Knowledge Base

Help Center

Find guides, tutorials, and documentation to get the most out of Hive Pro's Threat Exposure Management platform.

Press /
Getting Started
Integrations
Vulnerability Mgmt
Threat Intelligence
Compliance & SLAs
API Reference
Help Articles

Looking for a way to
manage threats better?

Compliance

Meet SLAs And Compliance Requirements Seamlessly

Discover how Hive Pro's automated SLA tracking and compliance mapping helps your team stay ahead of regulatory requirements. Configure automated workflows that notify stakeholders, generate audit trails, and maintain continuous compliance across ISO 27001, NIST, SOC 2, and more.

ComplianceAutomationSLA
Read Article
Getting Started

Comprehensive Cybersecurity Management

Read Article

A complete guide to Hive Pro's approach to continuous threat exposure management — from initial asset discovery through risk scoring, prioritization, and remediation. This walkthrough covers every stage of the TEM lifecycle, including how to interpret risk scores, configure remediation SLAs, and build executive-ready dashboards that communicate security posture in business terms your stakeholders will understand.

Configuration

Configuring Vulnerability Prioritization Rules

Learn how to set up intelligent prioritization rules that focus your security team on the vulnerabilities that matter most. Combine CVSS scores, exploit intelligence, asset criticality, and business context to build a dynamic risk model that evolves alongside your organization's threat landscape.

VulnerabilitiesRisk ScoringPrioritization
Read Article
Integrations

Integrating Hive Pro with Your Security Stack

Step-by-step guide to connecting Hive Pro with ManageEngine, Tenable, Rapid7, Axonius, and other tools in your environment. Automate data ingestion, enable bi-directional ticket sync, and orchestrate end-to-end vulnerability lifecycle workflows across your entire stack without switching context.

Read Article
Learn & Explore

Related Events

Stay current with the latest webinars, videos, and research from Hive Pro's security experts and partners.

Everything You Need to Know About the Spring Cloud Vulnerability
Blog

Everything You Need to Know About the Spring Cloud Vulnerability

This is a Hive Pro security advisory for CVE-2026-40982, a critical (CVSS 9.8) path traversal flaw in Spring Cloud Config Server's ResourceController. The core problem: a prior fix (CVE-2026-22739) only protected the profile parameter in one controller, leaving three sibling parameters — name, label, and path — unchecked in an adjacent controller. An unauthenticated attacker can send a single crafted HTTP GET request with a traversal sequence in any of those three variables and read arbitrary files off the server. No credentials, no user interaction, network access only. Deployments using a custom ResourceRepository are most exposed, since the built-in repository's fallback check doesn't apply to them. Why it matters: Config Server is the "master keyring" for a microservice mesh, so one file read typically hands over database passwords, cloud provider keys, and JWT signing secrets — enough to pivot into every downstream system, with regulatory fallout under GDPR, HIPAA, PCI-DSS, and SOC 2 / ISO 27001. The bigger narrative is a seven-year pattern: five CVEs in the same module, each fix scoped narrowly to the reported parameter while leaving adjacent ones open. HivePro found this one during BAS exploit development, disclosed it responsibly, and Spring patched all five affected branches (3.1.14 / 4.1.10 / 4.2.7 / 4.3.3 / 5.0.3) within 13 days — before public disclosure, no known exploitation. Recommendation: patch immediately, audit any custom ResourceRepository for path validation, and lock down network exposure regardless of patch status.

Support

Get in touch with us!

Can't find what you're looking for? Our expert security team is available around the clock to help you succeed.

Contact Us

Reduce real exposure. Not just vulnerability volume.