The new solution extends Gluware’s network automation platform to connected medical devices, aiming to close remediation gaps between vulnerability disclosure and documented patch.


Gluware has released Gluware IoMT Exposure Management, a new solution that extends the company’s automation platform to the Internet of Medical Things (IoMT), including infusion pumps, imaging systems, patient monitors, and clinical workstations. The solution automates the remediation workflow that follows a published vulnerability, matching common vulnerabilities and exposures (CVEs) to affected devices, identifying applicable patches, and executing changes within a hospital’s existing approval and audit processes.

The launch targets a persistent gap in healthcare cybersecurity operations. While hospitals have adopted capable tools for identifying vulnerabilities, the remediation workflow has largely remained manual, coordinated through spreadsheets, email threads, and ticketing systems, according to a release from Gluware. Unlike a laptop, a vulnerable medical device cannot simply be taken offline, requiring coordination with clinical schedules, backup equipment, and change documentation that will withstand regulatory scrutiny.

A Growing Backlog of Medical Device Vulnerabilities

The volume of disclosed vulnerabilities has outpaced the infrastructure hospitals depend on to act on them. CVE submissions rose 263% between 2020 and 2025, according to the National Institute of Standards and Technology.

That backlog is evident in hospital device fleets. According to Ordr’s 2026 medical device research, the average connected medical device carries 6.2 known vulnerabilities, roughly 75% of infusion pumps carry a vulnerability listed in the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, and roughly 60% of the installed base runs components no longer receiving manufacturer support.

The financial stakes for healthcare organizations remain significant. Healthcare has been the costliest industry for data breaches for more than a decade, averaging $7.42 million per incident, according to IBM’s 2025 Cost of a Data Breach Report.

Extending an Existing Platform to a New Device Class

Gluware IoMT Exposure Management is built on the same automation engine the company deploys across enterprise network infrastructure, and on device interaction and automation layer, a semantic translation layer proven across 56 operating systems and 22 vendors. The company positions the offering as an extension of an existing platform rather than a new point solution requiring separate integration.

“Most hospitals can tell you what’s on their network. Far fewer can tell you which of those devices are actually exposed today, when each one was fixed, and who approved the change,” says Jeff Gray, CEO and co-founder of Gluware, in a release. “Hospitals shouldn’t have to stand up a separate platform and a separate team to protect the devices closest to patient care. We’ve spent nearly two decades closing that gap on enterprise networks, under the kind of change control that clinical environments demand.”

A Five-Stage Remediation Pipeline

The solution connects five stages into a single workflow:

  • Clinical-grade discovery. Gluware uses Claroty xDome as the source of truth for IoMT inventory, pulling in device details and associated vulnerability relationships rather than establishing a parallel inventory.
  • Component-level vulnerability matching. CVEs are enriched with data from the MITRE CVE Program and matched to the specific components and configurations on each device, with the goal of reducing false positives and false negatives.
  • Advisory-to-patch translation. Through integration with the Microsoft Update Catalog, the platform retrieves the specific Knowledge Base update for each supported platform and flags components no longer receiving manufacturer support, where a compensating control may be the best available option.
  • A shared operational record. A new IoT Device Manager gives clinical engineering and IT teams a continuously updated view of the device fleet.
  • Change-controlled execution. Gluware’s Network RPA and ServiceNow integration open a change ticket for every patch action, route it through the hospital’s existing approval process, and record the completed action.

Development with Ohio State’s Wexner Medical Center

The solution grew out of work with The Ohio State University Wexner Medical Center, which was already running Gluware to automate its network and had established visibility into its IoMT fleet. Remediation, however, was still being coordinated by hand across teams and systems that were not designed to work together, and known vulnerabilities stayed open longer than intended.

Siji Atekoja, deputy CIO and CTO at the academic medical center, identified an opportunity to extend the network automation platform his teams already used into medical device remediation. Gluware and Ohio State jointly built the workflow that connects the medical center’s existing device inventory to automated vulnerability matching, patch identification, and change-controlled execution. That work became the basis for Gluware IoMT Exposure Management.

Gluware IoMT Exposure Management is available now through an early access program. Healthcare organizations interested in participating can contact their Gluware representative to schedule a working session.

ID 44963439 © Sudok1 | Dreamstime.com