Tekspace Research

Vulnerability Management

A Cyber SaaS Analysis 2026

Definition: The continuous cycle of finding, prioritising, fixing and verifying security vulnerabilities across an organisation’s operating systems and applications.

New domain assessments as they publish. Unsubscribe any time, and we never share or sell your data.

Breaches rarely happen because of a vulnerability that nobody scanned. Why do many organisations miss these gaps?

It’s generally because they are faced with multiple tools they must combine to comb through the noise, try to prioritise what’s important and then apply remediations at scale, often with great difficulty.

Effectively, they need to scan for the gaps, identify them, and remediate them in an efficient way.

This noisy, difficult-to-manage set of tools results in stagnation or, worse, practitioners ignoring or distrusting what they are shown, which leaves critical vulnerabilities open within their environments.

This means any vulnerability remediation tool that can help you prioritise efficiently can halve the workload or more, and start to shift you from noise, to signal, to remediating the most exploitable vulnerabilities in your environment.

Our observations of the vendors and tools that offer this intelligence to scan, prioritise and then remediate are quite nuanced. We’ll explore the different ways this is done and the different capabilities each one has.

Vulnerabilities are holes, fill them with hammers

Strip the jargon and a vulnerability is a hole in software. An attacker uses it to get in, or to move further once inside. Managing those holes means three distinct jobs:

  1. Finding holes = detection.
  2. Picking which ones matter = prioritisation.
  3. Filling them in = remediation.

The detection tool is not the hammer. It tells you where the holes are. Every solution here claims to do all three jobs, so we assessed each on how well it does them, not on how long its findings list runs.

The distinction matters because product labels blur it. Plenty of tools sold as vulnerability management stop at detection. As AI speeds up exploitation, a better scanner finds more, but it doesn’t close anything. Tools in this category have to remediate and patch what they detect.

The vulnerability space

The market is crowded with tools calling themselves vulnerability, patch or exposure management specialists while covering only part of the workflow. Before comparing anything, know which category you’re looking at. Here’s the split we use:

  • Detection-onlyspecialists in finding and validating exposures, with no fix layer of their own
  • Patch-onlydeploy and update software well, but bring no discovery or prioritisation
  • Cloud-native application protection platforms (CNAPP)a landscape of their own, securing cloud workloads and configurations rather than the endpoint estate
  • Orchestration layersaggregate findings from multiple tools, dedupe them and enrich them with additional information, then apply intelligent prioritisation or proof-of-exploit techniques. Some recommend how to remediate, including the full fix, but they aren’t the remediation hammer itself. They’re typically best considered for large enterprises

For larger enterprise teams, closing the loop is only part of the problem. When teams split patching, one for endpoints, one for infrastructure, one for cloud, one for network, even the best tool here leaves you reconciling an ever-growing list across all of them. Orchestration layers are built for that problem, and we’re benchmarking several strong ones separately.

We haven’t ranked every form of vulnerability management here. But several tools in this report can take in findings from a detection tool you already run, so you don’t have to throw out a scanner you’ve already paid for.

What we set out to measure

This assessment benchmarks 12 vendors using structured product research and vendor documentation.

We judged each one on how much of the loop it closes, from the first scan to proof that a fix landed.

Portrait photo of Frank De Pasquale
Frank De Pasquale
CEO at Tekspace

Threat Context

Insights from Parabellum Logo

CREST Pen Test certification badge. OffSec OSCE3 certification badge OffSec OSCE certification badge OffSec OSCP certification badge OffSec OSEP certification badge OffSec OSWE certification badge OffSec OSED certification badge OffSec OSWP certification badge OffSec OSAI certification badge

Attackers weaponise a disclosed flaw in hours. Most organisations still remediate in months.

The average time between a flaw’s disclosure and its exploitation has fallen from 63 days in 2018 to minus seven days in 2025: attackers now typically exploit a flaw about a week before a patch exists.1

On the defender’s side, the time to patch hasn’t moved. It still sits at roughly two months.6

Vulnerability exploitation is now the leading initial access vector, overtaking stolen credentials for the first time in nearly two decades of reporting.2

MOVEit Transfer showed what that looks like at scale. In 2023, the Cl0p ransomware gang exploited a zero-day SQL injection in the file-transfer tool before any patch existed. Two weeks after the patch shipped, more than 30 per cent of instances were still unpatched, and the breach eventually hit more than 2,700 organisations.11,12,13

In June 2026, ASD’s ACSC issued a national alert on a widespread credential-based campaign against Fortinet firewalls and VPN gateways, and named keeping those devices patched among its required mitigations.14

The physics of remediation · 2026

The window shrank on one side only

To exploit To remediate
0 · patch exists
63days2018
44days2020–21
32days2021–22
−7days2025
←
→
55–75 daysvaries by edition
0 20 40 60 80 days
Both series share one 0–80-day scale, so their positions are directly comparable. Mandiant’s figures are outlier-adjusted means, not medians.1 Edgescan’s range has shifted across editions, shown here as a band, not a point.6

AI is compressing the attacker's timeline, and its effect is accelerating.

