← All four agents
WATCH
Know when a new CVE plausibly affects software you run
A CVE is published and every vendor emails everybody. The eye narrows that feed to software versions supported by fresh inventory evidence. It stays silent when the version is unknown, labels a version match as potential, and preserves the evidence you need to decide whether to run a focused verification.
The advisory view.
See why an advisory matches an asset you own: the version we read, where we read it, and how strong the match is. Start a verification from here.
PotentialHighCISA KEVBackport risk
CVE-2026-3817 in OpenSSL 3.0.11
api.demo.acme.ioFirst seen 6 hours ago
This has not been tested yet. We matched an observed software version against an advisory. A focused verification determines whether the documented issue is exploitable here.
Why we think this applies
- Component observed
- OpenSSL 3.0.11
- Identified as
- pkg:generic/openssl@3.0.11
- Match basis
- The version we read falls inside a range the advisory describes as affected.
- Last observed
- 6 hours ago
The distribution may have patched this without changing the version string, so the banner alone cannot settle it.