LOGIC TELECOM
Tech worldJuly 23, 20263 min read

Kaspersky launches vulnerability management platform in Russia

Kaspersky VM centralises vulnerability discovery and prioritisation. We examine its confirmed functions, limits and the process required around it.

Dashboard prioritising vulnerabilities across enterprise infrastructure
Contents

On 15 July 2026, Kaspersky announced the commercial launch of Kaspersky Vulnerability Management in Russia. The platform is designed to centralise the discovery, prioritisation and remediation tracking of vulnerabilities across enterprise IT infrastructure.

Confirmed capabilities

According to the developer, the system discovers IT assets, checks configurations, enriches findings with its knowledge base and helps teams decide what to remediate first. It supports network and agent-based scanning, as well as assessments with different levels of access to target systems.

Kaspersky VM integrates with Kaspersky Security Center. An open API is available, and automatic data transfer to Kaspersky SIEM is planned. Licensing is based on the number of nodes, with the product positioned for environments containing at least ten devices.

Kaspersky also says that certification by Russia’s FSTEC and inclusion in the national software registry are being prepared. These were future steps when the announcement was published; the source does not state that either process has already been completed.

Why a vulnerability list is not enough

A scanner may produce hundreds or thousands of findings, but an identical technical severity does not imply an identical business risk. Priorities also depend on internet exposure, service criticality, active exploitation, data sensitivity and whether a patch can be applied safely.

The announcement cites Kaspersky Incident Response statistics indicating that one in three Russian attacks in 2026 begins with vulnerability exploitation and that the number of vulnerabilities grew by 24% year on year in the first half of 2026. These figures reflect one supplier’s observations and should not be treated as an incident forecast for every organisation. They are a reason to assess an organisation’s own estate.

Building a repeatable management process

The technology creates value only when ownership and remediation are defined:

  1. Maintain a current inventory of servers, endpoints, network devices, services and responsible owners.
  2. Set remediation deadlines for each asset class and risk level.
  3. Enrich technical severity with exposure, process criticality and compensating controls.
  4. Test updates and install them during an agreed maintenance window.
  5. When a patch cannot be applied, record the accepted risk, temporary control and review date.
  6. Rescan to verify that remediation has worked.

Useful management metrics include the share of overdue critical findings, mean remediation time, asset coverage and exceptions without an accountable owner—not simply the total number of findings.

Limits to test before procurement

The public announcement describes product capabilities but cannot replace a pilot in the customer’s own environment. A technical evaluation should cover:

  • discovery of virtual machines, containers, network equipment and short-lived assets;
  • the operational impact of agent and network scans;
  • prioritisation quality for the customer’s actual asset mix;
  • integrations with ticketing, SIEM, asset inventory and reporting systems;
  • knowledge-base update frequency and the time needed to add new checks;
  • deployment, logging, backup and role-separation requirements.

Maintenance windows and compensating controls are particularly important in operational technology. Applying a patch immediately to a legacy system can sometimes create more operational risk than temporary segmentation. Our report on increasing attacks against Russian industry provides the current threat context, while our guide to FSTEC requirements and data protection explains how controls relate to a threat model.

Takeaway

Kaspersky Vulnerability Management expands the choice of Russian tools for continuous vulnerability control. Its confirmed value is the combination of asset discovery, scanning and risk-based prioritisation. The business result, however, is measured by how quickly service owners remediate critical weaknesses and verify the fix. Certification and software-registry status should be checked separately at the time of procurement.

Source: Kaspersky’s official announcement dated 15 July 2026.

Primary source: Kaspersky: commercial launch of Kaspersky Vulnerability Management in Russia

SecurityInfrastructureRisk management

Read also