Roundups

Top 7 Vulnerability Management Tools in 2026

Tenable, Qualys, Rapid7, Microsoft Defender, Wiz, Greenbone and Nucleus Security, ranked on detection breadth, documented risk scoring and real pricing. Rapid7 folded InsightVM into Exposure Command and Google closed its $32B Wiz deal in March 2026.

A vast archive of iron doors, a few glowing from behind, with a surveyor marking one

TL;DR

  • Best overall for enterprise breadth: Tenable — Nessus engine, VPR risk scoring, published list prices for the entry SKUs.
  • Best if you want one agent everywhere: Qualys — single Cloud Agent, TruRisk scoring, FedRAMP High.
  • Cheapest if you already pay Microsoft: Defender Vulnerability Management at $2.00/user/month as an add-on — but it is licensed per user, not per asset.
  • The category shifted in 2026. Rapid7 folded InsightVM into Exposure Command, Google closed its $32B Wiz acquisition on 11 March 2026, and Tenable absorbed Vulcan Cyber. Standalone "vulnerability scanner" is no longer how any of the big three sell.

Vulnerability management is the continuous process of finding, prioritizing and remediating security weaknesses across your assets. The leading tools in 2026 are Tenable, Qualys and Rapid7 for full enterprise coverage; Microsoft Defender Vulnerability Management for Microsoft-standardized estates; Wiz for cloud-native environments; Greenbone/OpenVAS for self-hosted open source; and Nucleus Security for consolidating findings you already have.

The hard part is no longer detection. Every tool here will find more vulnerabilities than you can fix. What separates them is how honestly they tell you which ones matter, and what they cost to run at your asset count.

How we picked these

Selection criteria, in order of weight:

  1. Detection breadth you can verify — published CVE/check counts, documented OS and device coverage, and a real scanner or ingest architecture rather than a dashboard over someone else's data.
  2. Prioritization methodology that is documented. A tool that outputs a proprietary risk score without publishing its inputs is harder to defend to an auditor. We checked each vendor's own docs for whether CVSS, EPSS, CISA KEV and exploit telemetry feed the score.
  3. Pricing you can actually find. Vendors that publish real numbers scored higher than vendors that publish a page titled "pricing" with a contact form behind it.
  4. Deployment fit — SaaS, self-hosted, air-gapped and open source are genuinely different procurement problems.
  5. Current status as of October 2026. Ownership, renames and packaging changes in 2025–2026 were verified against press releases and SEC filings, not assumed.

All pricing and feature claims below were observed on vendor sites on 1 October 2026. Rankings reflect breadth of job coverage, not a judgment that lower-ranked tools are worse at what they do.

Quick comparison

Company Best for Deployment Pricing model
Tenable Broadest enterprise coverage SaaS, self-hosted, on-prem, air-gapped Published list price for Nessus and entry VM; platform on request
Qualys Single-agent continuous assessment SaaS (multi-region), private cloud, FedRAMP High On request; tiered host pricing on AWS Marketplace
Rapid7 Internal VM plus attacker-view context SaaS plus on-prem console On request; tiered asset pricing on AWS Marketplace
Microsoft Defender VM Microsoft-managed endpoint estates SaaS only $2.00/user/month add-on
Wiz Cloud and multicloud workloads SaaS On request
Greenbone / OpenVAS Self-hosted and data-sovereign scanning Self-hosted OSS, appliance Free community edition; enterprise on request
Nucleus Security Consolidating many scanners SaaS On request

1. Tenable

Tenable sells vulnerability management as part of Tenable One, its exposure management platform, with the Nessus scanner underneath. The scanner engine dates to 1998 and remains the reference implementation for credentialed network scanning — Tenable states its library covers 336,000+ CVEs, and ships 450+ pre-built scan and compliance templates. Nessus is light enough to run on a Raspberry Pi.

