SMB + MSP decision engine · deterministic by default

Fix the work that
changes exposure first.

Turn two ordinary CSV exports into a defensible first-12 remediation list. No account, no API key, and no upload: files stay in this browser.

Private by designLocal parsing · no network calls · demo data resets on refresh
01 / INPUTS

Bring the exports you already have.

Use a vulnerability CSV and, optionally, an asset CSV. Familiar column names are normalized safely; unknown or missing values are shown as lower confidence, never silently guessed.

Local text only · no uploads · ≤2 MB · ≤10,000 rows · ≤64 columns · malformed or binary content is refused
Safe demo loaded: 12 normalized records. Sample data is synthetic.
02 / ANSWER

Fix these 12 things first.

Ranked by a repeatable score, then explained in plain evidence.

01
Fix nowcheckout-api-prodOwner: Payments

Remote code execution in framework

CVE-2026-10001

Action: Apply the supported framework patch and retest the public checkout route.

severity 98/100known exploitationinternet-exposedbusiness importance 100/100
99priority score100% input confidence
02
Fix nowfile-transferOwner: Infrastructure

Managed file transfer flaw

CVE-2026-10003

Action: Apply the emergency vendor fix and rotate exposed service credentials.

severity 94/100known exploitationinternet-exposedbusiness importance 85/100
96priority score100% input confidence
03
Fix nowidentity-gatewayOwner: Identity

Authentication bypass in gateway

CVE-2026-10002

Action: Upgrade the gateway and validate privileged sign-in controls.

severity 91/100known exploitationinternet-exposedbusiness importance 95/100
96priority score100% input confidence
04
Fix nowvpn-gatewayOwner: Infrastructure

VPN denial-of-service

CVE-2026-10008

Action: Install the gateway hotfix and validate remote access availability.

severity 79/100known exploitationinternet-exposedbusiness importance 90/100
91priority score100% input confidence
05
Fix nowwarehouse-apiOwner: Supply Chain

Deserialization vulnerability

CVE-2026-10006

Action: Deploy the vendor update and run an order-path regression test.

severity 86/100public exploit signalinternet-exposedbusiness importance 90/100
89priority score100% input confidence
06
Fix nowsupport-portalOwner: Customer Operations

Server-side request forgery

CVE-2026-10005

Action: Upgrade the component and test egress restrictions.

severity 81/100public exploit signalinternet-exposedbusiness importance 80/100
85priority score100% input confidence
07
Fix nowhr-portalOwner: People Systems

Cross-site scripting

CVE-2026-10009

Action: Patch the portal package and test the employee workflow.

severity 72/100public exploit signalinternet-exposedbusiness importance 75/100
81priority score100% input confidence
08
Fix nextcrm-integrationOwner: Revenue Systems

OAuth token validation gap

CVE-2026-10007

Action: Update the integration library and test token audience validation.

severity 80/100no exploit signal suppliedinternet-exposedbusiness importance 85/100
75priority score100% input confidence
09
Fix nextfinance-dbOwner: Finance Systems

Database privilege escalation

CVE-2026-10004

Action: Patch during the approved maintenance window and verify least privilege.

severity 88/100public exploit signalnot marked internet-exposedbusiness importance 95/100
71priority score100% input confidence
10
Fix nextdesign-laptop-14Owner: Workplace

Local privilege escalation

CVE-2026-10012

Action: Deploy the endpoint update in the next managed ring.

severity 78/100public exploit signalnot marked internet-exposedbusiness importance 45/100
60priority score100% input confidence
11
Planbackup-serverOwner: Infrastructure

Backup agent escalation

CVE-2026-10010

Action: Update the backup agent and check job integrity.

severity 84/100no exploit signal suppliednot marked internet-exposedbusiness importance 80/100
56priority score100% input confidence
12
Plananalytics-workerOwner: Data Platform

Insecure temporary file

CVE-2026-10011

Action: Apply the update and verify worker isolation.

severity 75/100no exploit signal suppliednot marked internet-exposedbusiness importance 70/100
52priority score100% input confidence