Category filter
Patch and Update reports in Hexnode UEM
Hexnode UEM’s ‘Scan for updates‘ action allows IT administrators to scan Windows devices for available patches and updates. With the addition of Patch and Update Reports, IT administrators can now access comprehensive information about the updates that are available for their devices, or identify which devices are missing these updates.
Creating Patch and Update reports
Patch and Update reports are categorized as follows:
- Available updates
- Devices missing updates
- Devices pending reboot
- Fully patched devices
- Critical updates
- Major updates
- Minor updates
- Updates awaiting approval
- Applicable updates
- Patch compliance
- Applicable vulnerabilities
- Vulnerable devices
- Patch automation
To generate any Patch and Update report:
- Log in to your Hexnode UEM portal.
- Navigate to Reports > Built-in Reports > Patch and Update.
- Select the update report you want to generate.
Available updates
The list of updates available for Windows devices that are enrolled in Hexnode UEM.
The report contains the following details:
- Update Name: Name of the update.
- Description: Provides a summary of the patch or update, including its purpose, the issues it resolves, and any improvements it brings.
- Product: The OS or app for which the update is available.
- Missing Devices: Displays the number of devices where the update is not yet installed.
- Installed Devices: The number of devices where the update is in an Installed status. You can view the details of the devices, such as Device Name, User, OS, Version, and Serial Number, by clicking on the number corresponding to the respective update under the Installed Devices column.
- Platform: The device platform to which the update is applicable.
- Severity: The criticality of the update, categorized into levels such as Critical, Important, Moderate, or Low.
- Release date: Displays the date when the patch or update was officially released by the vendor.
- KB Number: The Knowledge Base (KB) reference number associated with the update. These KB numbers are unique identifiers provided by vendors like Microsoft to document specific updates and fixes.
- Update Classification: Indicates the type of update based on the platform. For Windows (Microsoft), classifications include Critical Updates, Definition Updates, Feature Packs, Security Updates, Service Packs, Tools, Update Rollups, Updates, and Upgrades. For macOS (Apple), classifications include Rapid Security Responses, Major Updates, Minor Updates, Firmware Updates, and Config Data Updates.
- Identifier: Provides a unique identifier for the update, which can be used for tracking or reference purposes.
- Type: Indicates whether the update is for the OS or an application.
- Vendor: Specifies the vendor that released the update, such as Microsoft, Apple, or a third-party application developer.
- Max download size: Shows the maximum size of the update or patch, helping admins prepare for network bandwidth considerations.
- More information: Provides a URL linking to a webpage with additional details or documentation related to the patch or update if there are any.
- Support URL: Links to the vendor’s support page for troubleshooting, FAQs, or assistance regarding the update.
- Approval Status: Indicates whether the update has been approved for installation through Hexnode UEM. (Pending or Approved).
- Max Install Size: Displays the maximum size of the update after the installation processes (such as unzipping) are completed.
- Beta Update: Indicates whether the update is a beta version. The value can be either True or False.
- Last Update Date: Indicates the most recent date when the update was added, detected, or released.
- Reboot: Specifies whether the update requires a system reboot to complete the installation.
- Uninstallation: Indicates whether the update can be uninstalled from the device after installation.
- Impact: Displays the potential impact level of the update, categorized as Critical, High, Moderate, or Low.
- Requires Network Connectivity: Indicates whether an active network connection is required to download, install, or uninstall the update.
- Requires User Input: Specifies if the update installation requires user interaction, such as providing consent or other inputs, to complete the process.
- CVSS v3.1: Displays the Common Vulnerability Scoring System (CVSS) v3.1 score assigned to the update, as provided by recognized vulnerability databases.
- Applicable Devices: The number of devices where the update status is anything other than ‘Installed’. This includes devices with statuses such as ‘Installable’, ‘Failed’, ‘Approved’, or ‘Pending Reboot’. You can view the details of the devices, such as Device Name, User, OS, Version, Serial Number, and Update status, by clicking on the number corresponding to the respective update under the Applicable Devices column.
