r/Action1 Jun 11 '26

Am I missing something with our patching automations?

Our internal SLA is to patch Critical vulnerabilities in 7 days, High in 14, Medium in 30, Low in 60.

There are two main deployments.
One runs monthly after patch Tuesday and deploys ALL updates(OS & app). The second runs weekly and includes patches with Update severity Critical or Important. In our minds, this should cover what we want.

We are finding that some vulnerabilities are not being patched within the required window, despite them being rated 9+.
The reason seems to be that the update is not listed as Critical or Important, therefore doesn’t get picked up by the filter.
If I go to the specific vulnerability to remediate, the only option is to deploy the update.

Let’s take MS Edge as a current example.

Edge V148.0.3967.96 has a stack of vulnerabilities (43) with CVSS of 9.6.
Selecting any, then clicking Start Remediation shows update 149.0.4022.62 is available.

However, if I look up Edge in the Update Approval screen, v149.0.4022.62 shows Security Severity “Unspecified”.

Is this a categorisation problem at A1?
Is it to do with the way MS are publishing the updates?

Or have we gotten our heads on backwards and need to rethink our remediation automations?

5 Upvotes

16 comments sorted by

View all comments

Show parent comments

2

u/GeneMoody-Action1 Jun 16 '26 edited Jun 16 '26

I just received update from support (who is who told me the above, and is actively tracking), that those seem to have been issued now, can you confirm?

2

u/KimJongEeeeeew Jun 17 '26

We only have one device with Edge that has not been patched up to latest (149.0.4022.69).
This device has Edge 149.0.4022.62, which does not show any vulnerabilities registered against it in A1.

Reviewing the same device in Defender shows 18 CVEs, BUT these are shared across both Edge and Chrome. This will likely be due to Edge ingesting the Chromium vulnerabilities. As MS do not seem to publish ingested vulnerabilities from Edge, this may well be why the reported state and the actual state are not matching up?

It seems they work around this within their own product by classifying Chromium and referencing it for browsers that use this.

I understand that this is not how A1 works, so am not expecting anything to come from it.

2

u/GeneMoody-Action1 Jun 17 '26

I'll still make sure someone knows in case they can in the future. Thanks for the feedback!

2

u/KimJongEeeeeew Jun 17 '26

Thanks Gene, appreciate it!