Vulnerability ManagementAutonomous Vulnerability RemediationRisk-Based Vulnerability Management (RBVM)

Vulnerability remediation platform combining automated patching, patchless protection, and scripting for 10,000+ applications.

Vendor Information

Vicarius logo

Vicarius

New York, NY, United States

vRx Overview

Vicarius vRx is an autonomous vulnerability remediation platform combining automated patching, patchless protection, and custom scripting across operating systems, applications, and third-party software, supporting over 10,000 applications across Windows, macOS, and Linux environments. The platform replaces reactive vulnerability detection with proactive resolution by automatically discovering installed software, identifying vulnerabilities, and correlating findings with threat intelligence to prioritize remediation based on actual exploitability rather than Common Vulnerabilities and Exposures (CVE) volume.

When patches are unavailable or cannot be applied due to compatibility or operational constraints, vRx provides patchless protection through memory-level virtual patching that blocks exploit behaviors without system restarts or application downtime, particularly valuable for zero-day vulnerabilities, legacy systems, and critical production environments. The platform includes a scripting engine with pre-built scripts and custom script capabilities to address complex vulnerabilities requiring specific configurations or registry changes, with automated deployment across thousands of endpoints based on policy rules for risk severity, asset criticality, compliance requirements, and operational windows, while customers report 60-80% improvement in vulnerability management processes including reducing mean time to remediate by 60-70%.

Founded in 2016 by Michael Assraf, Roi Cohen (Chief Executive Officer), and Yossi Zeevi (Chief Technology Officer) and headquartered in New York with operations in Tel Aviv, Vicarius has raised $60 million across four funding rounds led by Bright Pixel Capital, Jerusalem Venture Partners (JVP), and AlleyCorp, growing to approximately 112 employees serving 900+ customers across 70 countries. The platform has been recognized in Gartner's 2025 Magic Quadrant for Exposure Assessment Platforms as a Niche Player, featured in Gartner's Emerging Tech report on Preemptive Exposure Management and Automated Remediation, and included in the IDC MarketScape 2025 Worldwide Exposure Assessment Platforms Vendor Assessment, achieving ranked \"Highest Return on Investment (ROI)\" recognition on G2.

Key Capabilities

Standardized capabilities mapped to this product's security niche

Autonomous Vulnerability Remediation

Creates ITSM change records (ServiceNow, Jira Service Management), as part of the patch workflow, maintaining audit trail and change management compliance.

Applies OS and application patches to vulnerable systems automatically based on configurable risk thresholds, without requiring per-patch analyst approval.

Validates patch impact in a staging environment or test clone before applying to production, reducing remediation-caused service disruption risk.

Reverts applied patches to the pre-patch system state when post-deployment stability issues are detected.

Risk-Based Vulnerability Management (RBVM)

Cross-references the vulnerability inventory against live threat feeds tracking CVEs under active exploitation in the wild, surfacing vulnerabilities with confirmed attacker activity.

Incorporates asset metadata (network exposure, business criticality, data classification) into vulnerability prioritization so that a critical CVE on an isolated internal test system ranks lower than a medium CVE on an internet-facing payment server.

Scans cloud resource configurations and container image CVEs alongside traditional OS and application vulnerabilities in a unified risk view.

Assigns likelihood-of-exploitation scores using threat intelligence, vulnerability characteristics, and active exploit availability, independent of CVSS, which measures severity rather than exploitability.

Recommends the minimum patch set that eliminates the highest-risk exposure (accounting for shared libraries and patch co-dependencies), rather than presenting a ranked CVE list.

Creates tickets, assigns owners, and tracks remediation progress in ITSM platforms (ServiceNow, Jira), closing the loop between finding and fix rather than producing a static report.

Enforces remediation deadlines by severity, reports on SLA compliance, and escalates overdue findings through configured approval chains.

Integrations

Compatible tools and platforms

Asset Management SystemsAWSCrowdStrike MarketplaceEndpoint Management PlatformsMicrosoft Entra IDOktaPax8SIEM PlatformsSOAR PlatformsSSO ProvidersTicketing Systems

Solution Details

Compliance & Certifications

Regulatory frameworks and security certifications

SOC 2 Type II

Deployment Options

Where and how this solution can be deployed

CloudHybridOn-PremisesSaaS

Support Channels

Available support and communication options

24/7 SupportCustomer Success TeamEmail SupportKnowledge BaseTechnical Account Manager (TAM)

Pricing Model

How this solution is priced

Per Endpoint

How to buy

This profile hasn’t been claimed yet. Contact the vendor directly for pricing and purchasing options.

Is this your company?

Claim Your Profile