Devices missing updates
The list of all Windows devices along with the number of available updates that have not yet been installed on each device.
The report contains the following details:
- Device Name: Name of the device.
- Username: Name of the user.
- Platform: The platform of the device.
- Last Successful Scan: The date and time when the device were last successfully scanned for updates.
- Missing Updates: The number of available updates that are not installed on the device. You can view the details of the missing update, such as Name, Product, and Details, by clicking on the number corresponding to the respective device under the Missing Updates column.
Critical updates
The list of all patches with severity “Critical”.
The report contains the following details:
- Update Name: The name of the update or patch, such as the version and identifier of the update.
- Description: Provides a summary of the patch or update, including its purpose, the issues it resolves, and any improvements it brings.
- Product: The software, application, or OS component that the patch or update applies to.
- Missing Devices: Displays the number of devices where the update is not yet installed.
- Installed Devices: The devices where the patch or update has already been successfully installed.
- Platform: The device platform to which the update is applicable.
- Release date: Displays the date when the patch or update was officially released by the vendor.
- KB Number: The Knowledge Base (KB) reference number associated with the update. These KB numbers are unique identifiers provided by vendors like Microsoft to document specific updates and fixes.
- Update Classification: The type of update based on the platform. For Windows (Microsoft), classifications include Critical Updates, Definition Updates, Feature Packs, Security Updates, Service Packs, Tools, Update Rollups, Updates, and Upgrades. For macOS (Apple), classifications include Rapid Security Responses, Major Updates, Minor Updates, Firmware Updates, and Config Data Updates.
- Identifier: Provides a unique identifier for the update, which can be used for tracking or reference purposes.
- Type: Indicates whether the update is for the OS or an application.
- Vendor: Specifies the vendor that released the update, such as Microsoft, Apple, or a third-party application developer.
- Max Download Size: Shows the maximum size of the update or patch, helping admins prepare for network bandwidth considerations.
- More Information: Provides a URL linking to a webpage with additional details or documentation related to the patch or update if there are any.
- Support URL: Links to the vendor’s support page for troubleshooting, FAQs, or assistance regarding the update.
- Approval Status: Indicates whether the update has been approved for installation through Hexnode UEM. (Pending or Approved).
- Max Install Size: Displays the maximum size of the update after the installation processes (such as unzipping) are completed.
- Beta Update: Indicates whether the update is a beta version. The value can be either True or False.
- Last Update Date: Indicates the most recent date when the update was added, detected, or released.
- Reboot: Specifies whether the update requires a system reboot to complete the installation.
- Uninstallation: Indicates whether the update can be uninstalled from the device after installation.
- Impact: Displays the potential impact level of the update, categorized as Critical, High, Moderate, or Low.
- Requires Network Connectivity: Indicates whether an active network connection is required to download, install, or uninstall the update.
- Requires User Input: Specifies if the update installation requires user interaction, such as providing consent or other inputs, to complete the process.
- CVSS v3.1: Displays the Common Vulnerability Scoring System (CVSS) v3.1 score assigned to the update, as provided by recognized vulnerability databases.
- Applicable Devices: List all the devices that need to have a particular patch or update installed.
Major updates
The list of all patches with severity “Important”.
The report contains the following details:
- Update Name: The name of the update or patch, such as the version and identifier of the update.
- Description: Provides a summary of the patch or update, including its purpose, the issues it resolves, and any improvements it brings.
- Product: The software, application, or OS component that the patch or update applies to.
- Missing Devices: Displays the number of devices where the update is not yet installed.
- Installed Devices: The devices where the patch or update has already been successfully installed.
- Platform: The device platform to which the update is applicable.
- Release date: Displays the date when the patch or update was officially released by the vendor.
- KB Number: The Knowledge Base (KB) reference number associated with the update. These KB numbers are unique identifiers provided by vendors like Microsoft to document specific updates and fixes.
