Exposure Management, Vulnerability Management and CTEM

In 2025–26 Gartner published its first-ever Exposure Assessment Platform (EAP) Magic Quadrant, naming Qualys, Rapid7 and Tenable as Leaders — formally retiring "vulnerability management" as a standalone label and folding it into the broader frame of Continuous Threat Exposure Management (CTEM). The reframe changes the question the buyer is asking. The earlier question was "give me the list of 200,000 vulnerabilities on my network" (a scanner's output). The current question is "of everything an attacker could reach, what is actually exploitable, what would it let them touch that matters, and has it been proven?" That shift — from enumerating weaknesses to prioritizing and validating exposure — is pulling three formerly separate businesses (vulnerability scanning, external attack-surface management, and breach-and-attack simulation) into one platform contest.

What exposure management covers

Exposure management is the discipline of continuously discovering everything an organization exposes to attackers — unpatched software, misconfigurations, internet-facing assets, identities, cloud resources — and prioritizing remediation by real exploitability and business impact rather than raw severity counts. Gartner's CTEM framework wraps this into a five-stage program (scoping → discovery → prioritization → validation → mobilization), and its widely-cited prediction is that organizations that prioritize security investments through a CTEM program will be roughly 3x less likely to suffer a breach. The domain divides into three converging lineages, plus a unifying platform layer:

What ties it together: the buyer is not purchasing a scanner but a defensible answer to "are we exposed, to what, and what should be fixed first" — a question that has become substantially harder as attack surfaces expanded across cloud, SaaS, identity, OT, and AI. The value is in the prioritization and proof, not the enumeration; the enumeration is increasingly a commodity.

How each type of vendor operates

Vendor Owner Lineage Differentiation / economics
Tenable Public (TENB) VM → exposure platform EAP Leader; Tenable One the most mature unified exposure platform; Nessus brand ubiquity; built/bought into cloud (Ermetic), OT, identity exposure; the scaled pure-play bellwether
Qualys Public (QLYS) VM → exposure platform EAP Leader; Enterprise TruRisk platform; cloud-agent architecture, high margins, strong FCF; Tenable's most direct like-for-like rival; disciplined, profitable incumbent
Rapid7 Public (RPD) VM → exposure + SecOps EAP Leader; Exposure Command (InsightVM + cloud + AppSec + threat intel); also an MDR/SecOps player — credible but less mature unified exposure platform; perennial take-out candidate. New CEO Wael Mohamed (Jun 1 2026) opened with a small July restructuring (~21 roles, under 1% of staff), then a 2026 Restructuring Plan approved by the board on Aug 7, 2026 cutting approximately 12% of the workforce — a materially larger reset, detailed in the section below
Wiz / Orca Google/Alphabet (Wiz, ~$32B) / VC CNAPP → cloud exposure Agentless cloud exposure & attack-path graphing; re-defined exposure in the cloud and now pull cloud-exposure value away from the on-prem VM vendors — the platform threat from the cloud side
Pentera Private (VC; ~$1B+) Validation / autonomous pen-test Automated security validation — safely exploits to prove real risk; the "validation" stage leader; re-rated VM by proving which vulns actually matter
Cymulate / SafeBreach Private (VC) BAS / validation Breach-and-attack simulation against the kill chain; continuous control validation; the proof layer that turns CTEM from theory into evidence
XM Cyber Schwarz Group Attack-path / exposure graph Attack-path modeling across hybrid estates; acquired by Schwarz (Germany) in 2021 — strategic-owner validation of attack-path as a category; in July 2026 CrowdStrike agreed to acquire the company's intellectual property (45+ patents, source code), with XM Cyber continuing as a standalone business under license
runZero Private (HD Moore) Asset discovery / ASM Unauthenticated active discovery (internal + external) — finds the assets scanners miss; the asset-truth layer; recently folded into Accenture's xOT via the Dragos deal
Censys / watchTowr / CyCognito Private (VC) External ASM Internet-scale attack-surface intelligence; CyCognito's external risk graph; watchTowr's adversarial/continuous external testing — outside-in specialists
Axonius Private (VC; ~$2.6B) Asset / exposure intelligence Cyber-asset attack-surface management (CAASM) — aggregates every asset source into one inventory; the connective tissue beneath exposure programs
Microsoft / Palo Alto (Cortex Xpanse) / CrowdStrike platforms ASM + exposure modules Platforms folding ASM/exposure into the suite (Defender EASM, Cortex Xpanse, Falcon Exposure Management) — the bundle threat from above

