management
Safeguard articles tagged "patch-management" — guides, analysis, and best practices for software supply chain and application security.
64 articles
Upgrade Impact Analysis: Predicting Breaking Changes Befo...
Why 70% of security patches sit unapplied for months, and how diffing a package upgrade against your call graph predicts breaking changes before you run npm update.
Zero-Day Patch Response at Scale: Can Open Source Maintai...
Zero-day patch timelines swing from 3 hours to 10 weeks across open source projects. Here's why maintainer capacity, not tooling, is the real bottleneck.
CVE-2025-23121 in Veeam Backup & Replication: Patch Posture & SBOM Response
Veeam B&R authenticated RCE on the backup server scored CVSS 9.9. Backup infrastructure cannot be a soft underbelly. Here is the defender playbook.
CVE-2026-0300 in Palo Alto PAN-OS: Patch Posture & SBOM Response
PAN-OS Captive Portal pre-auth RCE scored CVSS 9.3 and landed on CISA KEV with a three-day patch deadline. Defender playbook below.
nginx/1.21.5: Which CVEs Affect It and How to Patch
If your Server header reads nginx/1.21.5, you are running an old mainline release. Here is what it is vulnerable to and the safe versions to move to.
Patch management strategies for open source dependencies
A practical guide to patch management for open source dependencies: prioritizing by reachability and EPSS, not CVSS alone, and building a repeatable remediation loop.
CVE-2025-47884 in Jenkins OpenID Connect Provider: Patch Posture & SBOM Response
Jenkins OIDC Provider plugin token impersonation scored CVSS 9.1. Defender playbook for CI/CD identity infrastructure.
CVE-2025-22462 in Ivanti Neurons for ITSM: Patch Posture & SBOM Response
Ivanti Neurons for ITSM auth bypass scored CVSS 9.8 and grants full admin access. Defender playbook for the ITSM patching emergency.
CVE-2023-4641: The shadow-utils Password Leak Explained
CVE-2023-4641 is an information-disclosure flaw in shadow-utils where a failed password change can leave the entered password lingering in memory. Here is who is affected and how to remediate it.
PHP 7.4.33 Vulnerabilities: The Real Risk of Running EOL PHP
PHP 7.4.33 was the final release in the 7.4 line before it reached end of life — running it today means every new vulnerability discovered afterward goes unpatched by design.
Server Vulnerability Assessment: A Step-by-Step Guide
A server vulnerability assessment finds the missing patches, weak configs, and exposed services on your hosts before an attacker does. Here is how to run one that produces action, not noise.
Where Is Java Installed? Finding Your JDK (Including Homebrew)
Where is Java on your machine? Between system installs, Homebrew, and version managers you can easily run a JDK you didn't mean to. Here is how to find every one — and why the answer is a security question.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.