Skip to content

Security Dashboard

The Security Dashboard provides centralized insight into software vulnerabilities detected across your environment. By correlating vulnerable applications, affected endpoints, and CVE severity data, Security Monitor supports efficient vulnerability assessment and remediation planning.

You find it under Windows → Security on the Vulnerabilities, Affected Endpoints, Affected Software, and Detected CVEs tabs. For the security configuration of your endpoints, such as antivirus and encryption, see the Security Overview.

Vulnerabilities tab with an Overall Exposure of 7.7 High risk, the CVEs by Severity chart, and the Top 20 Affected CVEs by CVSS list

The Vulnerabilities tab gives a fleet-wide picture of vulnerability exposure at a glance.

Overall Exposure is a score from 0 to 10. It’s the average of each endpoint’s severity-weighted CVE score across all scanned endpoints. Endpoints without vulnerabilities count as 0, and an endpoint’s most severe vulnerabilities weigh most in its score. The score is labelled by risk level:

Score Risk level
Below 4 Low
4 and above Medium
6 and above High
8 and above Critical

The CVEs by Severity (30 days) chart shows how the volume and composition of detected CVEs has changed over the past month, split into Critical, High, Medium, and Low severity. Use this to spot trends — a sudden spike in Critical CVEs typically means a newly published vulnerability affects software that is common in your fleet.

The Top 20 Affected CVEs by CVSS table lists the highest-severity vulnerabilities currently detected in the environment. Each row shows the CVSS score, the date the CVE was published, and a description of the vulnerability. Clicking a CVE ID opens the full CVE details page.

Security Monitor organizes vulnerability data into three tabs:

  • Affected Endpoints – devices affected by vulnerable software
  • Affected Software – applications introducing vulnerabilities
  • Detected CVEs – individual vulnerability records and severity scoring

These views allow administrators to analyze vulnerability exposure from different perspectives and prioritize remediation.

Affected Endpoints tab listing endpoints with their vulnerable software, CVEs, and highest CVSS score

The Affected Endpoints tab highlights which devices are most exposed to security risks.

Each entry displays:

  • Device Name
  • Last Check-in
  • Vulnerable Software Count
  • Detected CVEs
  • Highest CVSS Score
  • Exposure Score – the endpoint’s own severity-weighted CVE score from 0 to 10

The CVSS Score (0–10) is a standardized severity rating indicating the criticality of a vulnerability.

Selecting values within the table provides quick navigation:

  • Device Name opens the device-specific security view.
  • Vulnerable Software switches to the Software view filtered by the selected endpoint.
  • Detected CVEs switches to the CVE view filtered by the selected endpoint.

The list can be sorted by:

  • Name
  • Last Check-in
  • Vulnerable Software
  • Detected CVEs
  • Highest CVSS Score

Filtering options allow further refinement based on endpoint-specific criteria.

Affected Software tab listing vulnerable applications with their endpoints, CVEs, and highest CVSS score

The Affected Software tab highlights applications that introduce security risks across the environment.

Each entry displays:

  • Software Name and Vendor
  • Vulnerable Endpoints Count
  • Detected CVEs
  • Highest CVSS Score

If the software is supported within Repository Apps, a Check for Updates option is available. This provides direct access to the corresponding repository application page to review available updates when endpoints are not running the latest published version.

When end-of-life information is available for an application, the Status column shows a Support Lifecycle badge. Hover over the badge to see the application’s most recent releases:

  • Released – the release date
  • Support Status – when security support ends or ended, for example “Ended 14 days ago”
  • Release – the release line and its latest version

A release whose support has ended no longer receives security updates. Vulnerabilities found after that date stay open, so plan to upgrade or replace the application.

Support Lifecycle popover for Google Chrome, listing each release with its release date, support status, and release number

  • Software Name opens the Detected CVEs view filtered by that software.
  • Vulnerable Endpoints switches to the Endpoints view filtered accordingly.
  • Detected CVEs performs the same filtered navigation.