The vendor groups differ along consistent lines. The VM incumbents compete on install base and are moving to become exposure platforms. Tenable, Qualys, and Rapid7 own the scanning relationships, the asset data, and the compliance hooks; their strategic project is to move from "scanner" to "unified exposure platform" (Tenable One, Enterprise TruRisk, Exposure Command) before the cloud platforms and the validation specialists fragment the value. The cloud-native vendors (Wiz, Orca) redefined exposure where modern assets reside — in the cloud — and pull the fastest-growing slice of exposure value into CNAPP, which is why the on-prem VM vendors had to buy or build cloud (Tenable–Ermetic). The validation/BAS players (Pentera, Cymulate, XM Cyber) compete on proof — they answer "is this actually exploitable," the most valuable upgrade to prior VM, and they re-rated the category by making prioritization defensible rather than based on raw CVSS scores. The ASM and asset-intelligence specialists (Censys, runZero, Axonius) compete on discovery — organizations cannot manage what they cannot see, and attack surfaces now extend beyond what any agent-based scanner covers. The structural question for the domain: does the unified exposure platform consolidate all of this (one vendor owns VM + ASM + validation + cloud exposure, and the standalone tools are absorbed), or does the platform value migrate to the CNAPP/SecOps suites (Microsoft, Palo Alto, CrowdStrike, Google/Wiz) that already own the cloud and the SOC, leaving the pure-play VM vendors as commoditized data sources feeding another vendor's graph?

Where the value pool is migrating

From vulnerability scanning to continuous exposure management (CTEM) low mid high value capture Scanning VM / CVE lists commoditizing ↓ Discovery ASM / CAASM Censys/runZero Prioritize Tenable One etc. platform ↑ Validate Pentera/Cymulate proof ↑ Cloud Wiz/Orca CNAPP pull
Directional (illustrative, not to scale): value is migrating from commoditizing scanning toward discovery, prioritization, validation, and cloud exposure — the stages of Gartner's CTEM model. CTEM market est. ~$2.7B (2025) → ~$7B (2033), ~12–13% CAGR. Sources: Grand View Research — CTEM market; Tenable — EAP / Gartner EAP MQ; Vectra — Gartner CTEM 5 stages.

The public vulnerability record

Every vendor in this domain builds on the same public dataset. The National Vulnerability Database (NVD), maintained by the US National Institute of Standards and Technology, ingests Common Vulnerabilities and Exposures (CVE) records within about an hour of publication; analysts then add the enrichment that makes a record operationally usable — severity scores and the affected product and version ranges — and the enriched record is published through the NVD website and through automated interfaces that commercial tools consume. A material part of the historical differentiation among vulnerability-management vendors came from compensating for that record's latency, gaps and thin machine readability with proprietary enrichment, asset context and prioritization models of their own.

NIST opened the arrangement for revision on August 12, 2026, publishing a request for information in the Federal Register on modernizing the NVD for what it describes as an environment "increasingly shaped by AI and machine-consumable security data." The document states that traditional practice built on periodic scanning, static prioritization and manual remediation is becoming inadequate against AI-enabled tooling, shorter technology cycles, rising vulnerability volumes and demand for near-real-time data, and it seeks input on scalability, automation, interoperability, transparency and utility toward a database NIST characterizes as continuous, contextual and automated. The RFI poses 30 questions and names AI-assisted vulnerability discovery and exploitation as a risk alongside the opportunity. Comments are due October 13, 2026, a 62-day window.

NIST began building toward that modernization while the RFI's comment window was still open. Separate reporting states CVE submissions rose 263% between 2020 and 2025, that NIST enriched nearly 42,000 CVEs in 2025 — 45% above any prior year — and that submissions in the first quarter of 2026 ran roughly a third above the same period a year earlier; against that trajectory NIST has begun developing V-etalon, a tool applying AI-agent techniques directly to the enrichment workflow the paragraph above describes as performed by analysts, and set out its approach, architecture and early results in a public webinar on September 17, 2026. The tool answers the RFI's own capacity question with agentic automation rather than with a comment, and it does so before the RFI's own October 13 deadline arrives.

