VM / Cisco

Cisco Vulnerability Management

Cisco Vulnerability Management, formerly Kenna.VM, is a risk-based vulnerability-management product that ingests existing scanner findings, applies threat feeds, and supports service-level tracking by risk. It is in the sample as legacy context: Cisco published end of sale and a last-support date and did not name a replacement in the bulletin.

Legacy risk-based vulnerability managementResearch reviewed

What you are evaluating

This is not a current purchase path. End of sale is 10 March 2026 and last support is 30 June 2028. Remaining work is inventory, export, and successor design on the remaining support term, not new licenses.

A useful evaluation context

A plausible evaluation context is an existing Kenna or Cisco Vulnerability Management deployment that must prove export completeness and plan an exit before last support.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Risk-based ingest of findings from existing scanners rather than replacing those scanners.
  • Threat-feed context applied to ingested vulnerabilities.
  • Service-level tracking by risk for owner follow-up while the product remains supported.

Where it fits in the work

  1. Inventory every connected scanner, asset identifier, scoring configuration, exception, and owner mapping still living in Cisco Vulnerability Management.
  2. Export findings, asset identifiers, and exceptions into a durable store you control, and test that a reviewer can reconstitute them without the console.
  3. Use the remaining support term to choose a successor architecture; do not assume Cisco has named a replacement.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

On a licensed Cisco Vulnerability Management instance you still operate, export asset identifiers, findings, exception records, and risk-based service-level configuration into durable storage you control. Do not purchase new licenses.

Evidence to look for

A reviewer can rebuild asset identifiers, open findings, and documented exceptions from the export without the console, and can state the remaining support term and that no vendor-named replacement appears in the bulletin.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which asset identifiers, open findings, exceptions, and service-level rules actually export in a reusable form?
  2. What remaining support term applies to this instance, and who owns the successor decision?
  3. Which scanner integrations and threat-feed assumptions would have to be rebuilt elsewhere?

Names you may encounter: Kenna.VM · Kenna. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.