← Back to advisories & guidance
December 3, 2025
NCSC
Guidance
Summary
VMS - from GDS, helps UK public sector organisations identify and respond to security vulnerabilities in their internet-facing digital services. VMS goes hand-in-hand with the monitoring already offered by DNS Check (also from GDS). While VMS is an existing service already used by some organisations, what’s new is that GDS and NCSC have partnered to scale access to all eligible organisations via the MyNCSC platform. The service can find internet-facing vulnerabilities including: exposed files, storage buckets and admin panels new and existing CVEs in applications like Microsoft Exchange and ServiceNow software vulnerabilities like XSS and RCE exposed API keys and passwords IP addresses in untrusted locations Checks will continue to be added based on user feedback, with care taken to avoid any service disruption. It queries each service by host and IP address and each open port found.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
No CVEs are referenced in this publication.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.