Logo

Cisco Vulnerability Management

Cisco Vulnerability Management is a risk-based vulnerability management platform designed to help organizations identify which vulnerabilities create the greatest real-world security risk and prioritize remediation accordingly. Formerly known as Kenna.VM, the platform combines vulnerability data from multiple security tools with exploit intelligence, predictive analytics, asset context, and risk scoring to help security teams focus remediation efforts where they can reduce risk most effectively.

Quick Benefits

Cisco Vulnerability Management Benefits

At a Glance

Cisco Switch price quote banner

Need Cisco Pricing?

Tell us your requirements and receive a tailored quote for your Cisco licensing, deployment model and managed firewalls.

Get Price Quote →

License Overview

Cisco Vulnerability Management was offered primarily in Advantage and Premier editions.

Cisco Vulnerability Management Advantage provided the core risk-based vulnerability management capabilities, including centralized vulnerability data, asset and vulnerability risk scoring, predictive modeling, remediation prioritization, and Top Fixes recommendations.

Cisco Vulnerability Management Premier expanded these capabilities with deeper vulnerability intelligence, remediation-performance measurement, enhanced response to newly disclosed vulnerabilities, and additional research and workflow-enrichment capabilities.

The platform could aggregate vulnerability information from multiple scanners, endpoint-security tools, configuration databases, and other security systems rather than requiring organizations to replace their existing vulnerability scanners.

Cisco also offered related capabilities through Vulnerability Intelligence and the Application Security Module.

Cisco has now ended sales of Cisco Vulnerability Management. Organizations with active subscriptions should evaluate the remaining support period and determine how existing vulnerability workflows, integrations, and historical risk data will be handled during migration.

Product Overview

Traditional vulnerability-management programs often generate extremely large numbers of findings. Prioritizing those findings only through CVSS severity can result in security teams spending resources on vulnerabilities that are technically severe but unlikely to be exploited while more dangerous exposures remain unresolved.

Cisco Vulnerability Management was designed to address this problem through risk-based prioritization.

The platform aggregates internal vulnerability and asset information and combines it with external threat intelligence and exploitation data. This provides a more contextual view of each vulnerability.

Risk scores can be calculated for individual vulnerabilities, assets, and groups of assets. Security teams can then identify which remediation actions are expected to produce the greatest reduction in organizational risk.

The platform also provides Top Fixes recommendations, allowing teams to identify groups of vulnerabilities that can be remediated together for maximum impact.

Core Technical Flow

Cisco Vulnerability Management begins by collecting vulnerability and asset data from supported security platforms.

Existing vulnerability scanners, endpoint products, CMDBs, and other sources can feed findings into the platform. This allows organizations to centralize vulnerability information without replacing every existing assessment technology.

Cisco Vulnerability Management normalizes the incoming data and associates vulnerabilities with relevant assets.

The platform then enriches each vulnerability with external intelligence such as exploitation activity, weaponization information, threat behavior, and other real-world security signals.

Risk-scoring algorithms evaluate this combined information and calculate risk scores for vulnerabilities and assets.

Security teams can then use prioritization dashboards and Top Fixes recommendations to determine which vulnerabilities should be remediated first.

As vulnerabilities are fixed or environmental conditions change, risk scores and organizational risk posture can be recalculated to measure remediation effectiveness.

Options & Licensing Models

Cisco Vulnerability Management Option Primary Capabilities Typical Use
Advantage Centralized vulnerability management, risk scoring, predictive analytics, prioritization, and Top Fixes Organizations implementing risk-based vulnerability prioritization
Premier Advantage capabilities plus deeper vulnerability intelligence, remediation measurement, and advanced workflows Mature enterprise vulnerability-management programs
Vulnerability Intelligence Broader vulnerability and threat-intelligence information Security teams requiring vulnerability research beyond licensed assets
Application Security Module Aggregates application-security findings and prioritizes application vulnerabilities DevSecOps and application-security teams
Scanner Integrations Imports vulnerability findings from supported third-party security products Organizations maintaining existing scanner infrastructure
API Integrations Connects vulnerability intelligence with remediation and security workflows Automation and SOC integration

Cisco Vulnerability Management is no longer available for new purchases. These licensing options remain relevant primarily for understanding existing deployments, historical entitlements, and migration requirements.

Features & Benefits

Risk-Based Prioritization and Predictive Vulnerability Intelligence

Cisco Vulnerability Management combines internal vulnerability findings with real-world threat and exploit intelligence to determine which exposures represent the greatest practical risk. Instead of relying only on severity ratings, the platform considers exploitation activity, vulnerability characteristics, asset context, and historical threat behavior. Predictive analytics can also help security teams identify vulnerabilities that are more likely to become weaponized, allowing remediation to begin before widespread exploitation occurs.

Centralized Vulnerability Data and Remediation Optimization

The platform consolidates findings from vulnerability scanners, endpoints, CMDBs, and other security tools into a unified risk-management view. Top Fixes recommendations identify remediation actions that can reduce the largest amount of risk across the environment, helping security teams work through vulnerability backlogs more efficiently. Risk scoring for assets and groups also allows remediation teams to concentrate efforts on business-critical systems rather than treating every finding equally.

Reporting, Performance Measurement, and Security Workflow Integration

Cisco Vulnerability Management provides dashboards and metrics for tracking organizational risk, vulnerability trends, and remediation progress over time. Premier capabilities extend this with deeper remediation-performance measurement and vulnerability research. API and third-party integrations allow vulnerability information to support ticketing, security operations, application-security, and remediation workflows, making the platform part of a broader enterprise risk-management process.

Compatibility & Requirements

Existing Cisco Vulnerability Management environments should review:

Activation and Deployment

Historically, deployment began by provisioning the Cisco Vulnerability Management cloud environment and connecting existing vulnerability data sources.

Administrators configured integrations with vulnerability scanners, endpoint tools, CMDB platforms, and other supported security systems.

Asset and vulnerability information was then imported into the platform and normalized.

Teams could define asset groups, apply business context, review risk scores, and establish remediation workflows.

Top Fixes and vulnerability-prioritization dashboards could then be used to determine which remediation activities should receive the highest priority.

Because the platform is now end-of-life, new deployments should not be planned around Cisco Vulnerability Management.

Existing customers should instead inventory current integrations, export required data, document remediation processes, review subscription expiration dates, and establish a replacement strategy before the final support date.

Cisco Vulnerability Management Pricing and Quote

Cisco Vulnerability Management is no longer available for new quotations through standard Cisco ordering channels.

Cisco ended new product orders on March 10, 2026, and the last date to renew or add to an existing subscription was June 11, 2026.

Customers with active subscriptions can continue receiving applicable support and subscription services until June 30, 2028, according to their existing contract terms.

Organizations searching for Cisco Vulnerability Management pricing today should therefore focus on identifying existing entitlements and comparing current vulnerability-management alternatives based on capabilities such as:

 

Frequently Asked Questions