platform

Patch management

vRx brings every patch type into one view: Windows KBs, macOS updates, application patches, and Linux packages. Decide when and how each deploys. Your environment, your schedule, your rules.

request a demo
130
+

New vulnerabilities per day

80
%

reduction in manual patching

MTTR

from Months to Hours

benefits

Patching that fits how you work

vRx gives your team a complete view of every patch needed across your estate. Work through the queue on demand, set scheduled deployments, or configure rules that keep your environment current. The choice is yours, not the platform's.

Everything, one place

All patch types in one view: application patches, Windows KBs, macOS updates, and Linux packages, with consistent search and filtering across all.

Your call, always

Patch on demand, on a schedule, or by rule. vRx adapts to how your team works, not the other way around.

Fix what matters

vScore flags the patches that close your highest-risk CVEs first, so your team never patches in the wrong order.

Groups, not spreadsheets

Organize patches, assets, and software into reusable groups. Apply different policies to each and let dynamic rules keep membership current.

80% less effort

Teams using vRx cut time spent on manual patching by 80%, redirecting hours to higher-value security work.

Always audit ready

vRx logs, timestamps, and records every patch deployment, giving your team audit-ready evidence for any compliance framework.
key features

Automate patching across your entire estate

vRx covers all patch types in one unified view and gives your team full control over how and when patches deploy. Patch groups, asset groups, and software groups let you organize the work the way your environment demands.

Available updates view
+
One view for all patch types: application patches, Windows KBs, macOS updates, and Linux packages, with consistent search and filtering across all.
Static and dynamic patch groups
+
Hand-pick patches for static groups, or write a rule and let dynamic groups keep membership current as patch data changes. No manual maintenance.
Software group management
+
Group software by type, vendor, or custom rule, then apply patch policies and compliance checks to the whole collection at once.
Asset group targeting
+
Group assets by location, team, type, or custom tag. Target specific groups for deployment, canary testing, or phased rollouts without touching the rest.
OS and app coverage
+
Windows, macOS, and Linux covered alongside over 20,000 third-party applications from a single queue, with no additional integrations required.
Per-asset CVE precision
+
vRx computes CVE coverage per asset, not per patch, giving your team a precise view of what each upgrade closes on each machine.
Resources

Additional Resources

downloadable

True remediation solution brief

article

Why your 30-day patching cycle is an open invitation to attackers

Shortlist 2024 by Captera
Tech leader award by PeerSpot
4.8
Customer first by Gartner
Customer first by Gartner
4.7
Customer first by Gartner
Leader spring by G2
Leader spring by G2
Leader spring by G2
Leader spring by G2

What Our Customers Say About Us

See why enterprises trust our approach to AppSec to secure their business-critical applications

From urgency to strategy

“Vicarius allowed us to step away from reactive patching and finally manage vulnerabilities with strategy instead of urgency.”
No items found.
en / Anonymous IT Division Manager
Anonymous IT Division Manager
IT Division Manager

60% faster remediation, many hours saved

Anonymous Security Analyst
No items found.
en / Anonymous Security Analyst
Anonymous Security Analyst
Security Analyst

Patchless Protection is an incredible technology!

"vRx reduces the time customers spend on patching by reducing the overhead on the administrators, allowing them to do additional work. It saves time they would spend addressing the patching process, follow-ups, etc."
No items found.
en / Antwune Gray
Antwune Gray
VP IT Security and Services

Third-party software patching is the most valuable feature.

