Early Access. The Prebuilt App Vulnerabilities dashboard is part of the Addigy Intelligence Suite and is currently in Early Access.
Overview
What is the feature?
The Prebuilt App Vulnerabilities dashboard shows you which known security vulnerabilities (CVEs) exist in the Prebuilt Apps deployed across your fleet, which of your devices are affected, and how far along you are in patching them.
The Prebuilt Apps Vulnerability dashboard will only show devices and apps that are being managed by Prebuilt Apps. If you are deploying an app like Chrome via Smart Software and not managing the updates with Prebuilt Apps, it will not appear in the dashboard- even if Chrome has an open vulnerability in that version. This is intended to give insight into updates the admin can control with Prebuilt Apps - but is not a replacement for a third party security tool.
With it you can:
- See every open CVE affecting the Prebuilt Apps in your environment, in one table.
- Prioritize by severity and by whether a vulnerability is actively being exploited.
- See which apps carry the most open vulnerabilities, and where your unpatched exposure is concentrated by severity tier.
- Drill into any CVE to see the affected version, the fixed version, and the exact list of devices still at risk.
- Exclude devices from a CVE's metrics — with a required, attributable reason — when they can't or shouldn't be patched.
Note: Not every app in the Prebuilt Apps catalog is mapped in the NVD database- we are tracking over 100 applications currently and will do our best effort to increase that number as they become available in the NVD database.
The Prebuilt Apps Vulnerabilities dashboards only shows the previous 5 versions of an application- if there are machines running older version AND are managed by Prebuilt Apps - they will not appear in the dashboard. These may be devices that have been offline for a while or in storage and have not received the latest Prebuilt App update enforcement. When they power on and receive their update enforcement, they should appear in the dashboard as vulnerable.
Permissions
Access to this dashboard is permission-controlled:
- The View Prebuilt Apps permission is required to view the dashboard.
- A separate Exclude Devices permission is required to use the Exclude Device and Exclude Devices actions. Users without it can view the dashboard but will not see those actions.
Background
What is NVD?
NVD is the National Vulnerability Database, maintained by the U.S. National Institute of Standards and Technology (NIST). This product uses the NVD API but is not endorsed or certified by the NVD.
It is the authoritative public record of software vulnerabilities. This Every CVE on this dashboard comes from NVD, and the following fields are taken directly from it:
| Field | What NVD provides |
|---|---|
| CVE ID | The unique identifier, e.g. CVE-2025-4280
|
| Severity | Derived from the CVSS (Common Vulnerability Scoring System) base score |
| Version Affected | The app version ranges the vulnerability applies to |
| Version Fixed | The first version above the affected range |
| Vulnerability discovered | The date the CVE was published |
Severity tiers follow the CVSS scale:
| Tier | CVSS score |
|---|---|
| Critical | 9.0 – 10.0 |
| High | 7.0 – 8.9 |
| Medium | 4.0 – 6.9 |
| Low | 0.1 – 3.9 |
What is KEV?
KEV stands for Known Exploited Vulnerabilities. It is a catalog published by CISA (the U.S. Cybersecurity and Infrastructure Security Agency) listing vulnerabilities that are confirmed to be actively exploited in the wild — not just theoretically exploitable.
- In the CVE table, an active KEV shows a filled red indicator in the KEV column. A CVE with no active KEV shows an empty grey indicator.
- On a CVE's detail page, a View KEV report link appears only when KEV is True.
How often do we poll?
Addigy scans NVD once a day, at 07:00 UTC. That scan:
- Checks every Prebuilt App that has a CPE (the identifier NVD uses to match software) against NVD.
- Looks at the 5 most recently published versions of each app, plus any version assigned by prebuilt apps in one of the policies.
- Matches CVEs published within the last year only, as a rolling window.
- Pulls the CISA KEV feed to set the KEV flag.
How often is it updated?
Different parts of the dashboard refresh on different clocks:
| What | How fresh |
|---|---|
| Device install, uninstall, and version changes (your patch counts) | Within minutes — the Addigy agent reports its app inventory every 5 minutes (if online) |
| Newly published CVEs, changed severity, new fix versions | Daily — picked up by the 07:00 UTC scan |
| Policy changes (a new device, or a device newly assigned a policy) | Daily — scope is rebuilt during the same run |
In practice: if you push a patch today, the Devices Patched number moves within minutes. If a brand-new CVE is published today, it appears after the next daily scan. If you enroll a new device or change its policy today, it joins the dashboard's numbers the following day.