Frontier AI models now automate work that used to take skill and time: reading a fresh disclosure, finding the exploitable path, generating working attack code. In controlled evaluations, the fastest models took a published disclosure to working exploit code in about 20 hours, so even a flaw that is disclosed before it’s exploited now leaves defenders less than a day.9,10

Frontier labs now run named evaluations of exactly this capability, Anthropic's Mythos and OpenAI's Daybreak among them, and model performance on narrow cyber task suites is roughly doubling every few months.9,10

That capability is no longer confined to the lab. Since Anthropic disclosed Mythos in April 2026, the number of high- and critical-severity vulnerabilities published by major technology vendors has gone vertical: roughly 2,500 in July 2026 across 21 tracked firms, about five times the monthly record set before the announcement.16 Much of that is AI turned on the problem from the defender’s side, surfacing flaws before attackers reach them. The uncomfortable half is that the same capability, pointed the other way, weaponises them just as fast: the backlog waiting on a patch is now larger than any monthly cycle was built to clear.

Epoch AI · high- & critical-severity CVEs from 21 major vendors · 2026

The volume went vertical, too

Volume of high- and critical-severity CVEs disclosed by 21 major technology vendors, per Epoch AI. The rise tracks from Anthropic’s April 2026 disclosure of Claude Mythos, a model shown to find software vulnerabilities autonomously; multiples are against the pre-Mythos monthly record.16 Figures are rounded.

Not all of this capability sits behind a frontier lab's guardrails. Open-source and leaked model variants circulating outside those evaluations answer to no usage policy and cost nothing to run, putting comparable capability within reach of anyone, not just well-resourced attackers.5

The craft that once slowed exploitation down has been partly automated away. The craft of remediation has not.

Zero Day Clock · median time-to-exploit · measured vs. projected

The clock keeps compressing

  1. 201863 daysMeasured
  2. 20261 dayMeasured
  3. 20271 hourProjected
  4. 20281 minuteProjected
First two points are Mandiant/Zero Day Clock measured medians; last two are Zero Day Clock’s own trajectory model, not recorded observations, shown as a dashed line.17 The years are evenly spaced, not to scale. Figures are rounded.
Patch coverage · endpoint software vulnerabilities

Most patching stops at the OS

Standard update toolingOS + core first-party apps
20%
Everything elsethird-party, edge, unmanaged
80%
Zero-days exploited in the wild · 2025 90 Enterprise technology overtook everyday software as the leading target for the first time.4
Of exploited edge devices Half Sit on hardware the vendor has already stopped fixing, so there was no patch window to hit at all.5
Coverage bars are the share of endpoint software vulnerabilities each patch coverage model reaches, from Flexera’s global Annual Vulnerability Review.15 The two figures below them are also global, not Australia-specific. Figures are rounded.

Most Australian organisations are already patching. The catch is what they’re patching: standard update tooling was built for the operating system and a narrow set of first-party applications, a minority of what actually runs on the endpoint. It was never built for the laptop offline on leave, the remote worker whose device rarely touches the office network, or the firewall sitting outside that tooling altogether. Even across the managed fleet, some devices miss a given patch in every cycle, because an agent has broken, a disk is full, or the machine isn’t on when the maintenance window opens. Then there are dependencies: patch one component ahead of the applications built on top of it, and the fix is what takes the system down.

That uncovered majority is also where Australian obligation bites hardest, because third-party and edge-facing software is what attackers target first. Two of ASD’s Essential Eight controls, Patch Applications and Patch Operating Systems, sit in this domain, and the timeframe for internet-facing systems judged critical or under active attack is 48 hours. ASD calls patch currency the single most effective technical control to disrupt initial access.3 That is a remediation timeframe, not a scanning cadence; Essential Eight sets its own, shorter cycle for finding the vulnerability in the first place.

