> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-management-in-cortex-xsiam.md).

# Vulnerability management in Cortex XSIAM

{% hint style="info" %}

### Note

Requires the Cortex Cloud Posture Security, Cortex Cloud Runtime Security, Exposure Management, Cortex XSIAM Premium or ASM add-on.
{% endhint %}

Managing vulnerabilities effectively is crucial to proactively maintaining the security, integrity, and availability of IT infrastructure. Cortex XSIAM provides a comprehensive vulnerability management platform, helping you identify, assess, prioritize, and remediate security vulnerabilities across your entire IT infrastructure, including endpoints, code, and cloud.

Cortex XSIAM leverages advanced detection techniques, real-time threat intelligence, and automated workflows to streamline the vulnerability management process. This allows your security team to focus on the most critical issues, reduce risk exposure, and ensure compliance with industry standards and regulations.

Cortex XSIAM helps identify and prevent vulnerabilities across the entire application lifecycle, while prioritizing risk for your cloud-native environments. Integrate vulnerability management into any CI process, while continuously monitoring, identifying, and preventing risks to all the hosts and images in your environment. Cortex XSIAM combines vulnerability detection with an always up-to-date threat feed and knowledge about your runtime deployments to prioritize risks specifically for your environment.

{% hint style="info" %}

### Note

Cortex XSIAM vulnerability management provides the ability to identify and assess runtime vulnerabilities in every asset across traditional IT and cloud environments. For vulnerabilities detected in your software development lifecycle through application security scans, refer to the [Cortex Cloud Application Security](/cortex-xsiam/cloud-security/cortex-cloud-application-security.md) documentation.
{% endhint %}

## **Cortex XSIAM vulnerability concepts**

**Vulnerability**

A vulnerability is a CVE or other known software security weakness that can occur in a network or system. Vulnerabilities are typically defined by the National Vulnerability Database (NVD) and other established security information sources, such as GitHub Security Advisory or Red Hat Security Advisory.

{% hint style="info" %}

### Note

CVE is an acronym for Common Vulnerabilities and Exposures, which is a list of publicly disclosed security threats. We often use the term "CVE" to refer to a vulnerability that has been assigned a CVE ID. Cortex XSIAM identifies CVEs and non-CVE vulnerabilities.
{% endhint %}

**Vulnerability findings**

A vulnerability finding is a specific instance of a vulnerability that was discovered in your system through a vulnerability scan. Findings include both actionable and informational context, including information about the asset on which the vulnerability was discovered. Some findings might be critical and should be addressed as soon as possible; others are less important and won’t require any action at all. Cortex XSIAM applies vulnerability policies to findings to prioritize them and create issues for the ones that are most critical to remediate.

**Vulnerability issues**

Cortex XSIAM creates a vulnerability issue when a specific instance of a vulnerability in your environment matches a vulnerability policy. Each issue has a priority, assignee, and progress status associated with it. Issues also provide contextual information about the asset on which the issue is found, exploitability, and other information required for remediation and mitigation.

## **Vulnerability Management dashboard**

Vulnerability management analysts and managers can use the **Vulnerability Management** dashboard to visualize their most pressing risks, changes to risk over time, and remediation progress.

Navigate to **Home > Modules > Vulnerability & Exposure Management** and select **Dashboard** to see the detailed view.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management/vulnerability-management-in-cortex-xsiam.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