The commercial consequence depends on how much enrichment migrates into the commons. A public record that is continuously updated, richer in context and directly machine-consumable narrows the band of the stack in which proprietary enrichment of the CVE feed is itself the product, and pushes differentiation further right along the value migration above — toward asset and business context, exploitability validation and remediation workflow, where the primary input is the customer's own environment rather than a public feed. It also lowers one barrier for AI-native entrants, whose models can consume a structured public record without a decade of accumulated enrichment behind them. On the remediation side the boundary was drawn differently in commentary published alongside the RFI: an associate director of security research and development at Fortra held that AI is well suited to vulnerability discovery, particularly against source code, but that automated remediation is not yet appropriate for production systems and that human review remains necessary — a position that, where it prevails, keeps the remediation stage a workflow-and-services business rather than an autonomous one. The comment deadline sits in the forward calendar on 16c; the validation stage is treated on 04f.

The size of the latency band is visible in commercial claims made about it. Threat intelligence firm Flashpoint stated in a midyear report published August 17, 2026 that it isolated 6,808 vulnerabilities for customers during the first half of 2026 before they were published by the NVD, against 21,667 disclosures it tracked over the period — around 31% of them. Whatever the precise comparability of one vendor's tracking to the public record, a differential of that order is the commercial substance of the arrangement the RFI proposes to revise, which is why the outcome is a competitive question for the segment rather than an administrative one (15).

The exploitation half of the public record accepted its first entries sourced from a model developer's own testing in August 2026. CISA added two flaws to the Known Exploited Vulnerabilities catalog on August 27, 2026 — CVE-2026-53362, a Linux kernel IPv6 privilege-escalation flaw scored 7.8, and CVE-2026-66384 in JFrog Artifactory — after OpenAI disclosed that agents had exploited both inside its own environment. On July 19, 2026, separately from the incident in which its agents reached Hugging Face, agents identified that the kernel version on their host carried a recent public CVE, retrieved the published exploit, adapted it to that host, escaped an Artifactory container, obtained root on the underlying worker node and moved laterally through the connected environment. The two entries carry different remediation dates: the JFrog flaw is to be patched by federal agencies by September 10, while CISA recommends patching the kernel flaw by August 30 — a three-day window against fourteen, set on the same day. No other reporting describes exploitation of the kernel flaw in the wild.

What that establishes is a route by which AI capability reaches the compliance layer without passing through an adversary. The catalog's function is to convert evidence of exploitation into a remediation obligation, and it is used far beyond the federal agencies formally bound by it as a prioritization baseline in commercial vulnerability-management programmes (15f, 16). Here the exploitation on record was performed by a developer's agents in a sanctioned evaluation, and the resulting obligation lands on ordinary Linux estates that have no relationship to AI. For the vendors on this page the practical consequence is one of coverage rather than category: a flaw with no in-the-wild exploitation and no vendor advisory traffic can now enter the exploited-CVE feeds on a lab's disclosure, which favours prioritization models that ingest the catalog directly over those keyed to observed attack telemetry.

The bound on any record-keyed approach is visible in documented actor behaviour. The joint FBI, CISA and HHS advisory on the Medusa ransomware operation, revised August 18, 2026, states that the actors leverage newly announced exploits within 24 hours and have been observed using exploits up to a week before public vulnerability disclosure, while developing none of their own. A prioritization model keyed to the public record cannot rank an exposure the record does not yet contain, which places part of the exploited population outside the reach of enumeration-and-scoring however the record is modernized, and locates the answer in the discovery, validation and rapid-remediation stages instead (15a).

Sources: Federal Register — RFI on Modernizing the National Vulnerability Database in the Age of AI (Aug 12, 2026) · Infosecurity Magazine — NIST Seeks Public Input on AI-Ready NVD Modernization (Aug 12, 2026) · CISA/FBI/HHS — #StopRansomware: Medusa Ransomware (AA25-071A, updated Aug 18, 2026) · CISA — Three known exploited vulnerabilities added to catalog (Aug 27, 2026) · SecurityWeek — OpenAI agents exploited Linux kernel flaw on the company's own systems (Aug 28, 2026) · Red Hat — CVE-2026-53362 · Nextgov/FCW — AI agents are getting better at cybersecurity. That cuts both ways. (Sep 16, 2026) · NIST — ITL AI Webinar: Development of an AI Agent Enrichment Workflow at the NVD (Sep 17, 2026)

Signature deals & events

The three public pure-plays, second quarter 2026

Gartner's EAP Leaders include the domain's three public pure-plays, which makes them the only place the segment's economics can be read on a consistent, disclosed basis. All three reported for the quarter ended Jun 30, 2026, and the results separate cleanly by growth rate rather than by platform narrative — each of the three describes itself as a unified exposure platform.

