Watch Agent
Continuous CVE exposure: match each new advisory against the software you actually run, try to reproduce it, and say so either way.
A new CVE is published. The first useful question is whether an affected version is supported by fresh evidence on an asset you own. The Watch Agent answers that question against your inventory and labels the result as potential until verification proves more.
When the product or version is unknown, Watch creates no exposure claim. Feed and inventory health are measured separately so operators can distinguish a quiet day from a broken pipeline.
What the agent does
The Watch Agent reads new advisories continuously and compares each one against versioned software evidence in your asset inventory, including authenticated connected-site manifests where available. It never matches on your industry or a vendor list.
A match is a reason to look, not a result. You can start a focused verification, and managed Watch assessments may test it within the same rules of engagement the scope sets for every other assessment.
- It watches assets already in your inventory; connected-site manifests improve version coverage.
- It matches on a component and usable version, never on sector or product-only guesswork.
- It stays inside the scope. The rules of engagement apply here as everywhere.
The four states
Every advisory the agent raises carries one state, and the state says exactly how much is known. The distinction between "we found a version match" and "we made it happen" is the whole point of the agent, so the two never share a word.
- Potential — the version matches an advisory. Nobody has tried it yet.
- Verifying — the agent is attempting the documented vector right now.
- Confirmed exploitable — the agent reproduced it against your asset.
- Not reproduced — the agent tried and failed. The version matched; the exposure did not.
Why the agent thinks it applies
Every advisory shows its own reasoning before it shows its verdict. You can see the component the agent observed, the identifier it resolved it to, the basis of the match, and when it last saw the component on that asset.
This is what lets you disagree with the agent. A backport risk or a version conflict is flagged as such, because a distribution can patch a component without changing the version string the agent can read.
How exposures are ordered
Severity alone does not tell you what to do first. Each exposure carries the CVSS score from the advisory, the EPSS percentile for how likely exploitation is in the wild, and whether CISA lists it as known-exploited. An exposure the agent reproduced on an asset you own outranks a higher CVSS the agent could not reproduce.
- CVSS — how bad the issue is, according to the advisory.
- EPSS — how likely it is to be exploited, as a percentile.
- CISA KEV — whether it is known to be exploited in the wild.
- Reproduced — whether it works here, which outranks all three.
Where exposures appear
Potential exposures stay in Threat Watch while they are unverified. Only a confirmed verification creates or links a canonical Risk, preserving one evidence-backed risk lifecycle instead of presenting an advisory match as a proven finding.