Security Stack Logo
vRx logo

Vulnerability Management

vRx

Automated patching, patchless in-memory protection, and scripted fixes for 20,000+ apps and OSs.

vRx Overview

What it does

vRx is an autonomous vulnerability remediation platform that closes the loop between detection and fix rather than stopping at a ranked finding list. It discovers assets through an endpoint agent and the agentless vRadar network scanner, uses Software Bill of Materials (SBOM) based detection to catch vulnerable libraries that signature scanners miss, and remediates through three native paths: vPatch automated patching across Windows, macOS, Linux, and more than 20,000 third-party applications, vShield in-memory patchless protection, and vScript scripted fixes for configuration weaknesses.

How it works

vScore ranks each Common Vulnerabilities and Exposures (CVE) by combining CVSS, EPSS, and Known Exploited Vulnerabilities (KEV) signals with asset criticality and agentic exploit simulation from the vIntelligence layer, which also normalizes findings from EDR, SIEM, CSPM, and third-party scanners into one deduplicated queue. vPatch deploys patches on demand, on a schedule, or by policy rule, with asset groups for canary testing and phased rollouts, while vShield wraps vulnerable application memory to block exploit paths when no patch exists, without reboots. Each action is logged, re-validated, and mapped by vComply to HIPAA, PCI DSS, Cyber Essentials, and 100+ CIS Benchmarks.

Credentials and traction

Vicarius holds a SOC 2 Type II attestation achieved without exceptions. vRx was named a Niche Player in the 2025 Gartner Magic Quadrant for Exposure Assessment Platforms, a Major Player in the IDC MarketScape: Worldwide Exposure Management 2025 Vendor Assessment, and Best of Show in the Security (Enterprise) category at Interop Tokyo 2025. Customers include Toyota, Samsung, Domino's, the NHS, EL AL Airlines, Jamaica Broilers Group, and Starbucks, across more than 500 organizations in over 60 countries.

Key Capabilities

mapped to solution categories
Autonomous Vulnerability Remediation

Creates ITSM change records (ServiceNow, Jira Service Management), as part of the patch workflow, maintaining audit trail and change management compliance.

Applies OS and application patches to vulnerable systems automatically based on configurable risk thresholds, without requiring per-patch analyst approval.

Validates patch impact in a staging environment or test clone before applying to production, reducing remediation-caused service disruption risk.

Reverts applied patches to the pre-patch system state when post-deployment stability issues are detected.

Pairs each finding with a recommended remediation action scoped to the affected assets and routes it through a human approval step before execution, with policy rules defining which actions may run without approval.

Blocks exploit paths for a disclosed vulnerability at the memory level of the running application, without a vendor patch, reboot, or binary change, bridging the gap between disclosure and patch availability or covering end-of-life software.

Re-scans the asset after a patch, script, or mitigation executes and confirms the vulnerability is no longer present, rather than marking the finding closed on task completion.

Executes custom, community, or AI-generated scripts (PowerShell, Bash, Batch) on affected assets to close vulnerabilities that have no patch path, such as registry misconfigurations and hardening gaps.

Risk-Based Vulnerability Management (RBVM)

Cross-references the vulnerability inventory against live threat feeds tracking CVEs under active exploitation in the wild, surfacing vulnerabilities with confirmed attacker activity.

Incorporates asset metadata (network exposure, business criticality, data classification) into vulnerability prioritization so that a critical CVE on an isolated internal test system ranks lower than a medium CVE on an internet-facing payment server.

Scans cloud resource configurations and container image CVEs alongside traditional OS and application vulnerabilities in a unified risk view.

Assigns likelihood-of-exploitation scores using threat intelligence, vulnerability characteristics, and active exploit availability, independent of CVSS, which measures severity rather than exploitability.

Recommends the minimum patch set that eliminates the highest-risk exposure (accounting for shared libraries and patch co-dependencies), rather than presenting a ranked CVE list.

Creates tickets, assigns owners, and tracks remediation progress in ITSM platforms (ServiceNow, Jira), closing the loop between finding and fix rather than producing a static report.

Enforces remediation deadlines by severity, reports on SLA compliance, and escalates overdue findings through configured approval chains.

Aggregates and deduplicates findings from network scanners, endpoint agents, cloud scanners, and third-party tools into one normalized record for cross-estate risk ranking.

Continuously discovers external-facing assets (domains, IPs, cloud services, APIs, certificates) including assets deployed outside the official inventory.

Continuous Threat Exposure Management (CTEM)

Generates trend reports on exposure posture (new exposure, remediated exposure, outstanding exposure by severity), in business language suitable for security program reviews.

Maps the discovered exposure inventory against active threat actor targeting and in-the-wild exploitation data to surface vulnerabilities under active attack.

Creates and tracks remediation tasks across teams and ticketing systems, measuring exposure reduction over time rather than simply listing open findings.

Confirms whether prioritized exposures are actually exploitable by running or ingesting adversarial validation results, such as breach and attack simulation or automated penetration testing delivered natively or by an integrated third-party tool, and re-ranks or closes exposures on the outcome so the queue reflects confirmed rather than theoretical risk.

Ranks exposures by their accessibility, visibility, and exploitability combined with asset criticality, business impact, and the security controls already in place, so a medium-severity issue on a critical, reachable, unprotected service outranks a high-severity issue on an isolated or compensated one.

Discovers assets and their exposures across the external, internal, cloud, and end-user attack surfaces, covering endpoints, network and on-premises infrastructure, identities and entitlements, hosts, containers, IoT and OT, and cloud platforms and applications, either through native discovery or by integrating third-party discovery sources, and reports vulnerabilities, misconfigurations, unmanaged assets, and compliance gaps in one inventory.

Tracks the life cycle of exposures through a centralized, aggregated view supported by automated workflows.

Pushes a mitigation for a prioritized exposure directly to a security control, for example a firewall, endpoint, or posture-management rule, as a compensating measure when a patch is unavailable or delayed, and tracks that mitigation alongside the exposure until it is remediated.

Uses generative AI to produce exposure-specific fix instructions, scripts, or remediation playbooks from the finding and its asset context, so remediation owners receive an actionable plan instead of a generic advisory.

Compliance

certifications
SOC 2 Type II

Integrations

compatible tools
AteraAzure ADCrowdStrike FalconDuoGoogle G-SuiteJumpCloudOktaOneLoginSplunk

Implementation & support

Deployment model
Agentless (API Integration)Endpoint AgentSaaS
Support channels
DocumentationEmail SupportKnowledge BasePhone SupportTicketing PortalTraining / Academy

Info last updated on September 7, 2026

Buyers

Start a shortlist with vRx

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.