Skip to content

Teams running Vulnerability Response patch critical CVEs in half the time

Matt Day Matt Day
Teams running Vulnerability Response patch critical CVEs in half the time

We recently measured remediation behavior across anonymized customer fleets. Customer accounts running Vulnerability Response closed more of their critical vulnerabilities, and closed them faster. The pattern held across every customer cohort.

To see how our Vulnerability Response affects remediation, we compared critical- and high-severity vulnerabilities across two groups of customer fleets: those with Vulnerability Response enabled and those without.

Customer accounts running Vulnerability Response, on top of Iru Endpoint Management, remediated 85.4% of those vulnerabilities. The accounts with only Iru Endpoint Management reached 64.8%. That is a 31.7% improvement in coverage, before counting speed.

On speed, the gap widens. Median time to remediate dropped from 2.58 days to 1.21 days, 53% faster. The window between a Common Vulnerabilities and Exposures (CVE) record landing and a patch reaching the device closed by more than half.

The gap is structural, and it is widening

Public vulnerability counts climb every year, and the teams managing them are not growing at the same pace. AI-assisted attackers compress the time from disclosure to exploit, while the patch queue keeps filling. 

The math is unforgiving. Verizon's 2024 Data Breach Investigations Report (DBIR) found that even well-resourced organizations take around 55 days to remediate half of their critical vulnerabilities once patches are available. Every day in that window is a day the vulnerability stays exploitable.

Most patching workflows were built for a slower era. Security scans for vulnerabilities, files a ticket, and hands it to IT. IT coordinates the patch across tools, then waits on users to restart. Detection and remediation live in separate systems, so the handoff is where the time disappears.

What Vulnerability Response actually does

Vulnerability Response patches vulnerable applications in the Auto Apps catalog automatically, based on CVE severity and the rules the admin sets. The Iru Agent caches files and installs when an app is closed, or prompts the user ahead of a deadline when action is required. The admin sets the response once, and Iru manages the patching itself. As a result, end users work safely without needing to act on updates.

Detection and remediation sit in the same platform, so there is no second tool to reconcile. The Vulnerabilities view tracks remediation progress alongside the CVEs themselves. On Mac, this runs end to end without manual intervention.

Why it scales when teams don't

When a team manages hundreds of devices and applications, manual patching breaks down. Triaging CVEs by hand, mapping them to affected apps, and chasing restarts costs hours per cycle, multiplied across every new disclosure.

Vulnerability Response removes the per-patch labor. The cost of closing a vulnerability stops scaling with the size of the fleet. Teams keep pace with the volume because the tooling absorbs the work, not because they added headcount.

"Iru VM has simplified our entire vulnerability strategy. Combined with automatic Vulnerability Remediation and Auto-Apps, our support team of 7 can easily keep over 90 tenants compliant while we spend our time on client requests."

— Nick Reese, Sr. Engineer at Foojee

Getting started

Vulnerability Response is available to every customer running Iru Vulnerability Management on Mac. Configure it, add it to a Blueprint with an Assignment Map, and the catalog stays patched against critical CVEs without manual follow-up.

Book a demo to see it close the gap on your own fleet.

Recent Articles

Featured image: Rustbot, the macOS malware used in the latest Rust Supply Chain Attack
Cristian Molina 10 min read

Rustbot, the macOS malware used in the latest Rust Supply Chain Attack

On August 20, 2026, attackers published malicious versions of three widely used Rust packages to crates.io, the official Rust package registry. On macOS, the payload is a remote access trojan (RAT) that collects cloud credentials, SSH keys, cryptocurrency wallet data, and browser profile information, then sends it to attacker-controlled infrastructure. It installs a launch agent to survive reboots and accepts follow-on commands from its operators. Once running, it decrypts its configuration, profiles the host, Reads the local browser stores, installs persistence via LaunchAgent, and beacons out. The packages were available for approximately two hours before removal. The attackers also withdrew the previous stable versions, which pushed automated dependency resolution toward the compromised releases. Any environment that compiled an affected project during that window should be treated as compromised. This blog documents Iru's analysis of the native Apple Silicon ARM64 implant.

Threat Intelligence
Featured image: Inside the screensharingd Bugs: How macOS Screen Sharing Went from Root File Access to Pre-Auth Compromise
Csaba Fitzl 6 min read

Inside the screensharingd Bugs: How macOS Screen Sharing Went from Root File Access to Pre-Auth Compromise

In late July 2026, a cluster of vulnerabilities in macOS Screen Sharing turned what initially looked like a fairly constrained privilege problem into one of the more interesting macOS remote-attack stories in years.

Threat Intelligence
Featured image: Apple is deprecating hdiutil in macOS 27 Golden Gate. Are your scripts ready?
Arek Dreyer 3 min read

Apple is deprecating hdiutil in macOS 27 Golden Gate. Are your scripts ready?

If you spent part of last weekend fielding Slack messages about hdiutil, you're not alone. Jeff Johnson's lapcatsoftware.com blog flagged that the man page for hdiutil in the macOS 27 Golden Gate beta now carries a deprecation notice:

Educational

See Iru in action

Discover why thousands of teams choose Iru

By submitting this form I agree to Iru’s Privacy Policy and consent to be contacted by Iru about its products and services.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.