The Devices last updated: timestamp on each CVE's detail page tells you exactly when that page's device data was last refreshed.
When will a fixed version be available?
The dashboard tells you which version fixes a CVE, but that version still has to be packaged and published to the Prebuilt Apps Catalog before you can deploy it. Addigy's turnaround times, phased-release handling, and zero-day policy are documented here: Prebuilt Apps Overview .
Note: Not all CVEs have a fixed version. If there is not a fixed version - it will read as N/A.
The Dashboard Overview
This is the main Dashboard to show you everything that is happening in your fleet. It can be accessed by navigating to Dashboards > Prebuilt Apps Vulnerabilities.
Metrics
Top Apps with open vulnerabilities — a ranked list of the Prebuilt Apps in your environment carrying the most open CVEs, most-affected first.
Patching per Severity Tier — a bar for each of Critical, High, Medium, and Low, each showing its patched percentage.
Filtering and Searching
The table can be filtered by Severity and whether you want to view just KEVs. The admin can also search for a specific app or CVE number if known.
Policy Filtering
This Dashboard view can be changed to view every device in your organization, or you can select different policies. If you are choosing a policy that has child policies- devices in the child policies are shown as well.
The CVE Table
| Column | What it shows |
|---|---|
| CVE | The CVE identifier, e.g. CVE-2025-4280. Click it to open the CVE's Patch Report. |
| App | The affected Prebuilt App and version. |
| Devices Patched | A percentage and counts, e.g. 25% (5 / 20). |
| Severity | Critical, High, Medium, or Low, from the CVSS score. |
| KEV | Filled red = actively exploited. Empty grey = no reported active KEV. |
| First Detected | When Addigy first classified a device in your environment as at risk for this CVE, e.g. Aug 25, 2026 10:26:12AM EST. |
How "Devices Patched" is calculated (click the help icon on the column to see the definition):
Devices patched is the devices patched plus excluded devices, all over the total devices.
So an excluded device counts as patched for the purpose of this metric. The denominator is the devices that have the affected Prebuilt App installed.
"First Detected" is not the NVD publish date. It's the date Addigy first saw one of your devices as at risk. A CVE published three months ago that only entered your environment last week will show last week's date.
Tip. Help icons on the Severity and KEV columns explain the scoring scale and the CISA source.
What the Main Dashboard Doesn't Show
To keep the fleet-wide view readable, these are only available once you open an individual CVE:
- The specific devices affected, and which of them are patched
- The version that fixes the vulnerability
- Links to the external CVE and KEV records
- The ability to exclude devices from the metrics
The CVE Detail Page
To see details about a specific CVE or the view the devices affected, click any CVE identifier or the Devices Patched number in the main dashboard's table to open up the CVE details page.
This page gives the admin an overview of what a particular CVE looks like in the fleet.
The View CVE Report will appear on every CVE - this will link to the external NVD report. If there is a KEV report - that will take the user to the external KEV report - this will only appear if KEV = True. If there is no KEV, then the report will not be shown.
The Version Affected is the version of the software that is affected by the CVE, and the version fixed will show the app version that resolves the CVE - if one exists. If there is no published fix, this will show as N/A. Additionally the details such as the app and the severity are shown.
Vulnerability Details
| Field | Meaning |
|---|---|
| Version Affected: | The app version this CVE applies to, e.g. 2.0.3.4.5
|
| Version Fixed: | The first version that resolves it, e.g. 2.0.3.4.6. Reads N/A when NVD has not published a fix. |
| Vulnerability discovered: | When the vulnerability was published on NVD. |
| First detected in policy: | When this CVE was first seen in the selected policy — how long that policy has been exposed. |
| Devices last updated: | When this page's device data was last refreshed. |
When Version Fixed reads N/A, there is no version to upgrade to, so no device can be counted as patched. The row will stay on your dashboard until a fix is published or the app is removed.
Remediation Summary
Remediation shows one of two things:
-
In progress — a percentage and counts, e.g.
68% (24 / 35). -
Complete —
Completed at Nov 25, 2025 10:26:12AM EST, once every affected device is patched or excluded.- Note: Once a remediation is completed, it will drop off the dashboard- a future release will include historical reports.
Below all of the general information is the devices themselves that are affected.
We have a total count of the amount of devices, whether they have been patched or at risk and device excluded. For more information on how filtering works see this article.
| Count | Meaning |
|---|---|
| Total: | Devices with the affected Prebuilt App assigned |
| Patched: | Devices running at or above the fixed version |
| At Risk: | Devices still running an affected version |
| Devices Excluded: | Devices you've deliberately removed from the metrics |
Clicking the Patched count shows you exactly which devices are counted as patched — including the excluded ones.