- Update Classification: The type of update based on the platform. For Windows (Microsoft), classifications include Critical Updates, Definition Updates, Feature Packs, Security Updates, Service Packs, Tools, Update Rollups, Updates, and Upgrades. For macOS (Apple), classifications include Rapid Security Responses, Major Updates, Minor Updates, Firmware Updates, and Config Data Updates.
- Identifier: Provides a unique identifier for the update, which can be used for tracking or reference purposes.
- Type: Indicates whether the update is for the OS or an application.
- Vendor: Specifies the vendor that released the update, such as Microsoft, Apple, or a third-party application developer.
- Max download size: Shows the maximum size of the update or patch, helping admins prepare for network bandwidth considerations.
- More information: Provides a URL linking to a webpage with additional details or documentation related to the patch or update if there are any.
- Support URL: Links to the vendor’s support page for troubleshooting, FAQs, or assistance regarding the update.
- Approval Status: Indicates whether the update has been approved for installation through Hexnode UEM. (Pending or Approved).
- Max Install Size: Displays the maximum size of the update after installation processes such as unzipping are completed.
- Beta Update: Indicates whether the update is a beta version. The value can be either True or False.
- Last Update Date: Indicates the most recent date when the update was added, detected, or released.
- Reboot: Specifies whether the update requires a system reboot to complete the installation.
- Uninstallation: Indicates whether the update can be uninstalled from the device after installation.
- Impact: Displays the potential impact level of the update, categorized as Critical, High, Moderate, or Low.
- Requires Network Connectivity: Indicates whether an active network connection is required to download, install, or uninstall the update.
- Requires User Input: Specifies if the update installation requires user interaction, such as providing consent or other inputs, to complete the process.
- CVSS v3.1: Displays the Common Vulnerability Scoring System (CVSS) v3.1 score assigned to the update, as provided by recognized vulnerability databases.
- Applicable Devices: List all the devices that need to have a particular patch or update installed.
Minor updates
The list of all patches with severity “Moderate”.
The report contains the following details:
- Update Name: The name of the update or patch, such as the version and identifier of the update.
- Description: Provides a summary of the patch or update, including its purpose, the issues it resolves, and any improvements it brings.
- Product: The software, application, or OS component that the patch or update applies to.
- Missing Devices: Displays the number of devices where the update is not yet installed.
- Installed Devices: The devices where the patch or update has already been successfully installed.
- Platform: The device platform to which the update is applicable.
- Release date: Displays the date when the patch or update was officially released by the vendor.
- KB Number: Displays the Knowledge Base (KB) reference number associated with the update. These KB numbers are unique identifiers provided by vendors like Microsoft to document specific updates and fixes.
- Update Classification: The type of update based on the platform. For Windows (Microsoft), classifications include Critical Updates, Definition Updates, Feature Packs, Security Updates, Service Packs, Tools, Update Rollups, Updates, and Upgrades. For macOS (Apple), classifications include Rapid Security Responses, Major Updates, Minor Updates, Firmware Updates, and Config Data Updates.
- Identifier: Provides a unique identifier for the update, which can be used for tracking or reference purposes.
- Type: Indicates whether the update is for the OS or an application.
- Vendor: Specifies the vendor that released the update, such as Microsoft, Apple, or a third-party application developer.
- Max download size: Shows the maximum size of the update or patch, helping admins prepare for network bandwidth considerations.
- More information: Provides a URL linking to a webpage with additional details or documentation related to the patch or update if there are any.
- Support URL: Links to the vendor’s support page for troubleshooting, FAQs, or assistance regarding the update.
- Approval Status: Indicates whether the update has been approved for installation through Hexnode UEM. (Pending or Approved).
- Max Install Size: Displays the maximum size of the update after the installation processes (such as unzipping) are completed.
- Beta Update: Indicates whether the update is a beta version. The value can be either True or False.
- Last Update Date: Indicates the most recent date when the update was added, detected, or released.
- Reboot: Specifies whether the update requires a system reboot to complete the installation.
- Uninstallation: Indicates whether the update can be uninstalled from the device after installation.
