New IoMT Exposure Management solution automates hospital vulnerability remediation, from disclosure to documented patch
SACRAMENTO, Calif. — September 30, 2026 — Gluware, Inc., the intelligent automation company, today announced Gluware IoMT Exposure Management, bringing its proven automation platform to the Internet of Medical Things (IoMT) — the infusion pumps, imaging systems, patient monitors, and clinical workstations at the center of care delivery. The solution automates what happens after a vulnerability is published, matching CVEs to the specific devices affected, identifying the patches that apply, and executing the changes in line with the hospital’s own approval and audit processes.
Remediation is harder in a hospital than almost anywhere else. A vulnerable medical device cannot be pulled offline the way a laptop can, so patching one means working around clinical schedules and backup equipment. Every change also has to carry an approval and audit trail that will hold up to a regulator. Faced with those constraints, the industry built capable tools for identifying potential vulnerabilities and left the harder half of remediating them to spreadsheets, email threads, and manual ticket entry.
That manual process is losing ground. CVE submissions rose 263% between 2020 and 2025, according to NIST, outpacing the public vulnerability infrastructure hospitals rely on to turn a disclosure into a device-specific alert. The backlog now shows up in the fleet itself: the average connected medical device carries 6.2 known vulnerabilities, roughly 75% of infusion pumps carry one listed in CISA’s Known Exploited Vulnerabilities catalog, and roughly 60% of the installed base runs components no longer receiving manufacturer support at all, according to Ordr’s 2026 medical device research. Meanwhile, healthcare has remained the costliest industry for data breaches for more than a decade, averaging $7.42 million per incident in IBM’s 2025 Cost of a Data Breach Report.
A proven model, applied to a new device class
Gluware IoMT Exposure Management is built on the same foundational automation engine Gluware runs across enterprise network infrastructure, and on DIAL™ (Device Interaction and Automation Layer™), the semantic translation layer proven across 56 operating systems and 22 vendors. This is not another point solution for hospitals to integrate and maintain. IoMT Exposure Management is that platform extended to a new class of devices — the same platform, the same change-control model, and the same team already automating the network.
“Most hospitals can tell you what’s on their network. Far fewer can tell you which of those devices are actually exposed today, when each one was fixed, and who approved the change,” said Jeff Gray, CEO and Co-Founder of Gluware, Inc. “Hospitals shouldn’t have to stand up a separate platform and a separate team to protect the devices closest to patient care. We’ve spent nearly two decades closing that gap on enterprise networks, under the kind of change control that clinical environments demand.”
The solution connects five stages into a single pipeline:
- Clinical-grade discovery. Gluware leverages Claroty xDome as the source of truth for IoMT inventory, pulling in device details and the vulnerability relationships tied to each device rather than standing up a second inventory for hospitals to reconcile.
- Component-level vulnerability matching. CVEs are enriched against data from the MITRE CVE Program and matched against the specific components and configurations present on each device to reduce the false positives and false negatives that erode staff confidence in alerts.
- From advisory to applicable patch. Knowing a CVE exists does not tell a team what to install. Gluware’s integration with the Microsoft Update Catalog retrieves the specific Knowledge Base update for each supported platform and flags components that no longer receive manufacturer support, where a compensating control is the best available option.
- A shared operational record. A new IoT Device Manager gives clinical engineering and IT the same continuously updated view of the device fleet, closing a longstanding gap between two teams that use different tools and different vocabularies.
- Change-controlled execution. Gluware’s Network RPA and ServiceNow integration open a change ticket for every patch action, route it through the hospital’s existing approval process, and write the completed action back as a system of record.
Most of these stages already exist in a large hospital, spread across separate tools owned by separate teams. The delay accumulates in the handoffs between them: the export from one system into another, the cross-reference done by hand, the ticket opened manually and closed without a link back to the device it covered. Running the stages as one pipeline removes those handoffs, transforming the change record into a product of the work itself rather than something reconstructed afterward for an auditor.
Built from a customer requirement
The solution grew out of work with The Ohio State University Wexner Medical Center. The academic medical center was already running Gluware to automate its network and had built visibility into its IoMT fleet. However, remediation was still being coordinated by hand across teams and systems that were never designed to work together. These workflow constraints meant known vulnerabilities stayed open longer than anyone wanted.
Siji Atekoja, Deputy CIO and CTO, saw that the platform his teams already used to change the network safely could carry a medical device the rest of the way — from a published CVE to a patch applied, approved, and on the record. Gluware and Ohio State built that path together by connecting the medical center’s existing device inventory to automated vulnerability matching, patch identification, and change-controlled execution. That work became Gluware IoMT Exposure Management.
Availability
Gluware IoMT Exposure Management is available now through an early access program. Healthcare organizations interested in automating medical-device vulnerability remediation can reach out to their Gluware representative to schedule a working session and join the program. For more information, visit gluware.com.
Share this article
About Gluware
Gluware is an intelligent automation platform for the Agentic Era™. Teams model how infrastructure should work, then safely automate change against it across vendors and domains — so builders can reuse automation, operators can trust it, and leaders can scale without adding risk. Built on DIAL™ (Device Interaction and Automation Layer™), a semantic translation layer proven across 56 operating systems and 22 vendors, Gluware is extending that model from enterprise networks to connected device fleets. Gluware serves Global 2000 enterprises across finance, healthcare, pharma, energy, and government. Gluware, Inc. is headquartered at 500 Capitol Mall, Suite 2350, Sacramento, CA 95814.
Gluware Media Contact
Clayton Murtle
clayton@claytoncole.co