Skip to content

How Patcharo decides

Deterministic, sourced and explainable. Here is exactly how a status is computed.

Sources, in order of authority

  1. Vendor advisories and vendor-authored CVE records: affected and fixed releases.
  2. CISA Known Exploited Vulnerabilities: confirmed exploitation, due dates, ransomware use.
  3. NVD: CVSS scores and weaknesses (CWE).
  4. FIRST EPSS: probability of exploitation in the next 30 days.

Matching, step by step

  1. 1The recorded version is parsed with the vendor's own scheme (for example PAN-OS hotfixes or Check Point Jumbo Hotfix takes). If it cannot be parsed: Unknown.
  2. 2If it matches an exact affected release or falls inside an affected range: Affected, with the fixed release.
  3. 3If the source lists the branch as affected without patch-level detail: Needs review.
  4. 4If it is at or past the fix on an affected branch: Fixed.
  5. 5If the source assessed the branch and the release is outside every range, or the vendor states unlisted versions are unaffected: Not affected.
  6. 6Anything else: Unknown. Missing data never becomes a clean result.

Priority: why now

A priority score is the sum of visible reasons: known exploitation (KEV), exploitation probability (EPSS), severity, internet exposure, production environment and business criticality. Every point is shown next to the action.

Where AI is not used

No language model decides whether a product or version is affected, and no summary replaces the source. The only inputs are structured vendor and public data, versioned and checksummed.

Known limits

Coverage is limited to the products listed in the catalog. Vendors that publish only prose (no structured versions) produce Needs review rather than a verdict. Always confirm with the vendor advisory before a change.