Cybersecurity•September 14, 2026• 29 views

OuiHeberg launches free CVE monitoring on its VPS and dedicated servers

OuiHeberg launches free CVE monitoring on its VPS and dedicated servers

A server can run perfectly while using software with a vulnerability that has just been made public. To help you catch these situations, we are adding automatic vulnerability monitoring to our eligible VPS and dedicated servers. It is included at no extra cost and starts as soon as your server is delivered, with nothing to install.

If a known vulnerability is found, you get an e-mail that explains the problem, tells you how serious it is and how to fix it. If you want closer follow-up, an advanced option adds daily scans and alerts in the tools you already use.

Why now

More vulnerabilities are being published than ever. According to NIST, CVE submissions grew by 263% between 2020 and 2025, and the first quarter of 2026 was still nearly a third higher than the same quarter in 2025.

Artificial intelligence is speeding up part of this work by helping researchers comb through code. In March 2026, Mozilla announced 22 CVEs found in Firefox through its work with Anthropic, 14 of them rated high severity, all validated and then fixed. That is good news for security, but it also makes it hard to keep up with everything on your own.

How the monitoring works

A CVE is the public identifier of a known vulnerability in a piece of software. It makes it easy to find the description of the problem and the available fixes.

Our scanner checks your server from the outside, the way an attacker would, and looks for known vulnerabilities in the services it can reach. It handles IPv4, IPv6 and several addresses per server. Scans run again automatically, with no agent and no setup on your side.

It therefore sees what is exposed on the network, not what sits inside the server. It is not a full audit of your files and software.

Recognising our scanner

Scans always come from the same addresses, 82.41.137.56 over IPv4 and 2a0e:4007:fffe:703::257 over IPv6. HTTP requests identify themselves with the User-Agent header OuiHeberg-CVE-Scanner/1.0 (+https://cve-scanner.ouiheberg.com), and the page cve-scanner.ouiheberg.com describes the scanner.

This lets you spot it in your logs. If your firewall or Fail2ban blocks these addresses, the scan will not see your services and cannot alert you.

What comes with your server

  • An automatic scan every 7 days
  • An e-mail alert for each vulnerability found
  • The list of vulnerabilities and the monitoring status in your customer area
  • Support for IPv4, IPv6 and several addresses
  • The option to turn monitoring on or off whenever you like

The advanced option for closer follow-up

This paid option includes everything above. You can add it when ordering or later from your customer area.

One scan a day instead of one a week, at the time you choose.

Alerts in your tools. On top of e-mail, they reach you on Telegram, Discord, Slack, ntfy or by webhook as soon as a scan finds something.

10 on-demand scans a month, handy for checking that an update really fixed the problem without waiting for the next run.

An automatic ticket if a serious vulnerability is still open after several scans. It is there to get your attention, and nothing is changed on your server.

Both plans at a glance

FeatureIncluded monitoringAdvanced monitoring
PriceIncludedPaid option
Automatic scansEvery 7 daysEvery day
E-mail alertsYesYes
Vulnerability list in the customer areaYesYes
IPv4 and IPv6YesYes
Telegram, Discord, Slack, ntfy and webhook alertsNoYes
On-demand scansNo10 per month
Choice of scan timeNoYes
Ticket if a serious vulnerability persistsNoYes

What an alert looks like

The e-mail gets straight to the point. Here is a simplified version.

[OuiHeberg] 1 vulnerability detected on your server

Hello, our security scan has detected a new vulnerability on your server.

Severity critical
CVE reference and description of the problem
Affected address and port

What should you do? Update the affected software or extension to the fixed version given in the alert.

E-mails and the customer area are available in 26 languages. Only the name and technical description of the vulnerability, taken from public databases, may stay in English.

What the monitoring does not do

It warns you, but it does not fix anything for you. It is neither an antivirus nor a firewall, and it does not replace updates, backups or securing your access. A scan with no findings does not guarantee that a server is completely free of vulnerabilities either.

CVE monitoring is available today on eligible VPS and dedicated servers. You will find it in your customer area, and the advanced option can be added at any time.