GravityZone add-on

Patch Management, from the console you already run

GravityZone Patch Management keeps Windows, macOS, Linux and an extensive list of third-party applications current, automatically, from the same GravityZone console, agent and policy as the rest of your endpoint security - so patching stops being the job nobody has time for.

  • 180%

    Rise in exploited vulnerabilities

    as the way breaches start, 2024 Verizon Data Breach Investigations Report

  • Any tier

    Add-on to every solution

    to every GravityZone endpoint security solution, managed from the same console

0 to 99%Patch compliance reachedby a US Archdiocese after deploying GravityZone Patch Management, up from 75 percent
0 platformsPatched from one policymacOS, Windows and Linux, plus third-party applications on each
0 agentNo second agentpatching rides on the Bitdefender Endpoint Security Tools agent already installed

Three jobs

What automatic patching changes

The three outcomes the module is built for, in the order they matter to a breach.

01 / 03

Stop advanced attacks earlier

Stay ahead of threats by cutting the time to patch across macOS, Windows, Linux and third-party applications.

  • Critical security updates prioritised and installed automatically
  • Time to patch measured in hours, not maintenance cycles
  • The vulnerability is closed before the exploit arrives

02 / 03

Maximise efficiency and productivity

Reduce overhead with automatic and manual patching, effective patch prioritisation and granular controls.

  • Automatic and on-demand modes side by side
  • Reboots postponed so users and the network are not interrupted
  • Granular control over which patches go where, and when

03 / 03

Reduce risk

Drastically improve patch compliance with a solution that reliably updates vulnerable systems.

  • Risk exposure minimised across every endpoint
  • Compliance requirements met with evidence to show
  • Failed and missing patches visible, not assumed

Capabilities

Mitigate vulnerability exploitation and boost productivity

Unified endpoint protection with automated patching. Every screen below is the GravityZone console.

GravityZone Patch inventory listing patches with KB number, CVE count, Bulletin ID, severity, OS type, category and affected products, with Install, Uninstall and Ignore actions

Detailed Patch Inventory

Every patch with its CVE list, Bulletin ID, severity, OS type, category and the products it affects, in one searchable inventory across Windows, Linux and macOS. Missing patches deploy from here in a click, and a patch that would break a workflow can be blacklisted or held back temporarily.

  • CVE and Bulletin ID on every row, so a vulnerability report maps straight to a patch
  • Quick deployment of missing patches and patch blacklisting
  • Temporarily prevent a patch that might break a workflow
GravityZone policy module list with Patch Management selected alongside Antimalware, Sandbox Analyzer, Firewall, Network Protection, Device Control, Integrity Monitoring, Relay and Encryption

Comprehensive Protection

A complete operating system and application patching solution for macOS, Windows and Linux environments and an extensive list of third-party applications - switched on as one more module in the policy, beside antimalware, firewall and device control.

Patch Management policy page showing a maintenance window with target operations, patch scope covering security and non-security, and a weekly recurrence schedule

Automatic and On-Demand Patching

IT teams prioritise and automate the installation of critical security updates, schedule scanning for missing security and non-security patches or for a specific vendor or product, and postpone the reboot for patches that need one - without impacting the network or users' productivity.

GravityZone Network view filtered to the Patch Caching Server role, listing relay endpoints with their IP addresses and entity type

Patch Caching Server

Endpoints with the Relay role can act as Patch Caching Servers. When enabled, a relay stores software patches from vendor websites and distributes them to target endpoints inside your network - cutting internet traffic, conserving bandwidth, and tightening security by limiting external web access from endpoints.

Create report dialog for a Network Patch Status report, with options to run now or scheduled, include all patches or only those in the inventory, and email a PDF summary and CSV details

Reporting and Notifications

Comprehensive reports and notifications give full control and visibility over the status of installed, missing and failed patches across all endpoints - run now or on a schedule, delivered by email as a PDF summary and a CSV of the detail.

Requirements

What it needs and what it covers

Nothing new to stand up. The module runs on the GravityZone console and agent you already have.

