Definition · Known Vulnerabilities (CVEs)

What is Patch Management?

Patch management is the operational discipline of getting fixes onto systems. It covers watching vendor advisories, deciding what applies to your estate, testing updates, scheduling change windows, deploying, and confirming afterwards that the fix actually landed. It is distinct from vulnerability management, which is the broader process of finding and prioritising weaknesses, some of which have no patch at all.

The stages

  1. Inventory — know what software and firmware you run, and where
  2. Advisory intake — track vendor releases and CVE publications relevant to that inventory
  3. Prioritisation — sequence by exposure, exploitation evidence, and severity
  4. Test and deploy — validate in a staging path, then roll out
  5. Verification — re-check the asset to confirm the patched version is running

Step five is the one most often skipped. A patch recorded as deployed and a service still answering with the vulnerable version are different facts.

Why external exposure changes the sequence

Internet-facing systems collapse the attacker’s prerequisites — there is no need for a foothold first — so exposure is a legitimate reason to patch out of band. A vulnerability in the KEV catalogue affecting a public edge device belongs on a shorter clock than the same flaw on an internal workstation.

Where patch management runs out

Patching cannot address a zero-day with no fix, an end-of-life product with no vendor, or a system nobody knows exists. The first two need compensating controls; the third needs asset discovery, which is why external monitoring and patching programmes depend on each other.

EPSS and CVSS inform sequencing, CPE and NVD data inform applicability, and external attack surface management tells you which patched-or-not assets a stranger can actually reach.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.