Skip to Content

MC1490909 Microsoft Defender Vulnerability Management Private preview for selected developer package vulnerability coverage

Summary

Microsoft Defender Vulnerability Management is privately previewing expanded vulnerability coverage for selected Node.js, Python, and Java packages on Windows devices. It integrates with existing workflows, APIs, and exports, with rollout planned from September to December 2026. Organizations should prepare for increased data volume and validate integrations before enabling.

Message ID: MC1490909
Published: Oct 7, 2026
Service: Microsoft Defender XDR
Tag: New feature, Admin impact

Microsoft Message

Microsoft Defender Vulnerability Management is expanding vulnerability coverage to selected Node.js, Python, and Java packages on supported Microsoft Defender for Endpoint-managed Windows devices. During this private preview, participating customers can identify supported vulnerable packages, affected devices, and detected versions through existing vulnerability investigation and recommendation workflows. Package data may also become available through supported API, export, and Advanced Hunting experiences as those preview paths are enabled. The expanded coverage can increase the number of records returned through assessment APIs and complete-file exports. For JSON assessment exports, customers can use supported server-side filters to limit the returned population. Complete-file exports include the full enabled population, so customers can filter the downloaded files by ProductCategory or use the Microsoft-provided legacy component support list to preserve their previous processing scope where needed. This preview provides curated coverage rather than a complete package inventory. Coverage varies by package, platform, collector, and product experience. It does not provide SBOM, dependency graphs, reachability analysis, package ownership, or complete ecosystem coverage. Participants will receive enablement guidance, known limitations, test scenarios, and a dedicated feedback channel.

Rollout Schedule

  • General Availability (Worldwide): We will begin rolling out on late November 2026 and expect to complete by late December 2026.
  • Public Preview (Worldwide): We will begin rolling out on late October 2026 and expect to complete by late November 2026.
  • Targeted Release (Worldwide): We will begin rolling out on late September 2026 and expect to complete by late October 2026.

Impact on Your Organization

This feature expands vulnerability management coverage in Microsoft Security Exposure Management (MSEM) to include CVE exposure for a curated set of Node.js, Python, and Java packages on supported Windows devices onboarded to Microsoft Defender for Endpoint. These package findings will appear within existing experiences for software components, vulnerabilities, affected devices, and security recommendations, helping security teams identify developer-package exposure alongside the software and vulnerability information they already use.

For organizations that consume vulnerability data outside the portal, the expanded coverage may also affect assessment exports and downstream integrations. The preview introduces ProductCategory to help distinguish Applications, Components, and BIOS/firmware records, while JSON integrations can explicitly include the expanded component population. Complete-file exports for enabled tenants receive the full package population, so organizations should evaluate potential changes to file volume, ingestion, and downstream processing.

The initial preview has defined coverage boundaries. It is limited to Windows, and areas such as package-native identity, dependency relationships, ownership, SBOM, VEX, reachability, and affectedness are not included. Advanced Hunting remains available, but ProductCategory support in the relevant tables may not be enabled during the initial preview phase.

Action Required/Recommendations

Before enablement, admins should identify the people, integrations, and workflows that may be affected by the expanded package population. This includes JSON and complete-file assessment exports, Delta integrations, Advanced Hunting queries and custom detections where applicable, as well as API-based extraction, dashboards, BI, SIEM, ITSM, and data-lake ingestion. Organizations should also capture a baseline of relevant workflows, including current file sizes, ingestion and processing times, so they can compare behavior before and after activation.

Admins should review each integration before opting in and validate that existing applications, components, queries, and downstream processes continue to behave as expected after enablement. For Delta integrations, a new baseline should be established when the included population changes. For complete-file exports, organizations that need to preserve their previous component population can use the Microsoft-provided Legacy Components Support List during ingestion.

Finally, organizations participating in the preview need an approved environment and enablement window, along with named practitioner, integration, and rollback contacts. Microsoft enables the bounded package population for the approved environment, after which the organization should run its assigned scenarios and report unexpected endpoint, data, query, or processing behavior.

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.