Prioritization runs on VPR (Vulnerability Priority Rating), a 0.1–10.0 machine-learning score that Tenable documents as two components: technical impact derived from the CVSSv3 impact subscore, and a threat component built from recent and predicted exploit activity. Inputs include CISA KEV, NVD, public and private exploit databases and Tenable's own research. Nessus also surfaces raw CVSS and EPSS next to VPR, so you are not forced to trust the composite.

In 2026 Tenable added Hexa AI, an agentic layer inside Tenable One that went GA on 20 May 2026 and was extended in August to cover scan analysis, threat triage and automated patch verification.

Best for: Organizations that need one vendor to cover IT, cloud, web apps and OT, including air-gapped networks.

Pros

  • Published list prices for the entry products, rare in this category: Nessus Professional $4,790/year, Nessus Expert $6,790/year, and Tenable One Vulnerability Management $3,500/year for 100 assets (observed 1 October 2026).
  • VPR methodology, drivers and score bands are documented publicly, including an EPSS and CVSS comparison.
  • Deployment covers SaaS, self-installed scanner, on-prem Security Center and air-gapped Tenable Enclave Security.
  • Acquired Vulcan Cyber for roughly $150M, completed 7 February 2025, adding third-party findings aggregation to the platform.

Cons

  • Tenable One platform pricing is quote-only, on a page that advertises transparent pricing.
  • CNAPP, identity security and AI governance are paid add-ons on top of the Foundation and Advanced tiers, per Tenable's own pricing page — the headline tier is not the whole product.
  • Nessus Professional is a single-scanner tool with no centralized multi-user management; that path is an upsell to Security Center or Tenable One.
  • VPR was revised and scores shifted, and Tenable publishes a migration FAQ for it — meaning existing customers had to re-baseline.
  • Product naming churned through 2026 as SKUs were folded under the Tenable One label, which makes older documentation ambiguous.
Nessus Professional interface showing a Top 10 vulnerability report with severity counts
Image: Tenable

2. Qualys

Qualys runs VMDR — Vulnerability Management, Detection and Response — on its Enterprise TruRisk Platform. The architectural bet is a single lightweight Cloud Agent that continuously reports from on-prem servers, endpoints, public and private cloud, containers and mobile, supplemented by scanner appliances and cloud connectors.

Qualys publishes two separate scores, which is more transparency than most. QDS (Qualys Detection Score) rates an individual vulnerability 1–100, starting from CVSS and adjusting for Real-Time Threat Indicators including active exploitation and CISA KEV membership. TruRisk Score rates an asset 0–1,000 by combining QDS, threat intelligence and an Asset Criticality Score. Enrichment draws on 25+ threat intelligence sources.

The platform achieved FedRAMP High authorization for its Government Platform on 27 August 2025, sponsored by the DEA. At ROCon Houston 2025 Qualys extended Enterprise TruRisk Management with an agentic AI layer, including Agent Val for exploit validation with proof.

Best for: Teams that want continuous assessment from one agent rather than scheduled network scans, and regulated buyers needing FedRAMP High.

Pros

  • One agent covers the full estate, including containers and mobile, reducing the number of collectors to maintain.
  • QDS and TruRisk calculations are documented down to score bands and weighting, so prioritization is auditable.
  • FedRAMP High authorized Government Platform, plus multi-region PODs and a private cloud option for data residency.
  • Published per-host tiered pricing on its own AWS Marketplace listing — for example 128 hosts at $596/month rising to 5,120 hosts at $6,805/month (observed 1 October 2026).