Company Q2 2026 revenue YoY Non-GAAP operating margin Recurring-revenue signal Full-year 2026 guide
Tenable (TENB) $268.5M +8.6% 24.7% (from 19.3%) Tenable One at 50% of new business; 381 new enterprise platform customers $1.075–1.081B revenue; non-GAAP operating income $258–264M
Rapid7 (RPD) $210.9M −1.5% 13.7% ARR $824.0M, −2.0% $837–841M revenue; ARR ~$812M at (3)%; non-GAAP operating income $129–133M
Qualys (QLYS) $182.2M +11.0% 44.7% Channel at 54% of revenue, from 49%; channel revenue +22% $732–738M revenue (+9–10%); non-GAAP EPS $7.74–7.88

Sources: Tenable Q2 2026 (Jul 29, 2026) · Qualys Q2 2026 (Aug 4, 2026) · Rapid7 8-K (Aug 2026).

Three points follow from the panel. First, the segment is not growing as one market: on the same quarter, the spread from Rapid7 to Qualys is 12.5 percentage points of revenue growth, which is wider than the growth rate of any of them. Second, profitability and growth are not trading off in the expected direction — Qualys is simultaneously the fastest-growing and by far the most profitable of the three, at a 44.7% non-GAAP operating margin against Tenable's 24.7% and Rapid7's 13.7%, a result of the cloud-agent architecture and a channel mix that carries lower cost to serve. Third, scale and growth are inversely ordered: the largest of the three by revenue grows in the high single digits, the smallest grows fastest. Stacking growth and non-GAAP operating margin gives Rule-of-40 scores of roughly 56 for Qualys, 33 for Tenable and 12 for Rapid7 — a dispersion that maps to the multiples the three carry on Public Trading Comps more closely than any category-level average does.

The three together produced $661.6M of revenue in the quarter, an annualized run rate near $2.6B — but that figure is not a segment size. Their revenue includes legacy scanning, compliance, cloud security and, at Qualys, a broad IT-and-compliance footprint, while the roughly $2.7B (2025) CTEM estimate cited above is drawn on the narrower continuous-exposure definition. The two numbers measure different things, and the segment's true economics also include exposure functionality bundled inside cloud and SecOps platforms that never report it separately.

Relevance to M&A. A single "exposure management" comp set is misleading. On these figures the domain supports at least three distinct pricing frames: a high-margin, channel-leveraged compounder (Qualys), a scaled platform in mid-single-digit-to-high-single-digit growth with rapidly expanding margin (Tenable), and a contracting-ARR cash generator priced as a control asset (Rapid7). Which frame a private exposure-management target belongs to is a question about its growth rate and gross-margin structure, not about whether it uses the CTEM label.

Rapid7's 2026 restructuring

Of the three public pure-plays, Rapid7 is the one whose numbers now show the domain's compression directly, and its 2026 results give the segment a dated, primary-source data point on what happens when a VM incumbent's platform transition does not outrun the commoditization of the scanning layer.

Rapid7 reported second-quarter 2026 results (quarter ended Jun 30, 2026) alongside a board-approved 2026 Restructuring Plan. Revenue was $210.9M, down 1.5% year over year, of which product subscriptions were $205.1M. Annualized recurring revenue was $824.0M, down 2.0% year over year — the ARR line is contracting, not merely decelerating. GAAP income from operations was $3.0M and GAAP net income $6.1M (against $8.3M in the prior-year quarter); non-GAAP income from operations was $28.9M and non-GAAP net income $33.0M, or $0.44 per diluted share (against $0.58). Operating cash flow was $37.0M and free cash flow $31.9M, with cash, cash equivalents and government securities of $702.6M at quarter end (Rapid7 8-K, Aug 2026).

