vulnerability-management
Safeguard articles tagged "vulnerability-management" — guides, analysis, and best practices for software supply chain and application security.
689 articles
When One CVE Has Three Scores, Taking the Highest Is Not Caution
NVD says 9.9. The vendor says 7.0. CVSS v4 says 6.3. Collapsing that to 9.9 does not make you conservative — it discards the disagreement, which was the most informative thing you had.
The Version String Is Not the Vulnerability
A CVE that needs Windows, a dev server, and a reachable port is not exploitable because a version matched. Cataloguing what each advisory actually requires turns a lockfile diff into an argument.
"Not Demonstrated" Is Not "Not Vulnerable"
Exploitability is not a boolean. Collapsing it into one loses the only state that tells a developer what to do next — and quietly converts every unanswered question into a dismissal.
Patch Tuesday August 2026: ~398 Flaws, 3 Zero-Days, and One the Norks Already Used
Microsoft shipped fixes for roughly 398 CVEs on 11 August. Three are zero-days, one is under active exploitation by Lazarus, and the vendor tallies disagree by nearly 30.
66,000 CVEs: The Year Enumeration Stopped Being a Strategy
2026 is forecast to close near 66,000 CVEs, driven partly by AI-assisted discovery. At that volume reading the list is not a job anyone can do — and most programmes are still built around reading it.
Python setuptools package_index ReDoS (CVE-2022-40897)
CVE-2022-40897 is a ReDoS flaw in setuptools' package_index.py that can hang CI pipelines when parsing crafted index pages. Here's how to detect and fix it.
SBOM adoption in underwriting and actuarial software
Insurers price risk with software built on unvetted open-source code. Here's how SBOM underwriting software closes that blind spot.
SBOM for automotive ECU firmware and embedded software
How automotive ECU firmware SBOMs help OEMs and suppliers track embedded components, manage vehicle firmware vulnerabilities, and secure OTA updates.
How to manage open source risk in telecom OSS/BSS softwar...
A practical guide to managing telecom OSS/BSS open source risk—from SBOM inventory to dependency scanning—so carrier billing and network software stays secure.
2,130 AI-Related CVEs and Counting: The Surge Is Structural, Not a Blip
AI-related CVEs rose 34.6% year over year and more than 200% since 2023. The interesting question is what kind of vulnerabilities they are — because most of them are not model flaws at all.
Your 30-Day Patch SLA Meets a 48-Hour Exploitation Window
88% of exploitation against vulnerabilities with a public PoC now happens within 48 hours. No organisation patches everything that fast. The fix is a smaller fast lane, selected automatically.
Analysis of known MCP server CVEs and disclosed vulnerabi...
Two critical CVEs — in mcp-remote and Anthropic's MCP Inspector — reveal how MCP server vulnerabilities let untrusted servers execute code on client machines.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.