Prove Linux fixes are live.
Not just installed.
oxharden verifies vulnerability remediation from live host evidence: vulnerable packages, running kernels, mapped libraries, exposed services, and CIS/DISA STIG controls across RHEL-family Linux fleets.
Which fixes are actually running?
oxharden collects live host state once, then connects vulnerability findings, installed packages, running kernels, mapped libraries, exposed services, and compliance evidence into one answer security teams can act on.
Package risk
347 hosts · 2,184 packages assessed · 189 CVEs matched · 2m 11s
| Package | Fix | Hosts | KEV | Risk retired |
|---|---|---|---|---|
| xz-libs | 5.2.5-7 → 5.2.5-8 | 42 | KEV | 86 CVEs |
| openssl | 3.0.7-27 → 3.0.7-31 | 18 | 7.8 EPSS | 24 CVEs |
| kernel | 5.14.0-427 → 5.14.0-503 | 31 | reboot | 19 CVEs |
| glibc | 2.34-83 → 2.34-100 | 78 | KEV | 41 CVEs |
| polkit | 0.117-13 → 0.117-15 | 96 | KEV | 12 CVEs |
| curl | 7.76.1-29 → 7.76.1-31 | 24 | 8.2 EPSS | 9 CVEs |
Patch windows do not end at install.
oxharden shows what is still live.
“Patched” by version. Still running the vulnerable code.
A kernel CVE is not closed until the host reboots. A library fix is not live until every service that mapped it restarts. oxharden tracks applied-vs-live state, so your dashboard reflects what is actually running, not just what the package manager reports.
oxharden tracks applied-vs-live state, so patched-but-still-running risk stays visible until the fix actually takes effect.
CVSS is not a work queue.
A list of 189 CVEs is noise if the exploited ones are buried halfway down. oxharden brings KEV and EPSS to the top, then uses CVSS for impact context, so teams fix the vulnerabilities attackers are most likely to use first.
One remediation can close many findings.
oxharden groups findings by the work required: package upgrade, service restart, reboot, or configuration change. Copy the Bash or Ansible guidance where available, then re-scan to verify the risk is gone.
From finding to closure, with evidence.
Inventory, vulnerability risk, live patch state, compliance, and exposure all come from the same host record, so teams can move from finding to affected system to closure without guessing what changed.
See what your Linux fleet is really running.
Review a sample Patch Truth report, then start a 14-day trial to verify live fixes, restart debt, exposure, and compliance evidence on up to 30 of your own hosts.
curl -fsSL https://packages.executepath.dev/install.sh \ | sudo EXPECTED_GPG_FINGERPRINT=13094D5AB037E6CD79CDFA3A51687EAC6B931A09 bash
✓ live state synced · kernel · packages · ports
✓ first scan complete · 3 restart debts · 1 reboot pending
Questions, answered.
Deploy the lightweight agent with curl, dnf, or automation tooling like Ansible. It checks in periodically, captures package, process, port, and kernel posture, detects restart or reboot debt, and evaluates compliance locally on each host. The agent is strictly read-only, so it reports findings without making changes.