Patch management
Scan, approve, and deploy patches across your fleet.
Allocentra discovers, approves, and deploys patches across Windows, macOS, and Linux from one dashboard. Patch management is available on Growth plan and above.
Platform support
- Windows — Windows Update (WUA), OEM vendor updates (Dell/HP/Lenovo), and winget-managed apps.
- macOS — Apple
softwareupdateOS patches and Homebrew formula/cask updates. - Linux — apt, dnf, or yum security and package updates (Ubuntu, Debian, RHEL, Alma, Rocky).
Patch policies
Set default approval behaviour in Patches → Policies. Choose auto-approve severities, optional third-party app updates, deployment rings for pilot rollouts, and pre/post scripts that run around install jobs.
Approve and deploy
- Review missing patches on the Patches page or per device.
- Select patches and click Approve.
- The agent schedules installation during the next maintenance window or immediately, depending on policy.
Compliance view
The Patches dashboard shows compliance percentage across clients and devices, with per-OS breakdowns in scheduled reports. Filter endpoint patches by platform or source (OS vs apps) to prioritise critical CVEs.
CVE findings & KEV
When agents report missing patches that map to CVE IDs, Allocentra enriches CVSS from NVD and flags CISA KEV. Use catalogue filters, CVE search, and Fast-track all KEV to close patchable CVEs on managed devices.
The CVE Findings tab matches installed software versions for curated high-impact apps (Chrome, Edge, Zoom, and similar) and offers Remediate via patch fast-track or package upgrade. This is not a full CPE scan of every installed product.
Security notices
High-impact vendor advisories (for example third-party RMM consoles) may appear as notices with playbooks and optional audit scripts. Allocentra notifies and helps hunt on endpoints it manages — it does not claim to patch products you run outside the Allocentra agent.