DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk5 min

VEX Documents: Status, Justification, and Updates Explained

VEX documents communicate whether a specific product and release is affected by a vulnerability. Learn how to read status, justification, response and updates.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A VEX document says whether a specific product or release is affected by a known vulnerability, and may explain why or describe the supplier’s response. Its status applies to the product and version named in the advisory—not automatically to every product that uses the same component. To decide what it means for your deployment, match the vulnerability, product and release, then read the status, rationale and update information together.

What is VEX?

VEX stands for Vulnerability Exploitability eXchange. It is machine-readable information about whether a named product is affected by a known vulnerability. The OASIS Common Security Advisory Framework (CSAF) Version 2.1 VEX profile puts its purpose this way: “The main purpose of the VEX format is to state that and why a certain product is, or is not, affected by a vulnerability.” Read the OASIS CSAF 2.1 VEX profile.

A VEX statement is a supplier’s product-specific assertion, not a general verdict about a software component in every context. CSAF VEX associates product status with product and vulnerability records. A document can cover multiple products or releases and report different states for each, so check the exact product identity and release rather than relying on a product family name or a component match alone.

What do the VEX statuses mean?

In the CSAF VEX profile, the principal status values are known_affected, known_not_affected, fixed and under_investigation. Cisco’s VEX FAQ describes these in practical terms:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Status Practical meaning How to read it
known_affected The product is affected by the vulnerability. Use the advisory’s remediation or response information to determine what action the supplier recommends.
known_not_affected The product is not affected; no remediation is necessary for that product and vulnerability. Read the stated justification, and confirm that the product and release match your deployment.
fixed A fix has been applied to mitigate the impact. Check which release or product the fixed status applies to; do not assume your installed version includes the fix.
under_investigation It is not yet known whether the product is affected. Treat the status as unresolved and look for later advisory information.

These status definitions are for the CSAF VEX profile; other formats may use different fields or vocabularies. Cisco’s definitions and guidance appear in its Vulnerability Exploitability eXchange FAQs.

What does “not affected” mean?

known_not_affected is a claim about the product as identified in the advisory. The justification explains why the vulnerability does not apply to that product. It is not, by itself, a guarantee about every configuration or deployment choice a reader may have made. Cisco’s FAQ describes several common justification categories:

  • component_not_present: the vulnerable component is not included in the product.
  • vulnerable_code_not_present: the component may be present, but the vulnerable code is not.
  • vulnerable_code_not_in_execute_path: the vulnerable code is not reached along the relevant execution path.
  • vulnerable_code_cannot_be_controlled_by_adversary: an attacker cannot control the code in the way required for exploitation.
  • inline_mitigations_already_exist: a mitigation within the product prevents exploitation.

These are reasons for the supplier’s product-level assessment, not severity ratings. If the stated rationale depends on a particular product design or behavior, compare it with the product and release you actually run; do not substitute assumptions about your local configuration for the supplier’s stated scope.

How do status, justification and response differ?

They answer separate questions. Status is the disposition for a product and vulnerability; justification is why that disposition applies; response describes what the supplier has done or plans to do. CycloneDX’s vulnerability exploitability use case describes these as distinct information, alongside detail about unaffected versions. See the CycloneDX vulnerability exploitability use case.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For example, “not affected” is the status, “the vulnerable component is absent” is a possible justification, and “no remediation is needed” may describe the response. Keeping these concepts separate helps avoid mistaking an explanation for a fix or a remediation plan for proof that a particular installed release is already fixed.

How do I know whether a VEX statement applies to my product version?

  1. Identify the vulnerability. Match the vulnerability identifier in the advisory to the issue you are investigating.
  2. Match the product and release. Compare the product identity and version in the VEX record with the product actually deployed. If the advisory gives version-specific scope, use it rather than assuming that all releases share a status.
  3. Read the status and its context. Check the applicable status, any justification, and the supplier’s response or remediation information. For a fixed status, determine which release contains the fix.
  4. Check the advisory’s dates and source. Review its publication or update information and consult the supplier’s current advisory for the exact release before making a current security decision.

VEX complements, rather than replaces, product and component inventory. CISA’s Software Acquisition Guide explains that a software bill of materials (SBOM) helps identify components, while VEX helps determine whether known vulnerabilities affect a product and whether action is needed. Read CISA’s Software Acquisition Guide for Government Enterprise Consumers.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why did the VEX status change?

A status can change as a supplier investigates a vulnerability, learns more about a product, or makes a fix available. Cisco describes VEX information as point-in-time: it can become obsolete as vulnerabilities are disclosed, fixed and investigated. A previous “under investigation” status may be clarified later, and a fix may change the status for a particular release. Check the supplier’s updated advisory rather than treating an older VEX file as a permanent verdict. The CISA VEX Use Cases Document also illustrates that one document can give different statuses for different products and versions.

There is no universal update schedule established by these sources. Suppliers’ publication and revision practices differ, so the advisory’s own update details and the supplier’s current security information are the relevant guides.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Are all VEX files in the same format?

No. CISA identifies CSAF, CycloneDX and SPDX as formats in which VEX can be implemented, and also mentions OpenVEX implementations. The common purpose is to communicate vulnerability applicability, but the available sources do not establish that the formats have identical fields, product-identity methods, status vocabularies or requirements. When reading a file, identify its format and interpret its fields according to that format’s specification rather than assuming one schema applies to all.

If you are evaluating VEX support in a security workflow, useful questions include how the format identifies products and versions, what status and justification vocabulary it supports, how files are distributed and updated, and how vulnerability statements relate to an SBOM. A format name alone does not tell you whether a particular supplier publishes updates in a way your process can consume.

What does Microsoft’s 2026 VEX announcement cover?

In an announcement dated September 8, 2026, Microsoft said it was publishing VEX statements for all Microsoft-assigned CVEs. This is Microsoft’s stated coverage, not an industry-wide commitment or a guarantee about another supplier’s products or publishing practice. Read Microsoft Security Response Center’s announcement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.