Patch Management, from the console you already run
GravityZone Patch Management keeps Windows, macOS, Linux and an extensive list of third-party applications current, automatically, from the same GravityZone console, agent and policy as the rest of your endpoint security - so patching stops being the job nobody has time for.
as the way breaches start, 2024 Verizon Data Breach Investigations Report
Any tier
Add-on to every solution
to every GravityZone endpoint security solution, managed from the same console
0 to 99%Patch compliance reachedby a US Archdiocese after deploying GravityZone Patch Management, up from 75 percent
0 platformsPatched from one policymacOS, Windows and Linux, plus third-party applications on each
0 agentNo second agentpatching rides on the Bitdefender Endpoint Security Tools agent already installed
Three jobs
What automatic patching changes
The three outcomes the module is built for, in the order they matter to a breach.
01 / 03
Stop advanced attacks earlier
Stay ahead of threats by cutting the time to patch across macOS, Windows, Linux and third-party applications.
Critical security updates prioritised and installed automatically
Time to patch measured in hours, not maintenance cycles
The vulnerability is closed before the exploit arrives
02 / 03
Maximise efficiency and productivity
Reduce overhead with automatic and manual patching, effective patch prioritisation and granular controls.
Automatic and on-demand modes side by side
Reboots postponed so users and the network are not interrupted
Granular control over which patches go where, and when
03 / 03
Reduce risk
Drastically improve patch compliance with a solution that reliably updates vulnerable systems.
Risk exposure minimised across every endpoint
Compliance requirements met with evidence to show
Failed and missing patches visible, not assumed
Capabilities
Mitigate vulnerability exploitation and boost productivity
Unified endpoint protection with automated patching. Every screen below is the GravityZone console.
Detailed Patch Inventory
Every patch with its CVE list, Bulletin ID, severity, OS type, category and the products it affects, in one searchable inventory across Windows, Linux and macOS. Missing patches deploy from here in a click, and a patch that would break a workflow can be blacklisted or held back temporarily.
CVE and Bulletin ID on every row, so a vulnerability report maps straight to a patch
Quick deployment of missing patches and patch blacklisting
Temporarily prevent a patch that might break a workflow
Comprehensive Protection
A complete operating system and application patching solution for macOS, Windows and Linux environments and an extensive list of third-party applications - switched on as one more module in the policy, beside antimalware, firewall and device control.
Automatic and On-Demand Patching
IT teams prioritise and automate the installation of critical security updates, schedule scanning for missing security and non-security patches or for a specific vendor or product, and postpone the reboot for patches that need one - without impacting the network or users' productivity.
Patch Caching Server
Endpoints with the Relay role can act as Patch Caching Servers. When enabled, a relay stores software patches from vendor websites and distributes them to target endpoints inside your network - cutting internet traffic, conserving bandwidth, and tightening security by limiting external web access from endpoints.
Reporting and Notifications
Comprehensive reports and notifications give full control and visibility over the status of installed, missing and failed patches across all endpoints - run now or on a schedule, delivered by email as a PDF summary and a CSV of the detail.
Requirements
What it needs and what it covers
Nothing new to stand up. The module runs on the GravityZone console and agent you already have.
11 requirements
What it needs and what it covers
Requirement
What applies
1Console and agent3 itemsThe management side is whatever GravityZone you run today.
The same GravityZone console customers use today, for both GravityZone cloud and on-premises deployments
Patch Management appears as a module in the existing policy editor. There is no separate patching console, no separate login and no separate reporting engine.
Bitdefender Endpoint Security Tools, the agent already installed for endpoint protection
The module is enabled per policy. Endpoints receive it on the next policy sync without a reinstall.
Any endpoint holding the Relay role, when the option is enabled
A relay downloads patches from vendor sites once and serves them to the endpoints behind it, so a branch office with a thin internet line patches from a local copy.
2Operating systems4 itemsEvery platform the endpoint agent itself supports.
All desktop editions supported by GravityZone endpoint protection, from Windows 8
Compatibility follows the endpoint security product's own system requirements, so a Windows version the agent supports is a Windows version the module patches.
Microsoft Windows, server
All server editions supported by GravityZone endpoint protection, from Windows Server 2012 R2
macOS
Supported
Linux
Supported
3What gets patched4 itemsOperating systems and the applications on them, not one or the other.
Operating system patches
Security and non-security, on every platform above
An extensive, regularly updated list of vendors and products
Bitdefender maintains the supported vendors and products list on its business support site. Ask us for the current list rather than assuming a specific application is covered.
Patch scope per scan
Security only, non-security only, or a specific vendor or product
Patch identifiers
CVE and Bulletin ID on every patch in the inventory
Bitdefender publishes the full list of supported third-party vendors and products on its business support site and updates it regularly. Ask us for the current list before you commit to a rollout that depends on a specific application.
Why Bitdefender
Why choose GravityZone Patch Management
With vulnerability exploitation up 180 percent as the primary way breaches begin (2024 DBIR), reducing time to patch is crucial - and managing software updates is exactly the work IT teams do not have time for.
Unified, comprehensive solution
Deployed and managed from the same GravityZone console, agent and policy as the other security products on the platform. That streamlines security operations and closes the visibility gaps a separate patching tool leaves.
Maximum productivity and business continuity
Rapid patch deployment keeps patch compliance high with minimal disruption to users and operations, which is what actually improves the organisation's security posture rather than just its inventory.
Lower security costs
Consolidating patch management and endpoint security on a single vendor and platform helps enterprises and managed service providers reduce cost and simplify security operations and reporting.
In production
Bitdefender Patch Management has been fantastic. If a zero-day fix comes out, Bitdefender can update the entire organization with the latest security patch quickly. Patch compliance has gone from 75 to nearly 99 percent. Before, it was not uncommon for workstations in remote locations to go years without an update.
IT Director, US Archdiocese, Catholic Archdiocese, United States
Independent evaluations
The platform underneath, judged by people who publish their methodology
Patch Management is a module of GravityZone. These are the evaluations of the platform it runs on, each with the year it was published.
Top protection, lowest TCO
AV-Comparatives 2025 Endpoint Prevention and Response Test: Bitdefender achieved top breach prevention and the lowest total cost of ownership, and was the only vendor to block 100 percent of attacks during the first stage.
High visibility, minimal noise
MITRE ATT&CK Evaluations 2024: 100 percent analytical coverage for both Linux and macOS, with zero false positives in both cases.
Best Protection and Best Performance
AV-TEST Award 2023: GravityZone Endpoint Security took both Best Protection and Best Performance in the business users category.
Strong Performer in EDR
Named a Strong Performer in the Forrester Wave 2024 report on EDR platforms.
Customers' Choice 2026
A Customers' Choice in the 2026 Gartner Peer Insights Voice of the Customer for Endpoint Protection Platforms - the rating that comes from verified users rather than analysts.
Visionary 2026
Positioned as a Visionary in the 2026 Gartner Magic Quadrant for Endpoint Protection Platforms.
Where it fits
An add-on to whichever GravityZone tier you run
Patch Management is not a standalone product. It is licensed per endpoint on top of any GravityZone endpoint security tier, and switched on in the same policy.
Bitdefender sells this add-on online in some markets. In Thailand it is licensed through us - tell us how many endpoints and which tier, and we quote the add-on alongside it.
Tell us which GravityZone tier you run and how many endpoints, and we will quote Patch Management alongside it. Not on GravityZone yet? Start with a free trial of the platform and add the module when you are ready. Prices are for licences only and do not include implementation services.