# Vulnerability Remediation Last Updated On: 14 Sep 2026 Remediating vulnerabilities by deploying patches is a crucial part of maintaining a secure infrastructure. Using the patch management feature of Endpoint Central MSP, you can remediate vulnerabilities manually or through automated patch deployment. [Vulnerability Remediation](https://www.youtube-nocookie.com/embed/DnbeSrfQbCo?si=2V5rHDjiD3reXSCY) ## Overview Patches are released by vendors to fix security flaws, bugs, or performance issues in software and systems. Neglecting to address vulnerabilities can expose an organization to significant risks. When vulnerabilities are left unpatched, attackers can exploit them to gain unauthorized access to critical systems, leading to data breaches, theft, or corruption. Hence, vulnerability remediation is essential for ensuring a secure and resilient infrastructure. **Note** Most of the time, deploying a single patch may remediate a large number of vulnerabilities associated with that software. If a patch is not available, click on the vulnerability name to view the vendor-provided manual resolution steps as a workaround. Follow those resolution steps to fix them. If a vulnerability is detected in a component supplied with a product and no patch or workaround is available, contact the relevant product support team for help. Patches will be supported by Endpoint Central MSP as soon as the vendor releases them. ## Vulnerability Remediation through Manual Deployment of Patches To find the patches associated with a specific CVE, navigate to **Threats & Patches → Patches → Supported Patches** and apply the CVE ID filter. To remediate vulnerabilities through manual deployment of patches: - From the **Software Vulnerabilities** or **Zero-day Vulnerabilities** section, select the required vulnerabilities for which a patch is available and click **Install/Publish Patches**. - From the **Detected CVEs** section, select the required vulnerabilities and click **Fix CVEs**. When a vulnerability affects multiple operating systems, deploy the applicable patches separately for each platform: 1. Open **Software Vulnerabilities** and select the required vulnerability. 2. Click the affected system count. 3. Apply the **Windows** platform filter, select the applicable entries, and click **Install Patch**. 4. Repeat the platform filtering and deployment separately for **macOS** and **Linux**, where applicable. 5. Verify that every selected patch installs successfully. You will be redirected to the **Install/Uninstall Patch** window, where the required missing patches to address the selected vulnerabilities will be listed. Configure the manual deployment settings to install these patches. To learn more about configuring manual deployment settings, refer to [this page](https://www.manageengine.com/desktop-management-msp/help/patch-management/manual-deployment.html). ![Manual Vulnerability Remediation showing the Install/Uninstall Patch window with missing patches listed](https://www.manageengine.com/products/desktop-central/help/images/vm16.png) *Install/Uninstall Patch window listing missing patches for the selected vulnerabilities.* ## Automated Vulnerability Remediation As enterprises grow and their IT environments become more complex, manually applying patches across many servers, workstations, and devices becomes increasingly difficult. Automated patch deployment allows you to scale patching efforts, applying updates to thousands of devices simultaneously. Once you configure automated patch deployment, if the required patch is available and [is approved](https://www.manageengine.com/desktop-management-msp/help/patch-management/enable_patch_approval.html), vulnerability remediation automatically occurs without requiring additional manual intervention — these approved patches will be deployed to the chosen targets automatically. To learn more about configuring automated patch deployment tasks, refer to [this page](https://www.manageengine.com/desktop-management-msp/help/patch-management/apd.html). ## Related - [Vulnerability Management Overview](https://www.manageengine.com/desktop-management-msp/help/vulnerability-management/vulnerability-management-overview.html) - [Vulnerability Assessment and Prioritization](https://www.manageengine.com/desktop-management-msp/help/vulnerability-management/assess-and-remediate-vulnerabilities.html) - [Manual Patch Deployment](https://www.manageengine.com/desktop-management-msp/help/patch-management/manual-deployment.html) - [Automated Patch Deployment](https://www.manageengine.com/desktop-management-msp/help/patch-management/apd.html) - [Enable Patch Approval](https://www.manageengine.com/desktop-management-msp/help/patch-management/enable_patch_approval.html)