Security remediation intelligence
Know exactly what to patch, where, and why now.
Patcharo matches the exact versions of your firewalls and security appliances against vendor advisories, CISA KEV, NVD and EPSS, then turns the result into a short, explained list of actions.
259 vulnerabilities tracked · 149 known exploited · updated 30 Sept 2026
- NVD
- CISA KEV
CERT-FR
- EPSS
- Vendor advisories
Upgrade · EDGE-FW-01
Palo Alto Networks PAN-OS
11.1.2-h1→11.1.16-h1
Resolves 29 vulnerabilities
- CVE-2026-0301Affected
- CVE-2026-0280Affected
- CVE-2026-0281Affected
- CVE-2026-0283Affected
- Known exploited (CISA KEV)
- Critical severity
- 96% exploitation probability (EPSS)
- High severity
From inventory to verified fix
- 01
Know what you have
Exact product, version and patch level for every asset.
- 02
Know what affects you
Deterministic matching against vendor data. Unknown is never shown as safe.
- 03
Know what changed
New advisories, CISA KEV additions, CERT-FR alerts and vendor recommendation changes, as they happen.
- 04
Know what to fix
Remediation bundles: one upgrade that closes several vulnerabilities.
- 05
Know why now
Exploitation, exposure and business context explain every priority.
- 06
Verify the remediation
Completed work is checked against the recorded version, not taken on trust.
Sources Patcharo reads
Structured public and vendor data only. Every fact keeps its source, its retrieval time and the parser version that read it.
- CISA KEVKnown exploited vulnerabilities, federal due dates, ransomware use.
- NVDCVSS scores and weaknesses (CWE).
- CVE ProgramVendor-authored records: affected and fixed releases.
- FIRST EPSSProbability of exploitation in the next 30 days.
CERT-FR (ANSSI)Advisories, alerts and public MISP indicators compared with your watched IP addresses.
- Check PointSK advisories, support life cycle, recommended releases and Jumbo Hotfix Takes.
- FortinetPSIRT advisories and recommended releases per model.
- Palo Alto NetworksSecurity advisories for PAN-OS.
- CiscoSecurity advisories.
Version matching covers Palo Alto Networks PAN-OS, Fortinet FortiOS, FortiProxy, FortiManager, FortiAnalyzer and FortiWeb, and Check Point Security Gateway and Security Management with Jumbo Hotfix Takes; Cisco advisories are listed. Anything outside this coverage is shown as not covered, never as safe.
Built for the people who apply the patches
Why now
Every priority lists its reasons: known exploited, EPSS, severity, exposure, production, criticality.
Patch delta
See what a target release resolves, what remains and what it would introduce before you schedule it.
Evidence mode
Each determination shows the source, the affected range, the fixed release and the matcher version.
Watches without an asset
Follow a vendor, a product or a candidate version: new CVEs, CISA KEV, CERT-FR and recommendation changes, by e-mail.
Vendor recommendations, tracked
Recommended releases and maintenance builds get their own status, never mixed with vulnerability status.
Blast radius
For any CVE: which assets, accounts, environments and exposures are involved.
Risk exceptions that expire
Accepted risks carry a justification and an expiry date, never an open-ended waiver.
Made for MSSPs too
Business MSSP: up to 10 isolated customer organizations, an MSSP console and cross-customer reports.
No guesswork about vulnerability status
An AI never decides whether a version is vulnerable. Patcharo applies the ranges published by the vendor and the CVE Program. When the data does not allow a decision, the answer is Unknown or Needs review, never Not affected.
MethodologyFive explicit statuses
- AffectedThe installed release is inside a range the source lists as affected.
- FixedThe installed release is at or past the fix on an affected branch.
- Not affectedThe source's data shows this release is not affected.
- Needs reviewThe source lists this branch without patch-level detail. A person must check the advisory.
- UnknownThe data does not allow a decision. Patcharo never treats this as safe.
Simple pricing, full truth on every plan
Solo
For an independent engineer or a small estate.
€19/ month excl. VAT
- 10 assets
- 1 user
- Full vulnerability truth: every status, every source
- Evidence mode and fix confidence
- Remediation bundles and maintenance planner
- Monitors and analyzer
- CSV exports
Team
For security and network teams.
€59/ month excl. VAT
- 100 assets
- 5 users
- Full vulnerability truth: every status, every source
- Evidence mode and fix confidence
- Remediation bundles and maintenance planner
- Monitors and analyzer
- CSV exports
- Audit log
Business MSSP
For MSSPs managing their customers' estates.
€149/ month excl. VAT
- 10 managed customers
- 300 assets in total
- 15 users
- Full vulnerability truth: every status, every source
- Evidence mode and fix confidence
- Remediation bundles and maintenance planner
- Monitors and analyzer
- CSV exports
- Audit log
- Isolated customer organizations and MSSP console
- Cross-customer dashboard, alerts and reports
Enterprise
Custom volumes, SSO and support terms.
Contact us
- Custom customers, assets and users
- Full vulnerability truth: every status, every source
- Evidence mode and fix confidence
- Remediation bundles and maintenance planner
- Monitors and analyzer
- CSV exports
- Audit log
- Isolated customer organizations and MSSP console
- Cross-customer dashboard, alerts and reports
- SSO and custom terms
Asset boosters
Each plan has its own booster: add asset capacity without changing tier.
- Solo+10 assets · €10 / month
- Team+50 assets · €30 / month
- Business MSSP+150 assets · €60 / month
See what affects your estate today
Create an account, add a few assets and get your first prioritized actions in minutes.