- Impact: Displays the potential impact level of the update, categorized as Critical, High, Moderate, or Low.
- Requires Network Connectivity: Indicates whether an active network connection is required to download, install, or uninstall the update.
- Requires User Input: Specifies if the update installation requires user interaction, such as providing consent or other inputs, to complete the process.
- CVSS v3.1: Displays the Common Vulnerability Scoring System (CVSS) v3.1 score assigned to the update, as provided by recognized vulnerability databases.
- Applicable Devices: List all the devices that need to have a particular patch or update installed.
Updates awaiting approval
The list of all patches that are not yet approved by the admin.
The report contains the following details:
- Update Name: The name of the update or patch, such as the version and identifier of the update.
- Description: Provides a summary of the patch or update, including its purpose, the issues it resolves, and any improvements it brings.
- Product: The software, application, or OS component that the patch or update applies to.
- Missing Devices: Displays the number of devices where the update is not yet installed.
- Installed Devices: The devices where the patch or update has already been successfully installed.
- Platform: The device platform to which the update is applicable.
- Severity: The criticality of the update, categorized into levels such as Critical, Important, Moderate, or Low.
- Release date: Displays the date when the patch or update was officially released by the vendor.
- KB Number: Displays the Knowledge Base (KB) reference number associated with the update. These KB numbers are unique identifiers provided by vendors like Microsoft to document specific updates and fixes.
- Update Classification: The type of update based on the platform. For Windows (Microsoft), classifications include Critical Updates, Definition Updates, Feature Packs, Security Updates, Service Packs, Tools, Update Rollups, Updates, and Upgrades. For macOS (Apple), classifications include Rapid Security Responses, Major Updates, Minor Updates, Firmware Updates, and Config Data Updates.
- Identifier: Provides a unique identifier for the update, which can be used for tracking or reference purposes.
- Type: Indicates whether the update is for the OS or an application.
- Vendor: Specifies the vendor that released the update, such as Microsoft, Apple, or a third-party application developer.
- Max download size: Shows the maximum size of the update or patch, helping admins prepare for network bandwidth considerations.
- More information: Provides a URL linking to a webpage with additional details or documentation related to the patch or update if there are any.
- Support URL: Links to the vendor’s support page for troubleshooting, FAQs, or assistance regarding the update.
- Max Install Size: Displays the maximum size of the update after installation processes such as unzipping are completed.
- Beta Update: Indicates whether the update is a beta version. The value can be either True or False.
- Last Update Date: Indicates the most recent date when the update was added, detected, or released.
- Reboot: Specifies whether the update requires a system reboot to complete the installation.
- Uninstallation: Indicates whether the update can be uninstalled from the device after installation.
- Impact: Displays the potential impact level of the update, categorized as Critical, High, Moderate, or Low.
- Requires Network Connectivity: Indicates whether an active network connection is required to download, install, or uninstall the update.
- Requires User Input: Specifies if the update installation requires user interaction, such as providing consent or other inputs, to complete the process.
- CVSS v3.1: Displays the Common Vulnerability Scoring System (CVSS) v3.1 score assigned to the update, as provided by recognized vulnerability databases.
- Applicable Devices: List all the devices that need to have a particular patch or update installed.
Devices pending reboot
The list of all devices with at least one update in the status “Pending Reboot”.
The report contains the following details:
- Device Name: Name of the device.
- Username: Name of the user.
- Platform: The device platform to which the update is applicable.
- Last Successful Scan: The date and time when the device were last successfully scanned for updates.
- Updates Pending Reboot: The devices that are awaiting a reboot for the update to be fully applied.
Fully patched devices
The list of devices with all applicable updates installed.
The report contains the following details:
- Device Name: Name of the device.
- Platform: The device platform to which the update is applicable.
- OS Version: The operating system version.
- Device ID: The unique identifier assigned to the device upon its enrollment in Hexnode UEM.
- Username: Name of the user.
- Last Successful Scan: The date and time when the device were last successfully scanned for updates.
