Back Iotinsider Gluware targets medical device vulnerabilities with automation platform
Gluware is extending its network automation platform to connected medical devices , aiming to automate the process of identifying and patching vulnerabilities in equipment such as infusion pumps, imaging systems and patient monitors.
The US company said today that its new IoMT Exposure Management service can link published vulnerabilities to specific devices , identify applicable software updates and execute remediation through a hospital’s existing approval and audit processes.
The move addresses a persistent problem for hospitals, where patching a vulnerable device can be more complicated than updating a conventional IT system. Medical equipment may need to remain available for patient care, while changes often require coordination between clinical engineering, IT and security teams.
As a result, the process of turning a vulnerability disclosure into a completed, documented patch can involve multiple systems and manual handoffs.
The number of vulnerabilities recorded in the Common Vulnerabilities and Exposures (CVE) database rose 263% between 2020 and 2025, according to figures cited by Gluware from the US National Institute of Standards and Technology (NIST).
Gluware also cited research from Ordr , a healthcare IoT security company, which found that the average connected medical device has 6.2 known vulnerabilities. It said roughly 75% of infusion pumps have a vulnerability listed in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue, while 60% of connected medical devices use components that are no longer supported by their manufacturers.
Gluware said its platform is designed to bring together processes that are typically spread across separate systems.
The service uses Claroty’s xDome platform for medical-device inventory and vulnerability information, while vulnerability data from the MITRE CVE programme is used to match vulnerabilities with components and configurations on individual devices.
For supported devices, Gluware can then use Microsoft’s Update Catalog to identify the relevant Knowledge Base update. Devices containing unsupported components can instead be flagged for compensating controls, according to the company.
The final stage is change management. Gluware said its platform can create a ServiceNow change ticket for each patching action, route it through a hospital’s existing approval process and record the completed change.
“Most hospitals can tell you what’s on their network. Far fewer can tell you which of those devices are actually exposed today, when each one was fixed, and who approved the change,” said Jeff Gray, CEO and Co-Founder of Gluware.
The company said the service grew out of work with The Ohio State University Wexner Medical Center, which was already using Gluware to automate network infrastructure and had visibility into its connected medical-device fleet.
There’s plenty of other editorial on our sister site, Electronic Specifier ! Or you can always join in the conversation by commenting below or visiting our page.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
