We are excited to announce the release of Anchore Enterprise v6.1, built specifically to operationalize your SBOM data for instant blast radius analysis when a zero-day hits. We also added scan coverage for virtual machines and expanded the unified asset model to address global compliance regulations such as EU CRA.
A critical zero-day drops. The clock starts immediately, and the first question your team has to answer isn’t “how do we patch this?” It’s “where does this even exist in our environment?”
That question is harder than it should be. Traditional vulnerability management answers it with a full-environment scan, kicked off after the CVE is already public. Across thousands of container images, VMs, and third-party packages, that scan is slow, noisy, and full of false positives. Remediation stretches from hours into days or weeks, and your MTTR absorbs every bit of that delay. Meanwhile, the exposure window stays open.
Leveraging Your SBOM Catalog for Instant Blast Radius Analysis
To collapse MTTR from weeks to minutes, we must fundamentally shift how we manage software risk. Vulnerability identification can no longer be an ad-hoc search; it must be an ongoing, indexable query powered by complete software visibility. This is where Software Bills of Materials (SBOMs) stop being passive compliance artifacts and become the primary operational source of truth.
Anchore Enterprise continuously captures, centralizes, and queries comprehensive SBOMs across the entire software estate. Security teams gain instantaneous visibility into every component, layer, and dependency version. When a new vulnerability emerges, you no longer need to trigger heavy, time-consuming re-scans across your infrastructure. Instead, you instantly cross-reference new threat intelligence against your central SBOM catalog to pinpoint the exact blast radius and direct engineering teams straight to the fix.
With the EU CRA’s vulnerability and incident reporting obligations coming into force on September 11, 2026, having SBOMs constructed for all of your applications is paramount. Anchore enables your teams to satisfy external audits and meet industry regulations without the traditional friction.
Key Features Powering Anchore Enterprise v6.1
Vulnerability Search to Assess Zero-Day Impact (Blast Radius)
Leverage SBOM-powered asset indexing and our new Vulnerability Search feature to rapidly assess the blast radius of emerging zero-day vulnerabilities across container images, filesystems, and virtual machines. By querying your centralized catalog against newly published vulnerability feeds, security and operations teams can instantly filter and pinpoint every affected application across the organization. This bypasses manual inventory guesswork, enabling teams to isolate risks, prioritize remediation, and verify compliance status in minutes.
Unified Asset Model for Global Compliance
Establish a normalized view across the entire SDLC with one-click generation of unified SBOMs. This directly addresses EU CRA Annex I requirements, ensuring you maintain precise, auditable documentation of software components and their dependencies across your entire footprint.
Scan Coverage for Virtual Machines and More
Achieve true “shift-left” security by detecting vulnerabilities and compliance gaps earlier in development. With native filesystem scanning for virtual machines, source repositories, and build artifacts, Anchore ensures complete SBOM visibility for both containerized and traditional workloads.
Precision Triage with Anchore Score & VEX
Streamline vulnerability management by prioritizing real-world risk over static severity scores. By combining Anchore Score (our multi-factor risk index) with VEX (Vulnerability Exploitability eXchange) annotations, teams can instantly isolate the small fraction of exploitable vulnerabilities requiring immediate action while purging false positives, ensuring compliance with strict CRA and SEC vulnerability reporting rules.
Centralized Third-Party SBOM Management
Import vendor-provided SBOMs in CycloneDX and SPDX formats to extend full lifecycle visibility into software you didn’t build. This simplifies compliance with emerging supply chain transparency standards and ensures end-to-end security integrity.
Continuous Monitoring & Automated Reporting
Maintain continuous oversight of your compliance status with automated notifications triggered by vulnerability status changes. Anchore v6.1 supports POA&M-as-code, allowing organizations to manage allowlists and remediation plans directly within existing security workflows.
Shift-Left and Shield-Right
Anchore Enterprise v6.1 is designed to integrate seamlessly into existing CI/CD workflows so developers can find and fix issues early in the SDLC (shifting left), while giving security teams complete visibility and governance across production environments (shielding right).
- Enterprise Scalability: Built to handle the rigorous demands of the world’s largest software ecosystems without compromising performance.
- Proactive Compliance: Stay ahead of regulatory requirements, such as the US Cyber Executive Order and the EU CRA, with automated SBOM generation.
- Operational Efficiency: Eliminate “vulnerability fatigue” by using data-driven prioritization to focus on the small percentage of risks that actually impact your environment.
For additional information, please visit our release documents or contact our team for an in-depth demo.