About Patcharo
Security remediation intelligence for firewalls and security appliances.
Last updated 30 Sept 2026
What Patcharo is
Patcharo tells network and security teams which vulnerabilities affect the exact versions they run, which release fixes them, whether exploitation is known, what the vendor recommends and why a fix cannot wait, then lets them track the remediation. Know what you have, know what affects you, know what to fix, know why now.
Who it is for
Network and security engineers, IT and security teams, consultants and managed security providers who operate Check Point, Fortinet, Palo Alto Networks and Cisco firewalls and security appliances.
What it is not
Not a CVE list, not a CMDB, not a scanner. Patcharo installs no agent and never connects to your devices: it works from the versions you record and from public, official intelligence.
How it works
Vendor advisories and vendor-authored CVE records, CISA KEV, NVD, FIRST EPSS, CERT-FR and the vendors' life-cycle and recommendation pages are read at each synchronisation, checksummed and parsed. A deterministic matcher compares every recorded version with the affected and fixed ranges; a language model never decides a status. Every fact keeps its source and dates.
The public site
The same intelligence is published here for everyone: every CVE tracked with its severity, exploitation status, affected and fixed releases, the vendors' recommendations, CERT-FR references and support dates, in English and French, with sources and verification dates. The application adds the comparison with your own inventory.
Independence
Patcharo is independent from the vendors it covers and is not affiliated with them; product names are trademarks of their owners. This product uses the NVD API but is not endorsed or certified by the NVD.