All docs

Patch management

Scan, approve, and deploy patches across your fleet.

Allocentra discovers, approves, and deploys patches across Windows, macOS, and Linux from one dashboard. Patch management is available on Growth plan and above.

Platform support

  • Windows — Windows Update (WUA), OEM vendor updates (Dell/HP/Lenovo), and winget-managed apps.
  • macOS — Apple softwareupdate OS patches and Homebrew formula/cask updates.
  • Linux — apt, dnf, or yum security and package updates (Ubuntu, Debian, RHEL, Alma, Rocky).

Patch policies

Set default approval behaviour in Patches → Policies. Choose auto-approve severities, optional third-party app updates, deployment rings for pilot rollouts, and pre/post scripts that run around install jobs.

Approve and deploy

  1. Review missing patches on the Patches page or per device.
  2. Select patches and click Approve.
  3. The agent schedules installation during the next maintenance window or immediately, depending on policy.

Compliance view

The Patches dashboard shows compliance percentage across clients and devices, with per-OS breakdowns in scheduled reports. Filter endpoint patches by platform or source (OS vs apps) to prioritise critical CVEs.

CVE findings & KEV

When agents report missing patches that map to CVE IDs, Allocentra enriches CVSS from NVD and flags CISA KEV. Use catalogue filters, CVE search, and Fast-track all KEV to close patchable CVEs on managed devices.

The CVE Findings tab matches installed software versions for curated high-impact apps (Chrome, Edge, Zoom, and similar) and offers Remediate via patch fast-track or package upgrade. This is not a full CPE scan of every installed product.

Security notices

High-impact vendor advisories (for example third-party RMM consoles) may appear as notices with playbooks and optional audit scripts. Allocentra notifies and helps hunt on endpoints it manages — it does not claim to patch products you run outside the Allocentra agent.