ASD Essential Eight Maturity Model · time to patch, not time to scan

The 48-hour floor isn’t new for everything

Time allowed to patch a critical vulnerability, by category and Essential Eight maturity level
CategoryML1ML2ML3
Internet-facing services & OSAlready at the floor48h48h48h
Office suites, browsers, emailHits the floor at ML32 wks2 wks48h
Workstations (general OS)The average endpoint1 mth1 mth48h
Other applicationsNever reaches the floorNot required1 mth1 mth
The “critical or working exploit” timeframe at each maturity level, ASD Essential Eight Maturity Model. Filled cells are the 48-hour floor.3

Coverage gaps are one problem. A real share of what gets found cannot be patched on schedule at all.

Where a fix won’t land on schedule, the defensible answer is a compensating control: shield the vulnerable process in memory, or apply an explicit mitigation until it does. It’s not a replacement for endpoint detection and response.

Security Outcomes

With the threat context as a backdrop, what do Australian IT leaders prioritise when choosing a platform that fixes vulnerabilities as well as finds them? Expand each to see how we assess the vulnerability and patch management category.

1

Efficacy

  • Agent and agentless discovery across endpoints, infrastructure, network and OT
  • Prioritisation tuned to exploitability in your environment, not raw CVSS
  • Remediation validated, with in-memory mitigation where no patch exists
2

Operational Efficiency

  • OS and third-party patching automated on a schedule the team sets
  • Ring deployment, maintenance windows and reboot control to contain change risk
  • Agentic remediation available behind a human approval gate
3

User Experience

  • Routine work achievable without specialist skills or vendor assistance
  • Scanning and remediation in one console, not two products stitched together
  • Fixes that land without interrupting the person using the device
4

Reporting and Analytics

  • Closure rate and time to remediate tracked against Essential Eight timeframes
  • Continuous compliance posture against Essential Eight and CIS benchmarks
  • Reporting a board can act on without translation

Product Landscape

Many tools offer some level of patching. From more than 40 candidates, we’ve ranked the 12 solutions that detect, prioritise and patch in one platform on the Tekspace Cyber Continuum™ to show what makes the top platforms so effective for buyers.

Broad

  • SecOps Solution Icon
    SecOps Solution
  • PDQ Icon
    PDQConnect

Features

  • Agent and agentless scanning
  • Risk-based prioritisation
  • OS and third-party patch automation
  • Maintenance windows and scheduling
  • Reboot control
  • Compliance auditing (CIS)
  • Role-based access control
  • Real-time compliance dashboard
  • Staged / ring deployment (varies)

Comprehensive

See Vendors and Features
HCL BigFix Icon
ManageEngine Icon
Automox Icon
NinjaOne Icon
Tanium Icon
Qualys Icon
Action1 Icon
Ivanti Icon
Vicarius Icon
Tenable Icon
Adaptiva Icon

Comprehensive

  • HCL BigFix Icon
    HCLBigFix
  • ManageEngine Icon
    ManageEngineEndpoint Central
  • Automox Icon
    Automox
  • NinjaOne Icon
    NinjaOne
  • Tanium Icon
    TaniumComply + Patch + Deploy
  • Qualys Icon
    QualysVMDR + Patch Management
  • Action1 Icon
    Action1
  • Ivanti Icon
    IvantiNeurons for Patch Management
  • Vicarius Icon
    VicariusvRx
  • Tenable IconAdaptiva Icon
    TenableOne Vulnerability Management + Patch Management (powered by Adaptiva)

Features

  • Environment-tuned exploitability prioritisation
  • Scripting and orchestration
  • Patchless / in-memory mitigation for the un-patchable
  • Remediation validation (proof of closure)
  • Native ring deployment with promotion gates
  • Network and OT visibility
  • Agentic remediation with a human approval gate (frontier)
  • Continuous compliance posture

We collated 660+ disparate features across the twelve vendors, normalising them down to 41 scored features in 11 capability groups, each group sitting under one of the four outcomes above. A weighted scoring model then produces a single maturity score per vendor: a picture of feature depth, not just feature count. Every one lands in the Broad or Comprehensive tier, with no thin, single-purpose entrant at the bottom of the range.

