The flaw has been public for six hours. Does your Fortigate know yet?

patchletter brings together CISA KEV, Germany's BSI/CERT-Bund and NVD — and tells you which of your tools are affected. Not every vulnerability in the world. Yours.

1271 products9 live sourcesno account, no tracking

Just detected

See every actively exploited flaw

Three ways not to find out

You find out too late.

The flaw has been in the KEV catalogue for hours. The BSI publishes on the next business day. You read about it on Friday night.

Or you find out far too often.

A broadcast list does not know your stack.

Or not at all.

There is no mailing list for line-of-business software, NAS firmware or the camera in the warehouse. For 1271 products there is us.

The sources feed in. What goes out is one email about your tools.

Vulnerabilities do not surface in one place. They sit in the NVD, in CISA's KEV catalogue, in CERT-Bund's advisories, in the vendors' own bulletins — and they are discussed and traded in underground forums and on illegal marketplaces, often before a CVE number has been assigned. patchletter pulls these sources together and only gets in touch when one of them concerns your systems.

Six sources, one alert: how a patchletter notification comes aboutNVD/MITRE, CISA KEV, BSI CERT-Bund, vendor advisories, underground forums and illegal marketplaces all feed into patchletter.com AI. There, duplicate reports are bundled into one alert per vulnerability, matched against the tool stack you registered, and only delivered by email if they affect you.NVD / MITRECISA KEVBSI CERT-BundVendor advisoriesUnderground forumsIllegal marketplacesover 100 new vulnerabilities a daypatchletter.com AIBundle and deduplicateone alert per vulnerabilityMatched against your stackSophos, Proxmox, Microsoft 365Email, today 07:12Sophos Firewall: critical
Schematic, with example data. Which source last delivered, and when, is on the sources page with a timestamp.

1

Where the data comes from

Public sources provide the groundwork: NVD and MITRE for the base records, the KEV catalogue for flaws demonstrably being exploited, CERT-Bund for the German perspective, the vendors for their own advisories. On top of that come underground forums and illegal marketplaces, which hardly any provider evaluates.

2

What becomes of it

The same flaw is often reported by several bodies, in different words and in a different order. patchletter merges those reports: one vulnerability, one alert.

3

What reaches you

You record once which products you run. After that you only get advisories about exactly those products.

Every source with its last fetch

The difference is in the grey rows

Anyone can pull the feeds. We map every advisory onto the products in the catalogue by hand, and “does not affect you” is the statement admins pay for.

One advisory, mapped to actual productsA vulnerability record on the left is fed through a catalogue-matching module in the middle. On the right six products: four marked as affected, two greyed out as not affected. Only the four affected ones trigger an email.CVE-2026-735708.9 · actively exploitedSource: CISA KEVCatalogue match1271 productsZimbra Collaboration10.1.4affectedExchange Server15.2.2562affectedProxmox Mail Gateway8.2.1affectedPostfix3.9.1affectedNextcloud34.0.3not affectedSynology DSM7.4-90075not affectedonly these trigger an email
Example data. The value is in the grey rows: whoever gets everything gets nothing.

What Pro changes

Same flaw, two delivery pathsTwo parallel tracks on one time axis. Both start at the moment the flaw is detected. On the Pro track the alert is delivered immediately; on the free track the information only becomes visible on the website at the next daily run.ProFreeyou have to go and lookflaw detectedalert deliveredvisible on the websiteuntil the next daily run
The data is open to both. Pro finds out before the first customer calls.

Before the vendor stops shipping fixes

End of support is not a flaw. It is the day from which the next one goes unpatched — and it is known long in advance. With Pro, patchletter emails you 90, 30 and 7 days before support ends, bundled into a single message however many of your products fall in the same week. The dates themselves are yours to look up here at any time, without an account.

See every end-of-support date

Free and Pro

Free and Pro
Free0 €Prorecommended€49net/monthor €490 a year — two months free
Update emails for 1271 products
View CVE, KEV and BSI on the website
View end-of-life dates on the website
Security flag on the release
Email alert when it hits you
End-of-life warning by email, 90/30/7 days ahead
Immediately, not at the next daily run
BSI/CERT-Bund by email
Only advisories for your version
Invite colleaguesup to 5
Slack, Teams, webhook
Weekly report as PDF

Update emails are free — no limit, no credit card. Vulnerabilities and end-of-support dates are yours to read here, without an account. Pro pays for the alert to find you, rather than you having to look.

cancel monthly · card, SEPA direct debit or invoice

All details on the pricing page

Two ways in

Get Pro

Pick your tools, enter your address. It runs from there. There is no trial period; the monthly subscription has no minimum term and the annual one runs for twelve months first.

Get Pro

Or start small

Pick your tools and get the free update emails. You can switch any time.

To the catalogue

Double opt-in · no tracking · servers in the EU · one click to unsubscribe

Frequently asked questions

Is this the same as the BSI newsletter?
A broadcast list does not know your stack — you get everything or nothing. We only send what concerns the products you track, and we add sources the BSI does not cover.
Do you scan my systems?
We never see your systems. The match runs against the product names you entered.
What is included in the free plan?
The update email: a new version is out — for as many products as you like. Security labelling on the release, end-of-support warnings, CVE, KEV and BSI/CERT-Bund alerts are part of Pro. Reading costs nothing: all of those records sit on the website without an account, and what you pay for is being woken up.
Why €49?
The sources have to run around the clock, we maintain the mapping onto our catalogue by hand, and the server in Paris sits with a European host. Ads, data sales and investors would be the alternative. We take the subscription.
Can I cancel?
Monthly, to the end of the month, two clicks inside your account. With an annual subscription the first year runs, after that it continues indefinitely and can be cancelled monthly — with a reminder 30 days ahead. No questions, no retention offers.
Which sources exactly?
All of them listed individually, including the last successful fetch, on the sources page.

The next critical flaw is coming. The only question is whether you see it before or after your customers.

Pick your tools — free