Future Corporation (Headquarters: Shinagawa-ku, Tokyo; President and CEO: Tomohiko Taniguchi; hereinafter 'Future') has updated its vulnerability management solution 'FutureVuls' to include new features such as 'Software Health,' which evaluates the health of in-use open-source software (OSS) using objective indicators. Starting June 3, 2026, this update enhances FutureVuls' capabilities as a centralized platform for managing the overall health of the software supply chain by enabling continuous assessment of OSS maintenance status, in addition to detecting and responding to known vulnerabilities (CVE※1).

New Feature: 'Software Health' – Visualizing OSS Health with Objective Scores

Traditionally, vulnerability management has relied on scoring and addressing individual detected vulnerabilities (CVEs) using CVSS. However, the environment surrounding enterprise security is rapidly changing due to increasing numbers of detected vulnerabilities, increasingly sophisticated cyberattacks, and operational changes to public vulnerability databases that underpin vulnerability management (※2). There is now a growing demand for continuous evaluation of the overall health of the software supply chain and the establishment of effective risk governance.

Future identifies a critical emerging issue: OSS components that are no longer maintained over long periods despite the absence of an official End-of-Life (EOL) declaration from the developer. Based on Future's proprietary analysis of approximately 16,000 OSS components in production environments, about 10% are officially in EOL status, and an additional 50% are in a state of development stagnation or de facto EOL (※3). These components no longer receive security patches, and the risks hidden within the dependency relationships among systems containing OSS cannot be fully understood through CVE detection alone. Future believes that future security governance must integrate continuous evaluation of OSS health alongside vulnerability detection and response—what it calls 'Software Supply Chain Health Management'—and has implemented this major functional enhancement accordingly.

Analysis Results of Approximately 16,000 OSS Components in Production Environments (Future Research, 2026)

Key Updates in This Release

Since November 2025, FutureVuls has offered functionality to detect and centrally manage OSS components whose support has been officially declared ended, such as through repository archiving or deprecation. This update expands the platform's capabilities as a software supply chain risk management solution by adding health assessment for OSS without clear end-of-life declarations and enhanced SBOM support.

FutureVuls Workflow: Aggregation → Evaluation → Decision → Response, All in One Service

1. OSS Health Assessment: Visualizing Software Health and Detecting 'De Facto EOL'

The management interface displays each OSS component's maintenance status and recommended actions, enabling objective determination of 'Confirmed EOL (EOL-Confirmed)' and 'De Facto EOL (de facto development halt).' The accuracy of official EOL detection has also been improved by re-evaluating based on primary information sources (※4). To detect 'De Facto EOL,' Future employs its open-source tool 'uzomuzo-oss' (※5), which automatically classifies OSS lifecycle stages into multiple phases.

2. Visualizing Library Dependencies

Dependency relationships are now distinguishable as 'direct' or 'indirect' dependencies. When a vulnerability exists in an indirectly dependent OSS component, the platform enables reverse lookup of the originating direct dependency library on-screen, significantly reducing the investigation effort required to determine remediation strategies.

3. Expanded Information Sources: Support for European Databases (EUVD / ENISA KEV)

To support compliance with the Cyber Resilience Act (CRA), which comes into effect on September 11, 2026, FutureVuls now incorporates the European Union Vulnerability Database (EUVD) as a new vulnerability information source. Additionally, the threat intelligence ingestion scope now includes ENISA KEV from Europe, alongside existing CISA KEV and VulnCheck KEV.

4. Enhanced SBOM Support: Registration of Private EOL Information and Tool-Agnostic SBOM Ingestion

To facilitate practical SBOM implementation and risk assessment, FutureVuls now allows organizations to register and centrally manage EOL information for proprietary products and commercial software not listed in open-source databases like endoflife.date, keeping the data private per organization. SBOMs generated by tools not officially supported by FutureVuls can also be ingested, provided they comply with standard specifications (CycloneDX / SPDX).

Future will continue to enhance FutureVuls' functionality and will persist in publishing technical developments and research findings as open-source. Through the realization of 'Software Supply Chain Health Management' based on objective data, Future aims to contribute to improving the security posture of all organizations.

About FutureVuls

FutureVuls is a solution that enables centralized and automated vulnerability management—including detection, information gathering, response decision-making, task management, and patch application—for a wide range of systems, from operating systems and middleware to libraries. It is the enterprise commercial version of 'Vuls,' which is freely available on GitHub.

'FutureVuls' is a registered trademark of Future Corporation. Product website: https://www.vuls.biz/

※1. Vulnerabilities identified and publicly disclosed via the Common Vulnerabilities and Exposures (CVE) system.

※2. In April 2026, the U.S. National Institute of Standards and Technology (NIST) announced a shift in the operation of the National Vulnerability Database (NVD) toward a risk-based model, classifying unprocessed CVEs (Common Vulnerabilities and Exposures) published before March 1, 2026, as 'Not Scheduled' (no plan for enrichment). The priority for enrichment will be limited to vulnerabilities listed in catalogs such as the Known Exploited Vulnerabilities (KEV) catalog published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

A report by the U.S. Department of Commerce Office of Inspector General (OIG) highlighted that unprocessed vulnerabilities in the NVD increased from approximately 13,000 in June 2024 to over 27,000 by the end of 2025, and the proportion of severity scores aligning with independent assessments remained at only about 12%, revealing the limitations of vulnerability management relying solely on a single information source.

※3. Details of proprietary research on approximately 16,000 OSS components in production environments. https://www.vuls.biz/software-supplychain/eol-risk

※4. Health assessment is based on the latest stable version of the target package, not on individual versions detected within servers.

※5. uzomuzo-oss: https://github.com/future-architect/uzomuzo

FACT BOX

  • Source: PR TIMES
  • Category: New Product
  • Organizations: NIST / CISA / ENISA
  • Products / services: FutureVuls / uzomuzo-oss