Cons

  • Heavily modularized. VMDR, Web Application Scanning, Patch Management, TotalCloud, CSAM and Container Security are separate purchasable apps; full coverage means stacking SKUs.
  • No published pricing on qualys.com — the /pricing path returns a 404, so direct pricing is sales-led.
  • Value depends on getting the Cloud Agent deployed everywhere, which is real rollout and maintenance work.
  • TruRisk is a proprietary composite on a 0–1,000 scale that is not comparable to CVSS or EPSS, and needs Asset Criticality tuning before it means anything.
Qualys Enterprise TruRisk Platform eliminations screen listing QIDs with detection scores and remediation actions
Image: Qualys

3. Rapid7

The important 2026 fact about Rapid7 is packaging. Rapid7's own site now states that InsightVM "is now part of Rapid7 Exposure Command," pairing internal vulnerability data with attack surface, cloud and application risk. InsightVM still exists and still ships, but it is sold as a component: Exposure Command Essentials bundles VM with attack surface management, and Exposure Command Ultimate adds cloud and application security context.

The technical pitch is the pairing of two views — Surface Command showing what an attacker can see from outside, InsightVM showing what is exposed inside, with the same scan engine as before. Prioritization uses Active Risk, a 0–1,000 score built from current CVSS plus AttackerKB, Metasploit, ExploitDB, Project Lorelei and CISA KEV. As of the February 2026 platform release, Active Risk is the shared risk strategy across InsightVM, Cloud Security and Exposure Command.

Rapid7 remains public (NASDAQ: RPD). Activist investor Jana Partners pushed for a sale; a March 2025 settlement expanded the board from 8 to 11 seats with three Jana-backed directors. No take-private happened.

Best for: Teams that want internal vulnerability data and external attack-surface data scored on one scale.

Pros

  • Active Risk inputs are published, including AttackerKB and Metasploit exploit telemetry that competitors do not have.
  • Single risk strategy now spans VM, cloud and exposure products, so scores are consistent across modules.
  • Published tiered asset pricing on its own AWS Marketplace listing — 0–1,000 assets at $23,000 for a 12-month contract, scaling to 7,001–8,500 assets at $150,960 (observed 1 October 2026).
  • Keeps a hybrid footprint: SaaS Insight Platform plus on-prem Security Console, scan engines and the Insight Agent.

Cons

  • InsightVM is no longer positioned as a standalone purchase. Buyers who want only vulnerability management face platform packaging, and cloud plus application context sits behind the higher Ultimate tier.
  • Legacy risk strategies are formally end-of-life, forcing migration to Active Risk and re-baselining of historical scores.
  • Active Risk does not document EPSS as an input, unlike Tenable and Greenbone — you are taking Rapid7's own telemetry as the exploit signal.
  • No published direct list pricing on rapid7.com.
  • Governance is unsettled: an activist holds roughly 10% with three board seats under a cooperation agreement running to about January 2027.
Diagram showing how Rapid7 InsightVM vulnerability management fits within Exposure Command
Image: Rapid7

4. Microsoft Defender Vulnerability Management

Microsoft Defender Vulnerability Management delivers asset visibility, assessment and built-in remediation across Windows, macOS, Linux, Android, iOS and network devices, per Microsoft's documentation. It runs on the Defender for Endpoint sensor plus agentless scanners that keep monitoring devices not connected to the corporate network.

Several capabilities are genuinely uncommon: network share configuration assessment, authenticated scanning of unmanaged Windows devices, and inventory that reaches hardware and firmware, browser extensions and certificates. Prioritization uses Microsoft threat intelligence including breach likelihood predictions.

The economics are the real story. The add-on is $2.00 per user per month on Microsoft's own pricing page — an order of magnitude below per-asset enterprise VM pricing, if your estate fits the licensing model.

Best for: Organizations already standardized on Microsoft Defender for Endpoint P2 or Microsoft 365 E5, with user-centric rather than server-heavy estates.

Pros

  • $2.00/user/month published on microsoft.com (observed 1 October 2026) — the only genuinely cheap option here.
  • Inventory depth beyond software CVEs: firmware, hardware, certificates and browser extensions.
  • Agentless scanners continue assessing devices off the corporate network, which matters for remote fleets.
  • Authenticated scan for Windows reaches unmanaged devices without a permanent agent.