The Device Table
Lists every device that has the affected Prebuilt App assigned.
| Column | What it shows |
|---|---|
| Device name | Click it to open that device's GoLive page. |
| Patched | Green check = patched. Red cross = still at risk. |
| Patched Date | The date Addigy saw the device move past the fix. |
| Device Exclusion | Shows whether the device is excluded and who excluded it, e.g. Device Excluded by Owner. |
Excluding Devices
There may be reasons why an admin may want to exclude a certain device from the count - it could be a loaner device that is not currently powered on, a device that is sent off for repairs, or a testing device. Whatever the reason may be Admins have the full power to exclude devices from a CVE and have it count towards the patched count.
When admins exclude a device they must provide a mandatory reason for that exclusion. This will be logged as an event along with the admin that made the exclusion. Admins can also remove exclusions from a device if the state changes. The ability to exclude a device is controlled by it's own permission.
Excluding One Device
- On the CVE's Patch Report, click to box next to the device > Exclude device in the upper right
- The Exclude Device From Reports modal opens, confirming the device "will be excluded from patch metrics and reports."
- Enter your Exclusion Reasoning. This is required — the Exclude Device button stays unavailable until you do.
- Click Exclude Device.
The Devices Excluded: count increases and the device is treated as patched.
Excluding Several Devices at Once
- Select devices using the row checkboxes. Already-excluded devices have their checkbox disabled.
- Click Exclude Devices — the button is disabled until at least one device is selected.
- In the Exclude Devices From Reports modal, confirm the count and enter the required Exclusion Reasoning.
- Click Exclude Devices.
Reviewing and Removing an Exclusion
Open an excluded device's Device Excluded From Reports modal to see:
- Confirmation that the device "is currently excluded from patch metrics and reports"
- The Exclusion Reasoning that was recorded
- Exclusion created by — the user who created it
Click Remove Exclusion to put the device back into the calculations, counted by its actual patch status.
Exclusions are audited. Both excluding a device and removing an exclusion are recorded in System Events, along with the user who made the change and the reason given.
Exclusions outrank patch status. An excluded device stays excluded even after it updates past the fixed version. Remove the exclusion to have it counted on its real status again.
FAQs
What happens when a CVE is fully remediated?
It disappears from the dashboard. A CVE row is shown only while at least one device is still at risk, so once every affected device is patched or excluded, the row drops off the main CVE table. In a future release we will have a CSV report feature that will keep a record of all the completed times, and a historical dashboard to track.
Will remediated CVEs appear in historical dashboards?
Not yet. The current dashboard shows your live exposure, not a history. Historical and trending views are planned for an upcoming iteration.
Why does a device show as patched with no Patched Date?
A patched date is only recorded when a device that Addigy had previously classified as at risk moves past the fix. A device that was already on a safe version the first time Addigy saw it was never at risk, so it counts as patched with an empty date.
Why did a CVE drop off my dashboard when devices are still affected?
Addigy matches CVEs published within a rolling one-year window, so a CVE leaves the dashboard the day it turns a year old. It also leaves if the affected version falls out of the scanned set — Addigy scans the 5 most recently published versions of each app plus any version pinned by a policy, so publishing a new version can push an older one out of scope.
Why isn't one of my devices listed?
Check three things: the Prebuilt App must be assigned to the device; the device must be running a version within the scanned set (the 5 newest published versions, or a specific assigned version your policy); and if the device was enrolled or reassigned recently, it joins the numbers after the next daily scan. If the device has been offline for a while - it may not show in the dashboard, because it has a version older than the previous 5 versions.
A new device / policy change isn't reflected yet. Why?
Policy scope is rebuilt once a day. New devices and policy assignment changes appear the following day. After that, app installs, uninstalls, and version changes on that device show within minutes.
Does this dashboard cover apps outside the Prebuilt Apps Catalog?
No. This dashboard covers Prebuilt Apps only.
Is there a report I can download?
Not yet - a csv report is planned for a future iteration that can be generated from the dashboard view and the overview
I deployed a Prebuilt App via GoLive to my device- but why isn't it showing in the dashboard?
The app updates need to be managed by Prebuilt Apps in a policy - one off installs without a corresponding Prebuilt App in a policy to keep it up to date will not be included in the dashboard.