What you get
An asset register matched against CISA's actively-exploited vulnerability catalog, stating plainly what is and is not being checked.
Microsoft Exchange Server — recognised Checked against CISA's actively-exploited catalog by name. NOT checked against the full CVE corpus. CVE-2026-21410 · due 2026-09-04 · known ransomware use: Known Exploitation probability 42.1% over 30 days (FIRST EPSS estimate) internal-billing-service — unmatched Recorded but not being checked. An absence of findings here means it was not looked at, not that it is unaffected.
Illustrative extract showing the shape and depth of the output. Not captured customer work, and not a template you receive — your document is written from your own answers.
What is checked, and what is not
Checked automatically
- Matching is exact. A near miss produces no match, because a wrong product match attaches another product's vulnerabilities to your asset.
- A truncated or implausibly small feed is refused rather than trusted, so a bad download cannot look like a clean result.
- Every record names what was not retrieved, so a missing field reads as unknown rather than as absence of risk.
Not checked: your responsibility
- The full CVE corpus. Coverage is the actively-exploited catalog plus package dependencies imported from an SBOM.
- Anything you have not told us about. The register is only as complete as what you entered or imported.
- Whether a listed vulnerability is actually exploitable in your configuration.
Who it is for
Whoever owns the asset list and the patch queue.
With a free account
- The asset register, SBOM import, and matching against the CISA actively-exploited catalog.
Paid
- AI remediation advice on a finding: Not included in anything on sale today. If you need it, email hello@riskwoven.com and we will set it up for you.
Prices in US dollars, one-time, exclusive of tax. Full detail on pricing.