Cons

  • Licensed per user, not per asset — a poor fit for server estates, OT or asset-heavy environments. Microsoft notes Defender for Endpoint licenses cover up to five devices per user and do not include servers, which must be licensed separately.
  • The $2.00 add-on is not standalone; it layers on Defender for Endpoint P2 or M365 E5. Organizations on P1 or E3 need a different SKU whose price we could not verify on Microsoft's current pricing page.
  • Coverage is deepest on Microsoft-managed endpoints and thinner on heterogeneous network gear, appliances and OT than dedicated scanners.
  • Regional availability is limited — Microsoft's own pricing page repeatedly returns "this product is not available in your market."
  • SaaS only, tethered to the Microsoft Defender portal. No on-prem or air-gapped option.
Microsoft Defender Vulnerability Management dashboard showing exposure score and device recommendations
Image: Microsoft

5. Wiz

Wiz became a Google Cloud subsidiary when the $32B all-cash acquisition closed on 11 March 2026 — the largest in Google's history. Google's announcement states Wiz keeps its brand and continues supporting AWS, Azure, Google Cloud and Oracle Cloud.

The technical distinction is agentless-first scanning. Wiz says it detects vulnerabilities "without any agents," covering a catalog of 120,000+ vulnerabilities across 40+ operating systems, then correlates findings on its Security Graph and validates external exposure through Wiz ASM. That removes the deployment problem that makes agent-based VM slow in ephemeral cloud environments.

On-premises and third-party coverage works differently: it comes through Wiz UVM, which aggregates other scanners' findings, or the optional Sensor workload scanner. If your estate is mostly not cloud, you are buying an aggregator, not the snapshot scanner that makes Wiz distinctive. Our CNAPP platforms roundup covers the broader cloud security side of the product.

Best for: Cloud-native and multicloud estates where agent rollout is the bottleneck.

Pros

  • Agentless scanning means coverage in minutes with no per-workload deployment, which is the hardest part of cloud VM.
  • Security Graph correlates vulnerabilities with identity, network exposure and data sensitivity, so blast-radius analysis for a new CVE is immediate.
  • Genuinely multicloud across AWS, Azure, Google Cloud and Oracle Cloud, and Google has publicly committed to keeping it that way.
  • Published packaging names — Wiz One, Wiz Go and à la carte — with licensing designed to shift usage between capabilities.

Cons

  • Pricing is fully opaque. No list price, no per-asset rate; wiz.io/pricing is a three-step quote request form.
  • On-prem is second-class. Non-cloud coverage depends on aggregating third-party scanners or deploying the Sensor — not the agentless model being sold.
  • Agentless scanning is point-in-time by design. Continuous runtime detection requires the Sensor, which reintroduces agent deployment.
  • New ownership is a real procurement consideration: customers standardized on AWS or Azure are now buying multicloud security from Google and taking neutrality on trust.
  • Wiz's own site claims more than 65% of the Fortune 100, while Google's press release says 50%. Both are vendor figures and they do not agree.
Wiz console showing an AI security dashboard with findings counts and a top risks table
Image: Wiz

6. Greenbone / OpenVAS

Greenbone is the only fully open-source option here, and in 2025–2026 it moved the OpenVAS name to the center of its portfolio: the Greenbone Enterprise Appliance line became OPENVAS SCAN, and the Enterprise Feed became OPENVAS ENTERPRISE FEED. Greenbone says old and new names may be used interchangeably during the transition.

Architecturally it is a classic credentialed network scanner with no agents, built from openvas-scanner (engine), gvmd (manager) and the Greenbone Security Assistant web UI. The feed ships network vulnerability tests; current documentation screenshots show 182,097 NVTs. Licensing is genuinely open: the scanner is GPL-2.0, with gvmd and the web UI under AGPL-3.0.

OPENVAS AI runs an on-premises LLM so that, in Greenbone's words, data never leaves your network — a meaningful differentiator for data-sovereignty buyers. The company was founded in 2008 and positions heavily around European data sovereignty.

