Vulnerability remediation, end to end
Find it.Fix it.Prove it.
Validated remediation guides for Windows Server CVEs and every entry in the CISA known-exploited catalogue — free and open. Ironsmith Ops turns them into tracked, evidenced work your auditors accept.
Every script tested on Windows Server 2019 / 2022 / 2025 · rollback included
Live libraryupdated daily
HIGH 8.1CVE-2026-42897Reboot Required
Microsoft Exchange Server Cross-Site Scripting Vulnerability (CVE-2026-42897)
CRITICAL 10.0CVE-2026-20182Reboot Required
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability (CVE-2026-20182)
CRITICAL 9.8CVE-2026-41089Reboot Required
Windows Netlogon Stack-Based Buffer Overflow
CRITICAL 9.8CVE-2026-41089Reboot Required
Windows Netlogon Stack-Based Buffer Overflow
View full library →1,987
Remediation guides
Windows Server 2012 R2 → 2025, plus KEV-listed vendor advisories
6
Tested scripts
PowerShell, tested before publication, rollback included
1,597
KEV entries covered
Tracked against the live CISA known-exploited catalogue
100%
Free to read
No account, no paywall on manual steps
Ironsmith Ops
The scan tells you what’s broken. Ops tells you who’s fixing it.
Findings route to exactly one accountable team, carry an action plan with a committed date, and close only when the next scan confirms it. Change records, SLA clocks, and risk acceptances stay attached to the finding — so the evidence pack writes itself.
- One accountable team per finding — OS work to platform patching, engines to DBA, the rest to the app team that owns the host.
- SLA clocks by priority, with breaches surfaced before the audit finds them.
- Change records, maintenance windows and risk acceptances attached to the finding, not to a spreadsheet.
- Closure requires scan confirmation — a remediation that reappears reopens itself.
Illustrative view of the demonstration estate — the figures shown are synthetic, like the estate itself.