Applicable updates
The list of all patches applicable to the enrolled devices.
The report contains the following details:
- Name: The name of the update or patch, such as the version and identifier of the update.
- Description: Provides a summary of the patch or update, including its purpose, the issues it resolves, and any improvements it brings.
- Product: The software, application, or OS component that the patch or update applies to.
- Missing Devices: Displays the number of devices where the update is not yet installed.
- Installed Devices: The devices where the patch or update has already been successfully installed.
- Platform: The device platform to which the update is applicable.
- Severity: The criticality of the update, categorized into levels such as Critical, Important, Moderate, or Low.
- Release date: Displays the date when the patch or update was officially released by the vendor.
- KB Number: Displays the Knowledge Base (KB) reference number associated with the update. These KB numbers are unique identifiers provided by vendors like Microsoft to document specific updates and fixes.
- Update Classification: The type of update based on the platform. For Windows (Microsoft), classifications include Critical Updates, Definition Updates, Feature Packs, Security Updates, Service Packs, Tools, Update Rollups, Updates, and Upgrades. For macOS (Apple), classifications include Rapid Security Responses, Major Updates, Minor Updates, Firmware Updates, and Config Data Updates.
- Identifier: Provides a unique identifier for the update, which can be used for tracking or reference purposes.
- Type: Indicates whether the update is for the OS or an application.
- Vendor: Specifies the vendor that released the update, such as Microsoft, Apple, or a third-party application developer.
- Max download size: Shows the maximum size of the update or patch, helping admins prepare for network bandwidth considerations.
- More information: Provides a URL linking to a webpage with additional details or documentation related to the patch or update if there are any.
- Support URL: Links to the vendor’s support page for troubleshooting, FAQs, or assistance regarding the update.
- Approval Status: Indicates whether the update has been approved for installation through Hexnode UEM. (Pending or Approved).
- Max Install Size: Displays the maximum size of the update after installation processes such as unzipping are completed.
- Beta Update: Indicates whether the update is a beta version. The value can be either True or False.
- Last Update Date: Indicates the most recent date when the update was added, detected, or released.
- Reboot: Specifies whether the update requires a system reboot to complete the installation.
- Uninstallation: Indicates whether the update can be uninstalled from the device after installation.
- Requires Network Connectivity: Indicates whether an active network connection is required to download, install, or uninstall the update.
- Requires User Input: Specifies if the update installation requires user interaction, such as providing consent or other inputs, to complete the process.
- CVSS v3.1: Displays the Common Vulnerability Scoring System (CVSS) v3.1 score assigned to the update, as provided by recognized vulnerability databases.
- Applicable Devices: List all the devices that need to have a particular patch or update installed.
Patch Compliance
The list of all applicable patches and the percentage of devices on which the patch is installed.
The report contains the following details:
- Name: The name of the update or patch, such as the version and identifier of the update.
- Description: Provides a summary of the patch or update, including its purpose, the issues it resolves, and any improvements it brings.
- Product: The software, application, or OS component that the patch or update applies to.
- Missing Devices: Displays the number of devices where the update is not yet installed.
- Installed Devices: The devices where the patch or update has already been successfully installed.
- Platform: The device platform to which the update is applicable.
- Severity: The criticality of the update, categorized into levels such as Critical, Important, Moderate, or Low.
- Release date: Displays the date when the patch or update was officially released by the vendor.
- KB Number: Displays the Knowledge Base (KB) reference number associated with the update. These KB numbers are unique identifiers provided by vendors like Microsoft to document specific updates and fixes.
- Update Classification: The type of update based on the platform. For Windows (Microsoft), classifications include Critical Updates, Definition Updates, Feature Packs, Security Updates, Service Packs, Tools, Update Rollups, Updates, and Upgrades. For macOS (Apple), classifications include Rapid Security Responses, Major Updates, Minor Updates, Firmware Updates, and Config Data Updates.
- Identifier: Provides a unique identifier for the update, which can be used for tracking or reference purposes.
