of known exploited vulnerabilities in the first half of 2026 showed exploitation on or before the day their CVE was published.
Every new CVE starts with the same question: where do we have it?
A Run answers from the model Unizo already keeps current. There is no new scan to wait for.
Hunt by CVE. Built to hunt beyond it.
Hunt a specific CVE
Launch a Run for a named CVE and find every place it is present across your connected environment.
CVE-2026-2213Hunt what a CVE search can't see
Built for a vulnerable version named in an advisory before a CVE exists, and for a compromised package that will never get one.
Whichever way a hunt starts, it follows through the same way.
Present is a list. Reachable is the work.
Every instance is qualified against Live Security Context. Reachable ones become Exposures. For the rest, you can stand down with evidence.
Your policy decides what opens. You can override it at launch.
Qualified Exposures open Investigations as your policy sets. Each Investigation drafts its Plan, including a compensating control when a patch can't land yet.
How Plans are draftedA hunt doesn't end at the list. It ends at verified closure.
Answer "are we exposed?" with evidence.
Every Run leaves a Report: what was present, what was reachable, what opened, and when it was checked.
Common questions
Where does a hunt look?
Across the environment Unizo is connected to. The connected tools are listed on Integrations, and a tool with an API can be connected during setup.
How current is the answer?
A Run answers from Live Security Context, which is kept current from your connected tools on a refresh you can tune. There is no new scan to wait for.
Does a hunt change anything in our environment?
No. A Run finds, qualifies and records. Investigations open as your policy sets, and the accountable owner applies every change.
Can we choose whether Investigations open?
Yes. Your policy sets the default, and you can override it when you launch the Run.
What if the CVE comes back after we close it?
Once an Exposure is closed, Unizo reopens it if the root cause comes back.
What about threats that don't have a CVE?
Beyond a specific CVE, exposure hunting is built to hunt a vulnerable or compromised package, and follow it the same way, from where it is present to verified closure.
Bring us the CVE you're chasing right now.
We will show you where it is present, where it actually reaches, and who owns the fix.