Best for: Teams that must self-host, air-gap or keep scan data in a specific jurisdiction, and teams with no budget.

Pros

  • Genuinely free and self-hostable community edition under GPL-2.0 / AGPL-3.0, deployable from containers or source.
  • On-premises AI analysis keeps vulnerability data inside your network, unlike every SaaS option here.
  • EPSS scoring is integrated for exploit-likelihood prioritization.
  • Hardware and virtual appliance options, plus a 14-day enterprise trial, for teams that want self-hosting without building it.

Cons

  • The free Community Feed is deliberately limited, and Greenbone says so. Its own comparison page states the Community Feed "only covers a fraction of real-world threats" and that "thousands of vulnerabilities remain undetected." Coverage for enterprise products including Cisco, Microsoft Exchange and Palo Alto is Enterprise-only.
  • EPSS scoring, CIS Benchmarks, IT-Grundschutz compliance, multiple daily feed updates and guaranteed support response times are all Enterprise-gated.
  • No agents — credentialed network scanning only, which is weak for roaming devices and ephemeral cloud workloads.
  • Community is small: roughly 4,800 GitHub stars on the main scanner repo, and only a few hundred each on the manager and web UI.
  • Naming churn is confusing, with old and new product names coexisting by the vendor's own admission, and presence skews European with a thinner support footprint elsewhere.
  • No published pricing — greenbone.net/en/pricing returns a 404, and enterprise sales run largely through distribution.
Greenbone Security Assistant dashboard showing tasks by severity and NVT counts in the OpenVAS web interface
Image: Greenbone

7. Nucleus Security

Nucleus Security is not a scanner, and that is the point. It ingests findings from the tools you already own — 200+ out-of-the-box connectors spanning scanners, cloud security tools, asset management, ITSM, threat intel feeds, EDR, CSPM, SAST, DAST and OT — then deduplicates, enriches, prioritizes and pushes remediation into ticketing. The platform sits on what Nucleus calls its Data Core, a system of record for assets, exposures and threat intelligence.

Scale is the selling point: Nucleus states one Fortune 500 customer manages 1.9 billion active vulnerabilities on the platform. The team also publishes original research, including an analysis of every CISA KEV addition between October 2025 and March 2026.

In August 2026 Nucleus unveiled Helix, an AI engine comprising Nucleus Insights for exploit intelligence, Nucleus Discover for zero-day exposure, and a natural-language Helix agent. Funding is modest by comparison: $20M announced March 2022 and $43M announced February 2024, the latter led by Arthur Ventures and Lead Edge Capital with In-Q-Tel joining.

Best for: Organizations running three or more scanners that need one prioritized queue and automated ticketing, not another detection engine.

Pros

  • 200+ connectors mean it works with the scanners you have rather than replacing them — including OT and application security tools.
  • Automates the unglamorous part: deduplication across overlapping scanners, then rule-based ticketing into Jira with auto-close and bot comments.
  • Proven at extreme scale on a vendor-stated 1.9 billion active vulnerabilities.
  • Publishes original exploitability research rather than reselling a feed, and serves Federal and SLED buyers.

Cons

  • It has no native detection engine for traditional assets. You must already license Tenable, Qualys, Rapid7 or similar — Nucleus is an additional cost layer on top.
  • No published pricing, and the site's own Pricing navigation link returns a 404.
  • Key Helix capabilities were announced in August 2026 ahead of availability, with Discover and the AI agent slated for September — verify GA status rather than trusting launch messaging.
  • Value is directly proportional to connector depth for your specific stack; a shallow integration degrades the product.
  • Smallest vendor here at roughly $63M disclosed funding, with no round since February 2024.
Nucleus Security ticketing rule configuration for Jira alongside an average days to remediation chart
Image: Nucleus Security

How to choose vulnerability management software

Match the tool to your constraint, not to the feature matrix.

