Skip to main content

Vulnerability and patch management

How Trio MDM finds, fixes, and proves remediation of vulnerabilities — and a tour of the Patch & vulnerability pages.

Patch & vulnerability is where Trio MDM surfaces every known weakness on your fleet and helps you fix it — from the moment a vulnerability is discovered to the signed proof that it was remediated. You will find it in the left sidebar under Security > Patch & vulnerability.

It replaces one-off "install all patches" actions with a complete, auditable workflow: vulnerabilities are normalized into findings, you remediate them with controlled patch plans, and every deployment is recorded as signed evidence.


How it works

Trio MDM continuously builds your vulnerability picture from endpoint scans, vendor advisories, and threat-intelligence feeds, then drives it through four stages:

  • Discover – Every vulnerability is normalized into a finding with a CVE, severity, CVSS score, exploit status, and the list of affected devices.

  • Prioritize – Findings are ranked by severity, active exploitation, and how close they are to their SLA deadline, so the most urgent work rises to the top.

  • Remediate – You deploy the vendor fix with a patch plan. Patches are signature-verified and can be validated on sandbox devices before they reach the fleet.

  • Prove – Each patch run is captured as signed, immutable evidence you can export for compliance.

Auto-patch can run this entire loop for you on findings that match your rules, and Zero day response gives actively exploited vulnerabilities their own fast-track triage.


What's in Patch & vulnerability

The module is organized into eight pages:

  • Overview – Fleet-wide exposure at a glance: open findings, devices exposed, SLA risk, and auto-patch coverage.

  • Zero day – Triage for vulnerabilities under active exploitation or with public proof-of-concept code.

  • Findings – The full, filterable list of vulnerabilities, with a detail view for each.

  • Patch plans – Create, track, pause, resume, and retry deployments.

  • Auto-patch – Rules that remediate matching findings automatically, per platform.

  • Evidence – Signed remediation records and compliance reports for every patch run.

  • Audit log – An immutable record of every user and system action in the module.

  • Settings – Sandbox devices, the patch library, and SLA tiers.


Severity and SLA tiers

Every finding is graded critical, high, medium, low, or info, and each severity carries a remediation deadline called its SLA tier. The defaults are 7 days for critical, 14 days for high, 30 days for medium, and 90 days for low. Adjust them under Settings > SLA tiers.

If you have any questions, please contact Trio support.

Did this answer your question?