Skip to main content

UVM 1.0 Release Notes

Release date: May 2026

UVM 1.0 introduces JupiterOne's Unified Vulnerability Management product. You can now take raw findings from every scanner you run, deduplicate and prioritize them on the graph, and route remediation cases to the teams that own the affected assets.

What is new

FeatureWhat it means for you
The prioritization funnelA four-stage workflow — Vulnerabilities → Unified → Prioritized → Plans — visible as a live Sankey diagram on every UVM page
Vulnerability unificationOne row per CVE per asset, deduplicated across every configured scanner, with full source attribution
EPSS and KEV enrichmentExploitation probability from FIRST.org and CISA's Known Exploited Vulnerabilities catalog on every CVE
Configurable risk scoringA transparent composite score combining CVSS, EPSS, crown jewel status, and public exposure — weights you own
CPE-based remediation plansPrioritized vulnerabilities grouped by common fix, so teams act on a short list of plans instead of thousands of CVEs
AI-generated plan contentEvery plan ships with an AI-written remediation summary and step-by-step fix instructions
Ownership-based case routingCases route to owning teams in Jira through Hierarchical Resource Groups
AI AssistantSort, filter, and navigate UVM views in natural language

Supported scanner integrations

UVM 1.0 ships with first-class support for CrowdStrike Falcon, Qualys VMDR, SentinelOne, Tenable.io, and Wiz. SBOM-sourced findings are also recognized.

Getting started

  1. Confirm at least one supported scanner integration is configured and syncing
  2. Tag your business-critical assets with tag.crownJewel
  3. Open Vulnerabilities in the navigation and review the default risk configuration
  4. Open the Plans tab and create cases for the top remediation plans
  5. Confirm cases arrive in the correct Jira projects

For full feature documentation, see Unified Vulnerability Management.