- Type: Indicates whether the update is for the OS or an application.
- Vendor: Specifies the vendor that released the update, such as Microsoft, Apple, or a third-party application developer.
- Max download size: Shows the maximum size of the update or patch, helping admins prepare for network bandwidth considerations.
- More information: Provides a URL linking to a webpage with additional details or documentation related to the patch or update if there are any.
- Support URL: Links to the vendor’s support page for troubleshooting, FAQs, or assistance regarding the update.
- Approval Status: Indicates whether the update has been approved for installation through Hexnode UEM. (Pending or Approved).
- Max Install Size: Displays the maximum size of the update after installation processes such as unzipping are completed.
- Beta Update: Indicates whether the update is a beta version. The value can be either True or False.
- Last Update Date: Indicates the most recent date when the update was added, detected, or released.
- Reboot: Specifies whether the update requires a system reboot to complete the installation.
- Uninstallation: Indicates whether the update can be uninstalled from the device after installation.
- Requires Network Connectivity: Indicates whether an active network connection is required to download, install, or uninstall the update.
- Requires User Input: Specifies if the update installation requires user interaction, such as providing consent or other inputs, to complete the process.
- CVSS v3.1: Displays the Common Vulnerability Scoring System (CVSS) v3.1 score assigned to the update, as provided by recognized vulnerability databases.
- Applicable Devices: List all the devices that need to have a particular patch or update installed.
- Patch Compliance: Displays the percentage of devices in which a particular patch or update has been successfully installed, helping assess the overall compliance status across the organization.
Applicable Vulnerabilities
The list of all vulnerabilities applicable to the enrolled devices.
The report contains the following details:
- Name: The name of the vulnerability, often corresponding to the related update or patch.
- Description: Provides a summary of the vulnerability, including its purpose, the issues it resolves, and any improvements it brings.
- CVE ID: The unique identifier assigned to the vulnerability by the Common Vulnerabilities and Exposures (CVE) system.
- CVSSv3.1 Base Score: The base score of the vulnerability as per the CVSS version 3.1 standards, representing its severity.
- CVSS Vector String: The CVSS v3.1 vector string describes the specific metrics used to calculate the base score of the vulnerability.
- CVSS Rating: The qualitative severity rating of the vulnerability, such as Critical, High, Medium, or Low, based on the CVSS score.
- CVE.org link: Provides a direct link to the CVE.org page for more details and references about the specific vulnerability.
- Affected Devices: List all the devices that are affected by the corresponding vulnerability.
Vulnerable Devices
The list of all devices that are vulnerable along with the list of vulnerabilities.
The report contains the following details:
- Device Name: The name of the device where the detected vulnerabilities are present.
- Platform: The device platform on which the vulnerabilities have been identified.
- Device ID: The unique identifier assigned to each device upon enrollment in Hexnode UEM.
- Username: The name of the user associated with the device.
- Last successful Scan: The date and time when the device was last successfully scanned for vulnerabilities.
- Vulnerabilities: Lists the number of vulnerabilities detected on the respective device.
Patch Automation
The list of all automation created for patches.
The report contains the following details:
- Name: The name of the patch automation policy created.
- Description: Provides a summary of the patch automation policy, outlining its purpose or configuration details.
- Created Time: The date and time when the patch automation policy was created.
- Version: Indicates the version of the patch automation configuration or policy.
- Platform: Specifies the platform (such as Windows or macOS) on which the automation is applied.
- Mode: Displays the operational mode of the automation, such as Automatic or Manual.
- Status: The current operational state of the patch automation, specifying whether the process is completed or still in progress.
- Last Status Update: The most recent date and time when the status of the patch automation policy was updated.
On the Device missing updates, Device pending reboot and Fully patched devices report pages, you can click on the listed device and initiate the Scan for Updates right from the report page.
You also have the option to schedule reports at desired time intervals and have them automatically emailed to specified recipients. Additionally, you can Export the report to your device in either PDF or CSV format.







