Loading...

Microsoft Defender Vulnerability Management: Private preview for selected developer package vulnerability coverage

Microsoft Defender Vulnerability Management: Private preview for selected developer package vulnerability coverage

Microsoft Defender Vulnerability Management is privately previewing expanded vulnerability coverage for selected Node.js, Python, and Java packages on Windows devices. It integrates with existing workflows, APIs, and exports, with rollout planned from September to December 2026. Organizations should prepare for increased data volume and validate integrations before enabling. What and Why: Microsoft Defender Vulnerability Management is expanding vulnerability coverage to selected Node.js, Python, and Java packages on supported Microsoft Defender for Endpoint-managed Windows devices. During this private preview, participating customers can identify supported vulnerable packages, affected devices, and detected versions through existing vulnerability investigation and recommendation workflows. Package data may also become available through supported API, export, and Advanced Hunting experiences as those preview paths are enabled. The expanded coverage can increase the number of records returned through assessment APIs and complete-file exports. For JSON assessment exports, customers can use supported server-side filters to limit the returned population. Complete-file exports include the full enabled population, so customers can filter the downloaded files by ProductCategory or use the Microsoft-provided legacy component support list to preserve their previous processing scope where needed. This preview provides curated coverage rather than a complete package inventory. Coverage varies by package, platform, collector, and product experience. It does not provide SBOM, dependency graphs, reachability analysis, package ownership, or complete ecosystem coverage. Participants will receive enablement guidance, known limitations, test scenarios, and a dedicated feedback channel. Rollout Schedule: General Availability (Worldwide): We will begin rolling out on late November 2026 and expect to complete by late December 2026. Public Preview (Worldwide): We will begin rolling out on late October 2026 and expect to complete by late November 2026. Targeted Release (Worldwide): We will begin rolling out on late September 2026 and expect to complete by late October 2026. Impact on Your Organization: This feature expands vulnerability management coverage in Microsoft Security Exposure Management (MSEM) to include CVE exposure for a curated set of Node.js, Python, and Java packages on supported Windows devices onboarded to Microsoft Defender for Endpoint. These package findings will appear within existing experiences for software components, vulnerabilities, affected devices, and security recommendations, helping security […]

The post Microsoft Defender Vulnerability Management: Private preview for selected developer package vulnerability coverage appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender Vulnerability Management: Private preview for selected developer package vulnerability coverage

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Dynamics 365 Field Service: Automate optimizations with Scheduling Operations Agent

This release expands the optimization capabilities of the Scheduling Operations Agent to include the ability to create recurring optimizations...

1 hour ago

Microsoft Teams: Call quality feedback surveys for Teams Rooms on Android

Microsoft Teams will introduce call quality feedback surveys for Teams Rooms on Android starting November 2026. Users can rate audio, video, a...

2 hours ago

Microsoft Edge: Retiring legacy sign-in implementation on Windows

Microsoft Edge on Windows will retire its legacy direct-WAM sign-in in version 157, fully adopting the OneAuth library to standardize authenti...

2 hours ago

Microsoft Defender for Office 365: Post-delivery protection for malicious QR codes in Microsoft Teams

Microsoft Defender for Office 365 extends Teams URL protection to detect malicious URLs in QR codes post-delivery, warning users and enabling ...

3 hours ago

Microsoft Teams: Analytics for desk utilization in Teams Pro Management portal

Microsoft Teams Pro Management portal will add desk utilization analytics, showing usage, reservations, occupancy, and peak patterns. Requires...

3 hours ago

‘Record A Skill’ Capability in PowerPoint Copilot

PowerPoint Copilot will introduce a “Record a Skill” feature in October 2026, allowing users to record and reuse workflows for com...

3 hours ago

Microsoft 365: Targeted Release retirement

Microsoft 365 Targeted Release will retire in January 2027, replaced by Frontier, Standard, and Deferred release options. Administrators must ...

3 hours ago

Interim guidance for Manitoba time zone changes

A time zone change affects Windows devices in Manitoba, with Windows releasing a fix in October 2026. Manitoba is permanently moving to UTC-5 ...

3 hours ago

Microsoft Purview DLP: Improved setup and Intune multi-admin approval support for unmanaged apps in Edge for Business

Starting November 2026, Microsoft Purview DLP will improve setup and support Intune multi-admin approval for unmanaged apps in Edge for Busine...

3 hours ago

Microsoft Viva Insights: New Power BI report publishing capabilities for leaders

Microsoft Viva Insights is expanding Power BI report publishing to leaders, allowing them to publish and distribute reports directly. The R...

3 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.