Automated Software Vulnerability Remediation FAQ
Last updated: October 5, 2026
The Basics
What is automated software vulnerability remediation?
Cork reads the software installed on your clients' endpoints through your RMM and matches it to known vulnerabilities (CVEs and KEVs). It then pushes the updated version through your RMM, either one time or on a schedule.
Is this OS patching?
No. It covers software that runs on top of the operating system: browsers, PDF readers, 7-Zip, and similar apps. Keep your OS patching process as it is.
Which operating systems are supported?
Windows only, for now. WinGet and Chocolatey are Windows package managers. Mac and Linux endpoints can still show vulnerabilities, but they are not remediated automatically.
Do I need to install a new agent?
No. Everything runs through the RMM or endpoint manager you already have connected.
Which RMMs are supported?
Intune, NinjaRMM, DattoRMM, VSA X, and ConnectWise Automate, with more to come. Your RMM must also return a software inventory to Cork. Acronis, Atera, and Level do not return software through their APIs today, so vulnerabilities cannot be detected through them.
Where does the vulnerability data come from?
NVD and VulnCheck. VulnCheck is a community-driven superset of NVD, so it often flags actively exploited vulnerabilities sooner.
How is this different from my RMM's built-in third-party patching?
Most RMM patching covers a fixed list of roughly 200 to 300 apps and does not tie updates to vulnerabilities. Cork links each vulnerability to a package that fixes it, across 13,000+ supported applications.
How It Works
What are WinGet and Chocolatey, and do I need both?
They are the package managers Cork uses to install updates. WinGet comes with most Windows 10 and 11 machines, though some environments disable it through group policy (see 📄 Software Installer Scriptsfor the fix). Chocolatey only works where it is already installed. If you are not sure it is on your endpoints, uncheck it in Install Preferences.
Do I have to pay for Chocolatey?
No. Cork uses Chocolatey as a free package manager. You do not need a managed Chocolatey license.
What privileges does it run with?
Updates run with the same privileges as your RMM agent. Software installed per user is updated as that user. Software installed system-wide is updated at the system level.
Will it reboot machines or close open apps?
Cork never forces a reboot or closes a running app. If an app like Chrome is open, the update completes when the user restarts it. When you run remediation is your call, but we always recommend testing first, especially around line-of-business apps or strict EDR policies.
What if a device is offline when the schedule runs?
Most RMMs queue the job and run it when the device checks back in. Intune is the exception: it does not queue, so the install fails if the endpoint is offline or, for user-level installs, no one is signed in. The next scheduled slot retries it.
Will it conflict with patch policies already in my RMM?
It shouldn't. If Cork updates an app first, your RMM sees it is already current and skips it.
Setup and Scheduling
What do I need to set up first?
It depends on your RMM. NinjaRMM, DattoRMM, and VSA X need a script created for each package manager you plan to use. Some existing Ninja and Intune connections need to be reconnected, and ConnectWise Automate may need updated permissions. Step-by-step instructions are in 📄 Software Deployment Automation.
How should I roll it out?
Test on your internal or NFR tenant first. Then add a few trusted clients. Once vulnerability counts start dropping, expand to everyone.
What schedule do you recommend?
Pick one day and several consecutive hours, for example 8, 9, 10, and 11 PM, so a failed attempt retries the next hour. Schedules can run at any hour, multiple times a day, or multiple days a week.
Can I limit it to certain clients or severities?
Yes. A schedule can target All Clients, Clients with Financial Protection, Eligible Clients, or an individual client. A client-specific schedule takes precedence over a broader one. You can also remediate all vulnerabilities, Accelerated and above, Critical only, or KEVs only.
Can I exclude software that shouldn't be updated?
Yes. Each schedule lets you pick which software to include, and everything else is ignored. You can also silence a vulnerability from its three-dot menu. Silencing does not remove its impact on the Cork Score.
Results and Reporting
How do I know if a remediation worked?
Every attempt, successful or failed, is logged. See Risk Insights > Vulnerabilities tab (Recent Installs), and each client's detail page. "Sent to RMM" means the RMM accepted the job.
Why does a vulnerability still show as "sent" the next morning?
A successful install silences the vulnerability for up to a week. It clears once your RMM reports the fixed version on the next sync. Cork syncs overnight, or you can run Resync All from the Integrations page.
Why can't some vulnerabilities be remediated automatically?
Cork only remediates when it can confidently match your installed software, the vulnerability, and a package that fixes it. Older or licensed software often has no package. If you expected an app to be covered and it isn't, open a support ticket.
What is the Vulnerability Exposure Report?
Click the shield icon in the top right of the dashboard. It shows open vulnerabilities, how many Cork can remediate automatically, and which apps have the most vulnerabilities.
How does remediation affect the Cork Score?
Vulnerabilities age: the longer they stay open, the bigger the impact on the score. Fixing a critical vulnerability within about 5 days keeps its impact minimal.
Does remediation affect Financial Protection?
Not currently. Software vulnerabilities do not affect Financial Protection at this time, though that may change. Remediating them still strengthens your clients' security posture and Cork Score.
Billing
How is it billed?
It is an add-on, priced in tiers based on your total billable endpoints. If you enable it mid-cycle, the charge first appears on your next invoice.
Related Articles
📄 Automated Software Remediation: Setup guide for scheduling remediation, with the core FAQ
📄 Software Deployment Automation: Supported RMMs and the setup each one needs before remediation can run
📄 Software Installer Scripts: Package manager details, including how to re-enable WinGet when group policy blocks it
📄 Software Vulnerabilities: How vulnerabilities are detected and prioritized (Critical, Accelerated, Routine)
📄 Cork Cyber Score: How the score works and what moves it