Skip to main content

Manage Exceptions

Manage Exceptions lists the CVEs you've chosen to exclude from your vulnerability posture- either accepted as risk or marked not applicable- so they stop cluttering the Vulnerabilities list.

How to get here

You need View Manage Exceptions permission (ZiroPatchPlus edition).

  1. In the left sidebar, click Vulnerability to expand it, then click Manage Exceptions.

Navigate to: Vulnerability → Manage Exceptions

URL path: /vulnerability/manage-exceptions

The Manage Exceptions screen

The Manage Exceptions listThe Manage Exceptions list
ColumnWhat it shows
CVEThe excepted CVE- click for its full detail (read-only).
Exception TypeAcceptable Risk or Not Applicable.
Reason For ExclusionWhy it was excepted.
Created ByWho added the exception.
Created OnWhen (hidden by default).

Row actions: the eye icon opens the CVE's detail (view-only); delete removes the exception, putting the CVE back into the active list.

How do I add an exception?

You add exceptions from the Vulnerabilities list: select one or more CVEs and click Add Exceptions.

The Add Exception dialogThe Add Exception dialog
FieldRequiredNotes
ScopeYesWhich endpoints the exception applies to.
Exception TypeYesAcceptable Risk (you accept it) or Not Applicable (a false positive). Defaults to Acceptable Risk.
Reason For ExceptionNoA note explaining the decision.

Click Save. The CVE then appears here and drops off the active Vulnerabilities list for the scoped machines.

Tips & troubleshooting

  • An excepted CVE reappeared. Its exception may have been scoped to specific machines, or deleted here- check the Scope and re-add if needed.