SaaS watchlist
A CVE watchlist for a SaaS stack (not a scanner)
Updated 2026-08-28
How to monitor Okta, Slack, Salesforce, and M365 for exploited vulnerabilities without an agent, CPE database, or vulnerability scanner.
Scanners answer a different question
Tenable, Qualys, and Rapid7 find what is on your network. Snyk and Grype find what is in your repo. Neither knows that your CRM is Salesforce and your identity is Okta unless you also built a vendor inventory. Most mid-market companies have the scanner or the SCA tool. Fewer have a living list of SaaS that hold data, matched daily to KEV.
Build a watchlist in this order
List tools that hold customer data, source code, identity, or payments. Ten names is enough to start; fifty is a generous ceiling. Prefer official product names. Add the obvious parents (GitHub → Microsoft) even if you will later automate that. Subscribe to KEV, not to “all CVEs for Microsoft.”
ZeroDayTracker is that list with a catalog and a graph. Free accounts get three tools and direct matches. Keep Track ($20/month) raises the cap to 50 and turns on supplier fan-out and email digest. You still do not grant us SSO or network access.
What to ignore on purpose
Ignore CVEs for products you do not run. Ignore most HIGH on libraries you do not ship, unless you have SCA for that. Ignore Twitter threads that do not name a CVE. Do not ignore KEV rows that name a cloud host under a tool you listed. That last one is the watchlist’s whole job.
Watch the SaaS that holds your data.
Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.