First obligations from September 2026
Vulnerability Management

Detect, track, and remediate vulnerabilities — across your entire portfolio

Continuous NVD/OSV matching, CVE tracking with SLA management, and dashboard analytics in one platform

Annex I Part II of the EU Cyber Resilience Act requires manufacturers to address and remediate vulnerabilities without delay across the entire support period. Kunnus covers the complete workflow: components are continuously matched against NVD and OSV, and every detected vulnerability is tracked against SLA deadlines to resolution — including a real-time dashboard with MTTA, MTTD, and MTTR.

Annex I Part IINo. 2, 3, 7, 8
NVD & OSVData sources
CVSSScoring
SLA trackingDeadlines
app.kunnus.tech/vulnerabilities

Vulnerability Mgmt

12
Open
8
In Progress
47
Resolved (30d)
3
ENISA Reports
CVECVSSStatus
CVE-2024-0727
9.8
Patch Ready
CVE-2024-1234
7.5
In Analysis
CVE-2024-5678
6.1
Fix Deployed
CVE-2024-9012
4.3
Monitoring

Key Benefits

CVE Tracking & SLA Management

CVE list with CVSS score, severity badge, SLA status (On Track / At Risk / Breached), assignee, and discovered date.

Continuous Sync with Trustify

One-click sync against the Trustify database. Shows SBOMs scanned and new vulnerabilities discovered. Automatic correlation with your portfolio.

Security Updates Followed Up

Fixes and security updates are tracked per product and version — separate from feature updates, as Annex I Part II No. 2 requires.

Security Dashboard Analytics

MTTA/MTTD/MTTR metrics, CVSS histogram, top-risk products, components, and vendors. Configurable time range for trend analysis.

Capabilities

CVE Detail & Response Timeline

Annex I Part II No. 2

Full CVE information, affected components, status, assignment, and response timeline. Every step documented and traceable.

Own Vulnerability Reporting & Tracking

Art. 13

Manually report and track internally discovered vulnerabilities. Manual CVE entry, SLA assignment, and full tracking.

Regular Tests & Reviews

Annex I Part II No. 3

Continuous vulnerability monitoring plus CI scans with the open-source kunnus-scanner. Test cycles are documented as evidence.

CSAF Feed Ingestion

External CSAF feeds are auto-ingested and tracked against your SLA rules. Seamless integration into the existing vulnerability workflow.

Configurable Dashboard

Severity breakdown, SLA status, resolution metrics, and trend charts. Freely configurable time range for management reporting.

Use Cases

01

Proactive Vulnerability Management

A manufacturer syncs daily with Trustify, detects new CVEs automatically, and tracks remediation with SLA tracking — from discovery to fix.

02

Shared Components across the Portfolio

A vulnerability in a shared library affects twelve product variants. Kunnus shows all affected products instantly and tracks remediation per variant.

03

Management Reporting

The security dashboard shows MTTA, MTTD, and MTTR at a glance. Leadership gets reliable metrics for audits and compliance evidence.

Keep vulnerabilities under control

See how Kunnus automates CVE tracking and SLA management. We'll walk you through the workflow in a personalized demo.