Close

Broad

  • SecOps Solution Icon
    SecOps Solution
  • PDQ Icon
    PDQConnect

Features

  • Agent and agentless scanning
  • Risk-based prioritisation
  • OS and third-party patch automation
  • Maintenance windows and scheduling
  • Reboot control
  • Compliance auditing (CIS)
  • Role-based access control
  • Real-time compliance dashboard
  • Staged / ring deployment (varies)
Close

Comprehensive

  • HCL BigFix Icon
    HCLBigFix
  • ManageEngine Icon
    ManageEngineEndpoint Central
  • Automox Icon
    Automox
  • NinjaOne Icon
    NinjaOne
  • Tanium Icon
    TaniumComply + Patch + Deploy
  • Qualys Icon
    QualysVMDR + Patch Management
  • Action1 Icon
    Action1
  • Ivanti Icon
    IvantiNeurons for Patch Management
  • Vicarius Icon
    VicariusvRx
  • Tenable IconAdaptiva Icon
    TenableOne Vulnerability Management + Patch Management (powered by Adaptiva)

Features

  • Environment-tuned exploitability prioritisation
  • Scripting and orchestration
  • Patchless / in-memory mitigation for the un-patchable
  • Remediation validation (proof of closure)
  • Native ring deployment with promotion gates
  • Network and OT visibility
  • Agentic remediation with a human approval gate (frontier)
  • Continuous compliance posture

Want to know which of these fits your environment? We help with that.

A logo on a chart does not tell you whether the tool handles your third-party mix, your patching cadence, or the un-patchable backlog you are carrying.

Book your session

Conclusion

Score for closure and proof, not scan volume.

A decade of investment in vulnerability management has gone into finding the problem. Scanners got faster, coverage got wider, and the findings list got longer every year. Across the platforms assessed for this report, locating an issue is table stakes. What separates the platforms is what they do with the issue once it exists, and how they handle the ‘un-patchable’: the legacy system that’s out of support, the appliance the vendor won’t touch, the production system that can’t take the downtime a patch would need.

Coverage also deserves a closer look. A vendor may advertise support for thousands of Windows applications, but many entries on those lists are versions of the same application: one application in 45 versions is still one application. Take an image of your own environment and compare it against a tool’s de-duplicated catalogue, and in our experience the gap in what it can actually patch is 50 per cent or more. That doesn’t mean it can’t find the vulnerability. Scanning coverage is strong. The ability to patch what the scan finds hasn’t kept pace, pretty much across the industry, and not every application carries the same business impact if it’s breached.

That reframes what the category is for. Vulnerability management is being judged less on the sheer volume of findings a tool can produce and more on whether it can consistently and automatically remediate what it finds, and on whether the findings that can never close are being held under a compensating control rather than left open. Doing that consistently is what actually shrinks the footprint an attacker can use, not a longer scan report. What separated the platforms that scored well in this assessment was a focus on closure and proof.

In practice, this tends to look the same way each time. The highest-value move is closing the exploitable findings that can already be proven, in priority order. Next is standing up a compensating control for the un-patchable backlog, the findings no patch will reach. Last is a change in what gets measured, from the size of the open-findings list to the speed at which findings close.

No platform closes 100 per cent of what a scan turns up, and a real share never gets a patch at all. A program is judged on how honestly it handles that remainder, not on whether it hits zero.

The right platform fits your environment

The most comprehensive platform is not always the one that closes the loop that matters to you.

The right platform is the one that can detect, prioritise and automate remediation at scale, consistently and repeatably, and that keeps working the same way after the person who configured it leaves the business.

It also needs to cover the specific mix of third-party applications the organisation runs. A platform can excel everywhere else and still leave a critical slice of the environment unpatched if its catalogue does not reach that software.

Often, that same platform also consolidates tools already in place: a standalone scanner, a patch utility, and the vulnerability add-on inside an endpoint agent.

The closure evidence it produces is the same evidence an Essential Eight assessment, an ISO 27001 audit, or a cyber-insurance renewal increasingly asks to see.

We hope this analysis helps you make a deliberate, not reactive, choice.

When you're ready to pressure-test that choice against your own environment, you can book time with Tekspace directly.

Addendum

Credits

In launching this report, Tekspace would like to acknowledge contributions from the following teams and individuals.

Contributors

  • Lead Analysts — Frank De Pasquale, CEO at Tekspace.
  • Threat Context — Martin Dybalski, Director; Stuart Shanahan, Director of Technical Services; and Kris Bowen, Senior Offensive Security Consultant, all at Parabellum.
  • Research and analysis by the Tekspace Research team.