Sorting is available by:

  • Name
  • Vulnerable Endpoints
  • Detected CVEs
  • Highest CVSS Score

Filtering options are specific to the Software view.

Detected CVEs tab listing CVEs with the affected product, Microsoft MSRC badge, number of vulnerable endpoints, CVSS score and risk score

The Detected CVEs tab provides insight into the specific vulnerabilities affecting your environment.

Each entry displays:

  • CVE Identifier
  • Vulnerable Endpoints Count
  • CVSS Score
  • Risk Score – CapaOne’s contextual scoring system reflecting organizational impact

The Risk Score ranges from 0 to 100 and helps you decide which vulnerabilities to fix first. It combines the CVSS score, weighted at 75%, with the number of affected endpoints, weighted at 25%. The CVSS score weighs more, because a single vulnerable endpoint can be enough to compromise an organization.

A CVE can also show these badges:

  • Disputed – the vulnerability status of the CVE is contested in the NIST National Vulnerability Database.
  • Exploited – Microsoft reports that the CVE is actively exploited.
  • Selecting a CVE opens a dedicated CVE details page.
  • Selecting Vulnerable Endpoints switches to the Endpoints view filtered by the selected CVE.

Sorting is available by:

  • Name
  • Vulnerable Endpoints
  • CVSS Score
  • Risk Score

Filtering options allow focused investigation based on severity and risk relevance.

Selecting a CVE opens a details page providing comprehensive insight into the vulnerability.

The view includes three sections:

Displays endpoints where affected software is installed, allowing administrators to quickly assess exposure.

Provides structured vulnerability information including:

  • Affected Software
  • CVE Summary

This section explains how the vulnerability impacts the environment.

Provides authoritative reference links related to the CVE, including external vulnerability databases and technical documentation containing mitigation guidance and additional information.

For CVEs that Microsoft has published an advisory for, a Microsoft Security Update card shows Microsoft’s severity and exploitability assessment, whether the CVE is exploited or publicly disclosed, and the updates that fix it. Each fix lists the product, the article, and the fixed build number.

Microsoft Security Update card with the severity and exploitability assessment, and a table with the release date, product, article link, and fixed build number

Support Lifecycle of the affected software

Section titled “Support Lifecycle of the affected software”

When end-of-life information is available for the affected software, the details page also shows its Support Lifecycle. See Support Lifecycle.

Overall, this view enables administrators to understand vulnerability impact, evaluate exposure across endpoints, and prioritize remediation efforts effectively.

Security Monitor surfaces vulnerabilities — remediation happens by updating the affected software.

If the vulnerable application is covered by Repository Apps, the Affected Software tab shows a Check for Updates link that takes you directly to the repository app entry. From there you can confirm whether the latest version resolves the CVE and push the update to affected endpoints.

For software not in the repository catalog, update via a Company App entry or by distributing the updated installer through a Script.

A practical remediation workflow:

  1. Open the Vulnerabilities tab and note the Overall Exposure score and top CVEs.
  2. Switch to Affected Software and sort by Detected CVEs or Highest CVSS Score to find the most impactful applications. Check the Support Lifecycle badge for applications that no longer receive security updates.
  3. For each high-priority application, use Check for Updates if available, or plan a manual update deployment.
  4. After deploying updates, return to the Affected Endpoints tab and confirm that affected endpoints show a reduced CVE count following their next check-in.
  • CVSS scores are standardized — they come from the NIST National Vulnerability Database and are not calculated by CapaOne. A score of 10 means the vulnerability is remotely exploitable with no authentication required and full system impact.
  • A high CVE count per endpoint is normal for Windows devices with many installed applications. Focus on Highest CVSS Score and Exposure Score rather than raw CVE counts when prioritising remediation.
  • The Exposure Score per endpoint is distinct from the Overall Exposure score — it reflects that specific device’s vulnerability profile, not the fleet average.
  • CVE data is refreshed daily from the NIST CVE database. Newly published CVEs appear in Security Monitor after the next scheduled sync.