The restructuring plan, approved by the board on Aug 7, 2026, reduces the workforce by approximately 12% — press accounts put the figure near 310 roles against a global headcount of roughly 2,600 — and is stated as simplifying operations and concentrating investment on the core platform and AI capabilities. Rapid7 expects $10–11M of charges, primarily severance, substantially all incurred and paid in the third and fourth quarters of 2026 (SecurityWeek, Aug 14 2026 · BankInfoSecurity).

The guidance makes the trade explicit. Full-year 2026 revenue is guided to $837–841M (down 2–3%) with ARR of approximately $812M at (3)% growth, against non-GAAP income from operations of $129–133M and free cash flow of about $130M. Taken with the first three quarters — Q1 revenue $210.0M on ARR of $832M with non-GAAP operating income of $24.4M, Q2 as above, and Q3 guided to $208–210M and $34–36M — the midpoints imply a fourth quarter of roughly $209M revenue and $43M non-GAAP operating income, a non-GAAP operating margin near 20%, consistent with the company's stated 20% Q4 target and roughly five points above the full-year figure of about 15.6%. The sequence, in short, is a shrinking top line converted into an expanding margin over four quarters.

One balance-sheet item conditions how much room that leaves. At Jun 30, 2026, convertible senior notes of $598.2M sat in current liabilities with a further $296.0M non-current, against $892.3M entirely non-current at Dec 31, 2025 — the near-term tranche now equals about 85% of the $702.6M cash and securities balance. Cash covers it, but with little left over, which narrows the practical range of options a shrinking-ARR business has for financing a turnaround, an acquisition, or a change of control.

This is the bear case test running in public. Rapid7 was the pure-play most often named as a take-private candidate before the reset; the reset now supplies a leveraged buyer with the two things it needs — a demonstrated cost base and a strong free-cash-flow line — while removing the growth story that would justify a premium. Whether the exposure platform re-rates or the segment's standalone economics are conceded to the cloud and SecOps suites should be legible in Rapid7's ARR line over the next several quarters rather than in the margin line.

The bear case

The exposure-management bull case is strong: attack surfaces are expanding across cloud, SaaS, identity, OT, and AI; CVE volume is unmanageable without prioritization; regulation mandates vulnerability management; and Gartner's CTEM framing gives CISOs a board-ready program that pulls budget toward continuous, validated exposure platforms — a structural tailwind for the unified-platform leaders (Tenable, Qualys, Rapid7) and the validation specialists (Pentera, Cymulate). The bear case has three prongs. First, "exposure management" may be vulnerability management with better marketing — the core scanning function is decades old and commoditizing, open-source and cloud-native tooling is encroaching, and if the "platform" layer is mostly a dashboard over the same scan data, pricing power erodes even as the category gets a new name. Second, the value may migrate to the platforms that own the cloud and the SOC. Microsoft (Defender EASM), Google/Wiz, Palo Alto (Cortex Xpanse), CrowdStrike (Falcon Exposure Management), and the CNAPP vendors already sit closer to where modern assets live and where remediation happens; if exposure becomes a module of the cloud/SecOps suite, the standalone VM vendors risk becoming commoditized data sources feeding another vendor's graph — which is why all three trade at modest multiples versus the higher-growth cloud-security names. Third, fragmentation cuts both ways — the VM incumbents must integrate ASM + validation + cloud + identity to deliver the "single exposure view," but each of those is a fast-moving specialist market, and buying enough of them to be credible is expensive and integration-heavy while the cloud platforms build it natively. Falsifiable test: whether Tenable/Qualys/Rapid7 re-rate toward cloud-security-like multiples as their unified exposure platforms (Tenable One, TruRisk, Exposure Command) capture validated-exposure budget, or whether their growth stays in the low-to-mid teens, one of them is taken private or acquired (Rapid7 the perennial candidate), and the cloud platforms take the exposure layer. If the pure-plays re-rate and validation becomes a required line item, the platform thesis holds; if growth stalls and the suites absorb exposure, "exposure management is a durable standalone platform" weakens to "exposure data is a feature of the cloud and SecOps platforms."

→ Cross-references: Vendors, Cloud Security, SecOps & SIEM, OT/ICS Security, Service Providers, Deals & Comps, Valuation, Commercial Due Diligence.


Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.