July 28th, 2026

New

See Which Firmware Versions in Your Fleet Are Vulnerable

You can now upload an SBOM to any firmware version, and Spotflow automatically matches its components against known CVEs and tracks which of your deployed devices are affected.

Cross-referencing dependency lists against CVE feeds by hand doesn't scale. Spotflow does the matching for you, re-scans as the CVE database changes, and gives your team a structured way to assess and document each finding.

What you can do

  • Upload SBOMs per firmware version: SPDX 2 (tag-value) or SPDX 3 (JSON). Spotflow extracts the components and dependencies automatically.

  • Get matched against known CVEs, continuously: Checked on upload, then re-scanned as the CVE database updates, so newly disclosed vulnerabilities surface in firmware you already shipped.

  • Assess issues with VEX-style states: New findings start Not Assessed. Move each to In Triage, Affected, or Not Affected as your team investigates. Not Affected requires a justification.

  • See fleet-wide impact at a glance: The Security overview lists every firmware version with open issues, how many devices are affected, and lets you filter by severity or CISA KEV status.

  • Keep a full audit trail: Every assessment and ignore action is logged with who made it, when, and why.

Spotflow supports your CRA compliance work, but your organization is still responsible for determining which requirements apply and meeting them.

Read the full guide: Track security issues across your devices and Comply with CRA.

Check our Roadmap. Join our community on Discord.