Every day new security vulnerabilities in software are discovered and published as CVEs (Common Vulnerabilities and Exposures). CVE monitoring means: your systems are continuously matched against this database.
We identify affected packages and assess exposure, exploitability and existing controls in addition to the CVSS score. This determines the appropriate patching or containment action.
CVE-2024-XXXXX
CVSS 9.8 - Remote Code Execution
CVE-2024-XXXXX
CVSS 7.5 - Privilege Escalation
Patched
142 packages up to date
From automated scanning to documented risk assessment and action, our CVE process is transparent and traceable.
Inventory & Exposure
Regular automated vulnerability scans of all systems and services using up-to-date CVE databases.
Automated Notification
Automatic notification for new CVEs affecting your deployed software versions - prioritized by CVSS score.
Risk-based & documented
We assess exposure, exploitability, affected systems and existing controls. The service level governs response, not a blanket patch-completion deadline.
Documentation
Regular reports on the security status of your systems - for audits, ISO certifications and internal compliance.
From OS packages to container images - we cover all layers of your software infrastructure.
The service level defines when a qualified response begins. The appropriate protective or patching action follows from affected systems, exploitability, exposure and technical scope.
| Service level | Qualified response | Service window | Scope |
|---|---|---|---|
Essential | By the end of the next business day | Mon-Fri 08:00-17:00 CET/CEST | Assessment and regular remediation in the appropriate maintenance window. |
Business | P1 within 4 service hours | Mon-Fri 08:00-18:00 CET/CEST | Faster qualified response during the service window. |
Production | P1 within 60 minutes | P1 around the clock | 24/7 P1 response for the explicitly covered customer environment. |
Critical | P1 within 30 minutes including callback | P1 around the clock | Available only after readiness review, runbook approval and capacity confirmation. |
A response time is not a guaranteed resolution time. General vulnerability notices and vulnerabilities without evidence of exploitation are not automatically P1 incidents.
New vulnerabilities are published every day - only a few affect your systems, and even fewer require immediate action. The value is not in collecting CVEs, but in filtering and assessing them.
New CVEs arrive daily from multiple sources: NVD, vendor advisories and the distribution security trackers. No single feed is complete - which is why we cross-check several against each other.
Every CVE is checked against your software inventory: deployed packages, versions, container images. What does not run in your environment does not trigger an alert - which keeps the noise low.
The CVSS score alone is not enough. We additionally assess exploitability and exposure: is there a public exploit? Is the service reachable from the internet or only internally behind a VPN? Not every 9.8 is critical in your environment - and some 6.5 very much is.
The result is a documented decision: a regular patch in the appropriate maintenance window, a compensating control or immediate containment where there is an acute material threat. The exact action depends on risk, approvals and technical scope.
The difference to a bare scanner: a tool hands you a list of a hundred findings. We hand you the few decisions that actually need to be made this week.
We do not invent our own vulnerability data - we evaluate the established sources and match them against your systems.
The central CVE database maintained by NIST with CVSS ratings - our basis for matching and scoring.
Security announcements from the software in use - from Proxmox and Nextcloud to PostgreSQL. Often faster and more precise than the corresponding NVD entry.
The Debian Security Tracker and Ubuntu Security Notices show whether and in which package version a vulnerability is fixed for your distribution - decisive for the patch decision.
The warning and information service of the German BSI aggregates and assesses current vulnerabilities for the German market - including a criticality assessment.
For us, CVE monitoring is not an isolated tool but a building block of the monitoring ladder: CVE alerts run in the same alert flow as the infrastructure monitoring on our Zabbix cluster. The same escalation chains, the same contacts - from CPU spike to critical vulnerability.
These services complement your vulnerability management.
SLA & Service Levels
Four tiers with clearly defined response times.
Monitoring Only
24/7 monitoring from €79.90; alerts go to your team.
Managed Zabbix
Platform operations from €79.90; alerts go to your team.
Compliance
GDPR, ISO 27001 and BSI C5.
Server Management from €149.90
Your servers, our operations - patching, monitoring, and response.
Contract & Maintenance Model
How scope, maintenance cadence, and responsibilities are defined.
Legacy Operations
Operation and modernization of legacy systems.
CVE (Common Vulnerabilities and Exposures) is a standardized directory of publicly known security vulnerabilities. Each CVE has a unique ID and a CVSS score (0-10) that rates the severity. Unpatched CVEs are one of the most common entry points for cyberattacks.
Scan targets, methods and frequency are agreed according to inventory, exposure and system load. The selected service level governs response time for qualified incidents; it does not automatically determine the scan schedule.
We assess more than the CVSS score: actual exposure, affected systems, known exploitation and existing controls. Where there is an acute material threat, we initiate necessary containment and inform you as quickly as possible. A general vulnerability notice without evidence of exploitation is not automatically a P1 incident. The service level governs qualified response, not a blanket patch-completion deadline.
Yes. We provide exportable reports in your preferred format (PDF, CSV) suitable for ISO 27001, BSI C5 and GDPR audits. Reports document all found vulnerabilities, their status and the measures taken.
From multiple sources that we cross-check against each other: the NIST NVD, the security advisories of the vendors in use, the security trackers of Debian and Ubuntu, and the warning and information service of the German BSI (CERT-Bund). The matching against your software inventory happens through our scans - turning the global feed into a list that only concerns your systems.
Not indiscriminately. Every relevant CVE is first assessed for affected systems, exploitability, exposure and existing controls. Regular updates are applied in the next appropriate maintenance window. An acute material threat may require immediate, preferably reversible protective action. Implementation follows a documented decision and the agreed approval and action boundaries.
A zero-day is a vulnerability for which no patch exists yet - so patching is not an option. Instead, we reduce the attack surface: limit exposure (firewall, VPN), implement vendor-recommended workarounds and sharpen monitoring on the affected systems. As soon as a fix is available, it is applied with priority.
Tell us briefly what it is about - we will get back to you within one business day.
Customer feedback on monitoring, updates, maintenance, support and stable production systems.
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
