Cadres IT Operations & Infrastructure
Sheet SYN-08 Rev 2026.08
Start Trial

Sheet SYN-08 — Network Operations Manual

Vulnerability Management

Known-exploited and published vulnerability matching against the fleet, severity-based policy rules, and the exposure view.

Audience: Security and network operations teams Focus: Real exposure on real devices

Scope

Vulnerability management in Synapse starts from the fleet it already knows and asks which devices are exposed to which published and known-exploited vulnerabilities. This guide covers the matching, the review surface, and the policy rules built on top.

What gets matched

Synapse matches fleet devices against the CISA Known Exploited Vulnerabilities catalog and published vulnerability data from the NVD, using CPE 2.3 identifiers for precision. The known-exploited catalog is refreshed automatically on the platform’s maintenance cycle, so the matching baseline does not depend on anyone remembering to update it.

The review surface

The vulnerabilities view has two tabs:

  • Device matches. Every match between a fleet device and a vulnerability, with serial and status filters, the vendor, product, and vulnerability name, and a badge marking known-exploited entries. Known-exploited matches deserve attention first: they are the vulnerabilities attackers are already using.
  • The catalog. The full known-exploited-vulnerabilities catalog with free-text search, for looking up an advisory independent of whether it currently matches the fleet.

Vulnerability as policy

The vulnerability compliance domain turns exposure into a deterministic policy check alongside Wi-Fi standardization. Its rules control what fails a resource, including a minimum severity threshold, and it produces the same pass, fail, or not-applicable results on the same organization, label, or site scopes as every other policy. That keeps vulnerability posture on the same dashboard, with the same evidence discipline, as the rest of compliance.

Where it feeds

Vulnerability results drive one of the four health scoring dimensions, so sustained exposure shows up in site scores and rollups rather than staying buried in a list nobody opens.