"We have automated third-party patching on specific software, improving efficiency by 80%. vRx has reduced our patching time, which has improved our operations. It is more robust than other solutions because it offers better third-party remediation."
No items found.
en / Billy Turner
Billy Turner
VP, Managed Technology & Services

Complete Vulnerability Remediation Platform

"What stood out was that it wasn’t just a scanner or a patch manager. It was an entire remediation platform. You discover vulnerabilities, prioritize based on real risk, and remediate automatically."
en / Eric Dowsland
Eric Dowsland
Chief Customer Officer

My favorite feature is Patchless Protection

"With Vicarius' vRx, I've never seen a patch that failed or had to be rolled back. We're saving quite a bit of time. Our clients using vRx haven't had any issues, and they've easily established patching for all their endpoints."
en / Jeremy Herman
Jeremy Herman
Security Engineer

Great patching capabilities, helpful dashboard, and excellent support

"vRx has saved us an incredible amount of time. We can just rely on the automated system and the schedules we've set. It's a huge time saver. It's saved us hundreds of hours."
No items found.
en / Michael Cortez
Michael Cortez
Sr. Director of IT

Single source of truth, capable of handling any application in our fleet

"vRx gives a single pane of glass to see what patches needed to go out and what sort of vulnerabilities we have on our Windows machines. Our meantime to remediate vulnerabilities has gone down by about 60% to 70%."
No items found.
en / Peter Fallowfield
Peter Fallowfield
IT Manager

Merge Security & IT to Remediate Threats

“Vicarius’s vRx enabled Adama to centralize and consolidate work between IT and security teams, leading to a more efficient patching workflow."
No items found.
en / Oshri Cohen
Oshri Cohen
CISO

Unified vulnerability discovery, prioritization, and remediation

"Vicarius streamlines vulnerability management between IT & Security by directly linking identified vulnerabilities to required patches, enhancing efficiency. The automation process has saved at least 30 percent of our manual tasks."
en / Wayne Ajimine
Wayne Ajimine
Information Security Professional

EL AL secures global Patch Compliance

“Within two weeks we decided on Vicarius. Patch scheduling is now a one-day task instead of a full-time job.”
en / Tal Shachar
Tal Shachar
Deputy Director, Infrastructure, EL AL Airlines

Everything you need to know

What patch types does vRx cover?

vRx covers application patches, Windows cumulative updates and KBs, macOS point and major releases, and Linux package updates through APT, YUM, APK, and other package managers. All of them appear in one view, with consistent search and filtering across every patch type.

Does vRx patch automatically, or does my team control the schedule?

Your team controls it. vRx gives you three deployment options: patch on demand, set a scheduled maintenance window, or configure rule-based deployment for patches that match your criteria. The platform does not push patches without instruction. Your workflow determines when and what deploys.

What is the difference between static and dynamic patch groups?

Static groups contain a hand-picked list of patches that stays fixed until you change it. Dynamic groups use a rule, and membership updates whenever patch data changes. Use static groups for deliberate, auditable sets like pilot rollouts. Use dynamic groups for ongoing policies like "all Mozilla patches."

How does vRx compute CVE coverage for each patch?

CVE coverage in vRx is per asset, not per patch. Two assets upgrading to the same Firefox version can close different CVE sets if they are starting from different installed versions. vRx computes the delta between each asset's current version and the target, so your team sees the precise risk each patch closes on each machine.

Does vRx work in environments managed by WSUS?

Yes. vRx captures the management mode on each asset individually. A Windows KB can be flagged as WSUS-managed on one machine and Windows Update-managed on another within the same estate. Your team does not need to standardize patch management before deploying vRx. The platform adapts to how your environment is already set up.

What happens when there is no patch available for a vulnerability?

vRx offers two paths beyond patching. vShield Patchless Protection mitigates the vulnerability at the asset without applying a patch, blocking exploit paths until a validated patch is ready. vScript lets your team run community, custom, or AI-generated scripts for detection and remediation. All three paths read from the same discovery layer.

How does vRx decide which patches to prioritize?

vScore feeds directly into patch prioritization. It factors in exploitability, asset criticality, weaponization status, and business context alongside CVE severity. The result is a ranked queue where patches closing your highest-risk CVEs rank first, regardless of release date or generic severity score.

4.7/5

Remediate more vulns with vRx