Finite State is excited to announce a major expansion to our Reachability Analysis feature, delivering broader coverage, smarter prioritization, and dramatically faster performance. These upgrades give product security, DevSecOps, and compliance teams an unmatched ability to cut through vulnerability noise and focus on the risks that matter most.
With this release, Reachability now provides actionable intelligence for more than 90% of detected CVEs, runs, on average, in under an hour, and introduces advanced input vector analysis to significantly improve accuracy, all enabled by default in the Finite State platform.
Our expanded reachability dataset now includes 15,000 additional CVEs, selected based on real customer environments to ensure maximum impact.
What this means for you:
This expansion enables teams to immediately understand where real risk exists — and eliminate the rest from their backlog.
We’ve enhanced our analysis engine to deliver more precise, higher-quality insights.
Our new input vector analysis evaluates dataflow paths from external interfaces (network, file, console, etc.) to potentially vulnerable functions, identifying where exploitation is genuinely possible.
Why this matters:
These insights help teams quickly zero in on vulnerabilities that pose a real exploit risk.
Previously, reachability analysis required opting into our more heavyweight binary SAST scan. With this release, Reachability is fully integrated into our core analysis pipeline and runs automatically.
Key improvements:
This speed boost comes from a redesigned backend that replaces legacy tooling with a lighter, more efficient approach — drastically reducing memory usage and runtime.
Finite State’s exploit intelligence indicates whether a vulnerability is being exploited in the wild. When combined with expanded Reachability capabilities, teams get the most actionable view of risk possible.
You’ll now know:
This unified intelligence allows teams to confidently eliminate non-issues and rapidly escalate the vulnerabilities that pose true operational risk.
These upgrades are designed to help teams:
With expanded reachability capabilities, Finite State now delivers one of the highest-quality vulnerability triage solutions in the connected device security space, differentiated by breadth, depth, and speed.
If you’re a current customer, start a scan today to experience the expanded capabilities.
New to Finite State? Schedule a demo to see how Reachability can help your team prioritize risk with confidence and speed.