  • You need one vendor for IT, cloud, web apps and OT, including air-gapped sites. Tenable. It is the only option here that covers all of it, and the entry SKUs have real published prices.
  • You want continuous assessment without scheduling network scans. Qualys. One agent, continuously reporting. Budget for the rollout and for stacking modules.
  • You already run Rapid7 or want attacker-view and internal data on one score. Rapid7 Exposure Command. Accept that InsightVM alone is no longer the product.
  • You are a Microsoft shop with a user-centric estate. Defender Vulnerability Management at $2.00/user/month. Price your servers separately before you commit — the per-user model breaks down on server-heavy estates.
  • Your assets are mostly cloud and ephemeral. Wiz. Agentless coverage solves the deployment problem that makes agent-based VM slow in cloud. See also our CNAPP roundup.
  • You must self-host, air-gap, or you have no budget. Greenbone/OpenVAS. Go in knowing the free feed does not cover enterprise products — that is Greenbone's own statement, not a criticism from outside.
  • You already own three scanners and drown in duplicate findings. Nucleus Security. It fixes the consolidation problem and nothing else.

One thing none of these tools fixes: remediation capacity. If your constraint is that nobody patches, a better scanner produces a longer list, not fewer incidents. That is an org problem, and vulnerability management software only makes it measurable.

Adjacent categories worth reading before you buy: EDR tools for endpoint detection, SIEM tools for log correlation, API security platforms for a layer most scanners miss, and IAM solutions since identity exposure now feeds most of these risk scores.

Frequently Asked Questions

What is vulnerability management?

Vulnerability management is the continuous cycle of discovering assets, scanning them for known weaknesses, prioritizing findings by real-world risk, remediating or mitigating them, and verifying the fix. It differs from a one-off vulnerability assessment because it runs permanently and tracks whether risk is actually declining over time.

What is risk-based vulnerability management?

Risk-based vulnerability management prioritizes by likelihood of exploitation and business impact instead of raw CVSS severity. Tools layer exploit intelligence on top of CVSS — CISA KEV membership, EPSS probability, observed attacker activity, asset criticality — producing scores like Tenable VPR, Qualys TruRisk or Rapid7 Active Risk so teams fix the few hundred findings that matter.

What is the difference between patch management and vulnerability management?

Vulnerability management finds and prioritizes weaknesses; patch management deploys the fixes. Many vulnerabilities have no patch and need configuration changes or compensating controls instead. Several vendors sell both — Qualys Patch Management and Tenable's patch verification, for example — but they are usually separate modules with separate licensing.

How do you automate vulnerability management?

Automation works best at three points: continuous discovery through agents or cloud connectors, automatic prioritization using documented risk scoring, and rule-based ticketing that routes findings to the owning team with auto-close on verification. Nucleus Security specializes in the third. Full auto-remediation remains rare because patch failures break production.

Why is vulnerability management important?

Most breaches exploit known vulnerabilities with available patches rather than novel zero-days. Vulnerability management shrinks that window by making exposure measurable and assigning ownership. It is also a compliance requirement under PCI DSS, SOC 2, ISO 27001 and most cyber-insurance questionnaires, which generally expect documented scanning and remediation SLAs.


Editor's note — sources: Tenable One pricing, Nessus Professional, Tenable VPR documentation, Tenable–Vulcan Cyber acquisition, Tenable Hexa AI, Qualys VMDR, Qualys TruRisk score calculation, Qualys FedRAMP High, Rapid7 InsightVM, Rapid7 risk strategies, Rapid7 board settlement 8-K, Microsoft Defender Vulnerability Management docs, Defender VM pricing, Google completes Wiz acquisition, Wiz vulnerability management, Greenbone OPENVAS rename, Greenbone feed comparison, Greenbone license information, Nucleus Security platform, Nucleus $43M round. Pricing and feature claims observed 1 October 2026 and subject to change.

Get Edgewisely in your inbox

Business stories that matter, free. Enter your email — no password, no account to set up.
jamie@example.com
Subscribe