11 requirements

What it needs and what it covers
RequirementWhat applies
1Console and agent3 itemsThe management side is whatever GravityZone you run today.
The same GravityZone console customers use today, for both GravityZone cloud and on-premises deployments
Bitdefender Endpoint Security Tools, the agent already installed for endpoint protection
Any endpoint holding the Relay role, when the option is enabled
2Operating systems4 itemsEvery platform the endpoint agent itself supports.
All desktop editions supported by GravityZone endpoint protection, from Windows 8
Microsoft Windows, serverAll server editions supported by GravityZone endpoint protection, from Windows Server 2012 R2
macOSSupported
LinuxSupported
3What gets patched4 itemsOperating systems and the applications on them, not one or the other.
Operating system patchesSecurity and non-security, on every platform above
An extensive, regularly updated list of vendors and products
Patch scope per scanSecurity only, non-security only, or a specific vendor or product
Patch identifiersCVE and Bulletin ID on every patch in the inventory

Bitdefender publishes the full list of supported third-party vendors and products on its business support site and updates it regularly. Ask us for the current list before you commit to a rollout that depends on a specific application.

Why Bitdefender

Why choose GravityZone Patch Management

With vulnerability exploitation up 180 percent as the primary way breaches begin (2024 DBIR), reducing time to patch is crucial - and managing software updates is exactly the work IT teams do not have time for.

Unified, comprehensive solution

Deployed and managed from the same GravityZone console, agent and policy as the other security products on the platform. That streamlines security operations and closes the visibility gaps a separate patching tool leaves.

Maximum productivity and business continuity

Rapid patch deployment keeps patch compliance high with minimal disruption to users and operations, which is what actually improves the organisation's security posture rather than just its inventory.

Lower security costs

Consolidating patch management and endpoint security on a single vendor and platform helps enterprises and managed service providers reduce cost and simplify security operations and reporting.

In production
Bitdefender Patch Management has been fantastic. If a zero-day fix comes out, Bitdefender can update the entire organization with the latest security patch quickly. Patch compliance has gone from 75 to nearly 99 percent. Before, it was not uncommon for workstations in remote locations to go years without an update.
IT Director, US Archdiocese, Catholic Archdiocese, United States

Independent evaluations

The platform underneath, judged by people who publish their methodology

Patch Management is a module of GravityZone. These are the evaluations of the platform it runs on, each with the year it was published.

AV-Comparatives 2025 Endpoint Prevention and Response test result for Bitdefender

Top protection, lowest TCO

AV-Comparatives 2025 Endpoint Prevention and Response Test: Bitdefender achieved top breach prevention and the lowest total cost of ownership, and was the only vendor to block 100 percent of attacks during the first stage.

MITRE ATT&CK Evaluations 2024 badge

High visibility, minimal noise

MITRE ATT&CK Evaluations 2024: 100 percent analytical coverage for both Linux and macOS, with zero false positives in both cases.

AV-TEST Award 2023 for Best Protection and Best Performance, business users

Best Protection and Best Performance

AV-TEST Award 2023: GravityZone Endpoint Security took both Best Protection and Best Performance in the business users category.

Forrester Wave 2024 Strong Performer badge for endpoint detection and response

Strong Performer in EDR

Named a Strong Performer in the Forrester Wave 2024 report on EDR platforms.

Gartner Peer Insights Customers' Choice 2026 badge

Customers' Choice 2026

A Customers' Choice in the 2026 Gartner Peer Insights Voice of the Customer for Endpoint Protection Platforms - the rating that comes from verified users rather than analysts.

Gartner Magic Quadrant for Endpoint Protection, May 2026, showing Bitdefender in the Visionaries quadrant

Visionary 2026

Positioned as a Visionary in the 2026 Gartner Magic Quadrant for Endpoint Protection Platforms.

Questions

Patch Management, answered

Stop leaving the patching to whoever has time

Tell us which GravityZone tier you run and how many endpoints, and we will quote Patch Management alongside it. Not on GravityZone yet? Start with a free trial of the platform and add the module when you are ready. Prices are for licences only and do not include implementation services.