Key Highlights
Scheduled scans compare all managed Windows, Linux, and macOS endpoints against a centrally synced patch repository, and each missing patch arrives with the vendor's own severity and CVE-based risk context attached.
A local patch database stays synced from the central repository, so assessments always run against current vendor data.
Manual "Update Now" sync or a daily scheduled sync, chosen per operational preference.
Configurable patch categories and per-OS sync keep the repository scoped to the estate.
One repository serves Windows, Linux, and macOS assessment from a unified console.
Scheduled scans detect missing patches on managed endpoints, eliminating the need for anyone to run an audit by hand.
Each managed endpoint is compared against the repository on its scan schedule.
New gaps appear as scans refresh each machine's missing-patch picture.
Results feed the same console that drives deployment, with no export-import step.
Each missing patch carries the vendor's own severity, and a synced CVE repository adds risk context on top.
Vendor-supplied severity classes: Critical, Important, Moderate, and Low, with no invented scoring.
CVE-based prioritization ranks exposure by severity, exploitability, and real-world exposure.
Prioritization is rule-based, not AI-driven, so the ranking is explainable to any reviewer.
Vendor-defined patch types keep the backlog readable, and out-of-the-box reports turn scans into decisions.
Categories include Security Patches, Critical Updates, Definition Updates, Bug Fixes, Feature Updates, Update Rollups, Service Packs, Hotfix, Tools, and Updates.
OOB reports list missing, applicable, and declined patches per scope.
The same assessment data feeds compliance scoring on the Patch Compliance & Vulnerability page.
Assessment reaches the whole estate, covering all operating systems and the application layers running on each.
Windows, macOS, and Linux endpoints are all scanned from one console.
Linux coverage spans the major distributions, including Ubuntu, Debian, CentOS, RedHat, Rocky, Alma, openSUSE, Oracle, Mint, and Pardus.
Third-party application patches are assessed alongside OS patches, covering 60+ applications with the same scanning engine.
Intelligence
Most patch failures are discovery failures. A machine that never got scanned is a machine nobody knew was behind, and a flat list of missing patches gives no way to tell an urgent kernel fix from a cosmetic update.
Motadata ServiceOps closes both gaps: scheduled scans keep the missing-patch picture current throughout the estate, and vendor severity plus CVE-based risk context tells the team which gaps deserve the next maintenance window.
How It Works
Update local patch database daily from central repositories, scoped by category and OS.
Scan endpoints:Run scheduled scans detecting missing patches on Windows, Linux, macOS, and 60+ third-party apps.
Apply vendor severity (Critical, Important) and patch types (Security, Hotfix) to missing patches.
Prioritize exposures by severity, exploitability, and exposure using synced CVE repository rules.
Manage RedHat endpoints via Agent Nomination or Satellite Server with SHA-256 checksums.
Output OOB reports detailing missing, applicable, and declined patches for deployment decisions.
Role-Based Value
Nothing hides, scheduled scanning means a machine's missing patches are known before an incident finds them.
Nothing hides, scheduled scanning means a machine's missing patches are known before an incident finds them.
Discovery, assessment, and the deployment that follows share one platform and scope model, so the programme does not span disconnected tools.
Discovery, assessment, and the deployment that follows share one platform and scope model, so the programme does not span disconnected tools.
Rule-based ranking gives auditors and change boards a documented rationale rather than a black box.
Rule-based ranking gives auditors and change boards a documented rationale rather than a black box.
OS patches and third-party applications are assessed by the same scanning engine, so nothing sits in a coverage blind spot.
OS patches and third-party applications are assessed by the same scanning engine, so nothing sits in a coverage blind spot.
From Visibility to Control
Nothing hides. Scheduled scanning means a machine's missing patches are known before an incident finds them.
Risk-first ordering. Vendor severity plus CVE context puts the dangerous gaps at the top of the list.
Explainable priorities. Rule-based ranking gives auditors and change boards a rationale, not a black box.
One console. Discovery, assessment, and the deployment that follows share the same platform and scope model.
One engine, whole estate. OS patches and 60+ third-party applications are assessed by the same scanning engine, so nothing sits in a coverage blind spot.
Explore More