References

  1. Mandiant (2026), M-Trends 2026
  2. Verizon (2026), 2026 Data Breach Investigations Report
  3. Australian Signals Directorate (2023), Essential Eight Maturity Model
  4. Google Threat Intelligence Group (2026), Look What You Made Us Patch: 2025 Zero-Days in Review
  5. VulnCheck (2026), 2026 State of Exploitation: Exploring the Network Edge
  6. Edgescan (2026), Vulnerability Statistics Report
  7. Gartner (2024), How to Grow Vulnerability Management Into Exposure Management
  8. Gartner (2022), Implement a Continuous Threat Exposure Management (CTEM) Program
  9. Cloud Security Alliance (2026), The Collapsing Exploit Window: AI-Speed Vulnerability Weaponization
  10. Institute for AI Policy and Strategy (2026), Mythos and the Evolving Cyber Landscape
  11. Progress Software (2023), MOVEit Transfer Critical Vulnerability (CVE-2023-34362)
  12. Cybersecurity and Infrastructure Security Agency (2023), Known Exploited Vulnerabilities Catalog: CVE-2023-34362
  13. Australian Cyber Security Centre (2023), Cyber Threat Advisory: MOVEit Transfer Vulnerability (CVE-2023-34362)
  14. Australian Cyber Security Centre (2026), Reported widespread credential exposure affecting Fortinet Firewalls and VPN Gateways
  15. Flexera (2025), Annual Vulnerability Review
  16. Epoch AI (2026), Disclosed CVEs: July Reached 5× the Pre-Mythos Record
  17. Zero Day Clock (2026), Zero Day Clock

Vulnerability Management category

What this report does and doesn’t claim to cover, how we compare products fairly, and what to do if you still have questions.

Scope

Tekspace’s Vulnerability Management Cyber SaaS Analysis 2026 is not an exhaustive survey of every vulnerability or patch management product in Australia. It focuses on the 12 platforms, selected from more than 40 candidates, that detect, prioritise and patch in one tool.

Feature Granularity Model

We compare products at what we call Level 2: The Functional Group: specific enough to be meaningful, broad enough to compare very different products fairly, without losing sight of how they’re meaningfully different.

Further questions

Why isn't a raw CVE or CVSS count enough to prioritise patching?

A raw count treats every finding as equally urgent, and a CVSS score rates how severe a flaw could be, not whether it can be exploited where it was found. Many listed vulnerabilities can't be: the path is closed, the component is unreachable, or another control already blocks it. A platform that ranks findings by real exploitability in your environment, rather than by CVSS alone, can halve the list a team needs to act on.

How is this different from running a bare vulnerability scanner?

A scanner does one of the three jobs this category covers: detection. It finds vulnerabilities and lists them. A vulnerability and patch management platform also prioritises those findings by how exploitable they are, deploys the fix, and rescans to confirm the fix landed. This report only assesses platforms that do all three.

What's in scope for this report, and what's been set aside?

This report evaluates software that performs the end-to-end workflow in one consolidated tool: detect, prioritise, and patch.7,8 The Tekspace Cyber Continuum™ selected 12 vendors from a broader discovery across more than 40 candidates. Adjacent categories are reserved for separate research: detection-only tools (no fix layer of their own), patch-only tools (no discovery or prioritisation), CNAPPs (cloud workloads, not the endpoint estate), and orchestration layers (aggregate and prioritise findings from the tools you already run, but don’t apply the fix themselves).

How were vendors scored, and how were the 12 in this report actually compared?

We normalised the market to 41 scored features across three maturity bands: table-stakes (most vendors), common (moderate coverage), and differentiating (limited coverage, specialist depth). A weighted scoring model favours features that need greater technical depth, producing one maturity score per vendor. We assess each at the Functional Group level, specific enough to show where products differ, general enough to stay useful to IT leaders new to the category. The most comprehensive tool is not automatically the best buy: where vulnerability management is one feature inside a broader platform, breadth is context, not credit, and where a vendor runs another vendor's engine underneath, we flag the OEM relationship, because two "different" products can be the same technology.

What happens if I want another vendor assessed?

Get in touch. This report focuses on solutions widely regarded as market leaders or strong emerging players, not every product on the market, and we are glad to look at ones we have not yet covered.

Disclaimers

All assessments reflect Tekspace’s independent professional judgement based on structured product research.

This report is intended as a decision-support tool and does not constitute professional advice. Organisations should conduct their own due diligence appropriate to their specific requirements, risk profile, and regulatory obligations.

If you believe any information in this report requires correction, or if you would like your product assessed for inclusion, contact Tekspace Research at hello@tekspace.com.au.

Contact our team
Get the next assessment
No vendors selected yet
Make an enquiry