Scalefusion has launched Veltar Vulnerability Management, a new capability designed to connect vulnerability detection with remediation. It can identify vulnerabilities across managed Windows and macOS endpoints, help security teams determine which ones need attention first, and then send those findings directly into Scalefusion UEM for patching.
The idea itself is not new. Vulnerability scanners have been identifying CVEs for years. The problem starts after the scan is complete.
A security team may find hundreds of vulnerabilities, but someone still needs to figure out which ones actually matter, which devices are affected, whether a patch is available, and how quickly the issue needs to be fixed. In many organizations, that process also involves moving information between security and endpoint management tools.
This is the gap Scalefusion is trying to address with Veltar.
I have worked with vulnerability testing, penetration testing and bug hunting for years, and one thing I have learned is that a vulnerability list is not the same thing as a remediation plan. A report can contain a lot of findings, but treating every vulnerability with the same urgency is neither practical nor useful.
Veltar tries to add more context to that decision. The platform combines CVSS, EPSS, CISA’s Known Exploited Vulnerabilities (KEV) data and endpoint context to calculate risk. Scalefusion says it also considers 30-day EPSS likelihood and active exploitation signals when helping teams prioritize vulnerabilities.
That is important because CVSS alone does not tell the complete story. A vulnerability can have a high severity score but may not be actively exploited, while another vulnerability with a lower score could be attracting attackers right now. CISA’s KEV catalog provides another useful signal because it focuses on vulnerabilities that are known to have been exploited in the wild.
Veltar also maps those vulnerabilities to the actual devices, applications, and operating system builds affected by them. That sounds like a small detail, but it can make a significant difference when dealing with a large endpoint fleet.
Knowing that a CVE exists is one thing. Knowing that it affects 17 specific laptops running a particular application version is much more useful to the person responsible for fixing it.
Scalefusion has built the workflow around five steps: discover, assess, prioritize, remediate and verify. The platform continuously detects vulnerabilities across supported operating systems and applications. Scalefusion says newly surfaced CVEs reported within the last 24 hours can also be tracked alongside existing findings.
Teams can then prioritize vulnerabilities using threat and exploitability signals, device context and remediation deadlines. Veltar includes resolution windows for Critical and High vulnerabilities, allowing administrators to track which findings are within their SLA and which ones have become overdue.
This SLA tracking is one of the more practical features in the announcement. Security teams do not just need to know what is vulnerable. They also need to know what has been sitting unresolved for too long.
Once a vulnerability is prioritized, Veltar can connect the finding to Scalefusion UEM’s patch management workflow. The company says teams can deploy applicable operating system and third-party application updates without moving findings between separate consoles or manually transferring vulnerability data.
And there is one more step that is easy to overlook: verification. Veltar can track patch status and remediation across affected endpoints, giving administrators a way to check whether the vulnerability was actually resolved. That matters because pushing a patch is not necessarily the same as successfully fixing every affected device.
This approach also fits with what Scalefusion has been building with Veltar. The company already positions Veltar around endpoint security capabilities such as web security, device trust, compliance and secure access. Vulnerability management adds another security function that is directly connected to the devices already being managed through its UEM platform.
I think this is the strongest part of the announcement. Scalefusion is not simply adding another vulnerability dashboard. It is trying to connect the vulnerability finding with the system that can actually fix it.
That matters even more as the time available to respond to security vulnerabilities gets shorter. I recently wrote about how cyberattacks are evolving faster than ever and security updates are catching up. Finding a vulnerability quickly is useful, but the real security benefit comes from reducing the time between discovery and remediation.
There are still limitations, though. Veltar is focused on managed Windows and macOS endpoints. It is not a replacement for every vulnerability management or security scanning product an enterprise might use. Organizations have servers, network infrastructure, cloud environments, web applications and other assets that may need different security tools.
So I would look at Veltar as an endpoint-focused layer rather than a complete replacement for the traditional security stack.
For companies already using Scalefusion UEM, the integration could make the remediation process considerably simpler. Instead of discovering a vulnerability in one place, figuring out which devices are affected somewhere else and then starting another patching workflow, the entire process can happen within the same endpoint management environment.
Whether that actually reduces remediation time in large environments will depend on how accurately Veltar identifies vulnerabilities, how quickly its threat intelligence is updated and how well the patching workflow handles real-world exceptions. Those are the things that matter once the product moves beyond the feature list.
For now, Scalefusion’s approach makes sense. Security teams do not need another report telling them that they have vulnerabilities. They need better context about what is dangerous, which devices are affected, what needs to be fixed first and whether the fix actually worked.
Veltar Vulnerability Management is now available for managed Windows and macOS endpoints, with support for vulnerabilities across operating system components and third-party applications.

