The flaw has been public for six hours. Does your Fortigate know yet?
patchletter brings together CISA KEV, Germany's BSI/CERT-Bund and NVD — and tells you which of your tools are affected. Not every vulnerability in the world. Yours.
1271 products9 live sourcesno account, no tracking
Just detected
Three ways not to find out
You find out too late.
The flaw has been in the KEV catalogue for hours. The BSI publishes on the next business day. You read about it on Friday night.
Or you find out far too often.
A broadcast list does not know your stack.
Or not at all.
There is no mailing list for line-of-business software, NAS firmware or the camera in the warehouse. For 1271 products there is us.
The sources feed in. What goes out is one email about your tools.
Vulnerabilities do not surface in one place. They sit in the NVD, in CISA's KEV catalogue, in CERT-Bund's advisories, in the vendors' own bulletins — and they are discussed and traded in underground forums and on illegal marketplaces, often before a CVE number has been assigned. patchletter pulls these sources together and only gets in touch when one of them concerns your systems.
1
Where the data comes from
Public sources provide the groundwork: NVD and MITRE for the base records, the KEV catalogue for flaws demonstrably being exploited, CERT-Bund for the German perspective, the vendors for their own advisories. On top of that come underground forums and illegal marketplaces, which hardly any provider evaluates.
2
What becomes of it
The same flaw is often reported by several bodies, in different words and in a different order. patchletter merges those reports: one vulnerability, one alert.
3
What reaches you
You record once which products you run. After that you only get advisories about exactly those products.
The difference is in the grey rows
Anyone can pull the feeds. We map every advisory onto the products in the catalogue by hand, and “does not affect you” is the statement admins pay for.
What Pro changes
Before the vendor stops shipping fixes
End of support is not a flaw. It is the day from which the next one goes unpatched — and it is known long in advance. With Pro, patchletter emails you 90, 30 and 7 days before support ends, bundled into a single message however many of your products fall in the same week. The dates themselves are yours to look up here at any time, without an account.
Free and Pro
| Free0 € | Prorecommended€49net/monthor €490 a year — two months free | |
|---|---|---|
| Update emails for 1271 products | ||
| View CVE, KEV and BSI on the website | ||
| View end-of-life dates on the website | ||
| Security flag on the release | ||
| Email alert when it hits you | ||
| End-of-life warning by email, 90/30/7 days ahead | ||
| Immediately, not at the next daily run | ||
| BSI/CERT-Bund by email | ||
| Only advisories for your version | ||
| Invite colleagues | up to 5 | |
| Slack, Teams, webhook | ||
| Weekly report as PDF |
Update emails are free — no limit, no credit card. Vulnerabilities and end-of-support dates are yours to read here, without an account. Pro pays for the alert to find you, rather than you having to look.
cancel monthly · card, SEPA direct debit or invoice
Two ways in
Get Pro
Pick your tools, enter your address. It runs from there. There is no trial period; the monthly subscription has no minimum term and the annual one runs for twelve months first.
Get ProOr start small
Pick your tools and get the free update emails. You can switch any time.
To the catalogueDouble opt-in · no tracking · servers in the EU · one click to unsubscribe
Frequently asked questions
- Is this the same as the BSI newsletter?
- A broadcast list does not know your stack — you get everything or nothing. We only send what concerns the products you track, and we add sources the BSI does not cover.
- Do you scan my systems?
- We never see your systems. The match runs against the product names you entered.
- What is included in the free plan?
- The update email: a new version is out — for as many products as you like. Security labelling on the release, end-of-support warnings, CVE, KEV and BSI/CERT-Bund alerts are part of Pro. Reading costs nothing: all of those records sit on the website without an account, and what you pay for is being woken up.
- Why €49?
- The sources have to run around the clock, we maintain the mapping onto our catalogue by hand, and the server in Paris sits with a European host. Ads, data sales and investors would be the alternative. We take the subscription.
- Can I cancel?
- Monthly, to the end of the month, two clicks inside your account. With an annual subscription the first year runs, after that it continues indefinitely and can be cancelled monthly — with a reminder 30 days ahead. No questions, no retention offers.
- Which sources exactly?
- All of them listed individually, including the last successful fetch, on the sources page.