Kandji's Vulnerability Management feature scans fleets for known vulnerabilities (CVEs) based on data from the National Vulnerability Database (NVD). Built for macOS and Mac applications, it provides vulnerability coverage with app inventory data updates every 15 minutes. The Kandji Agent identifies software changes automatically through Apple's Endpoint Security framework. The feature utilizes the CVSS score to prioritize and measure vulnerability severity, and references the Known Exploited Vulnerabilities (KEV) catalog for prioritization. It provides patching capabilities that can be automated or manually triggered. Administrators can use the application and OS patch management tools to address vulnerabilities. The feature helps IT and security teams identify and remediate vulnerabilities through a unified workflow.