Wazuh Weekly Vulnerability & Patch Report Automation
Stop copying CVE IDs into spreadsheets every Monday.
This plug-and-play n8n workflow reads your Wazuh Vulnerability Detector inventory, enriches it with NVD facts, CISA KEV (actively-exploited) and EPSS (exploit-probability) threat intel, has a local AI (Ollama) write plain-language patch instructions, and emails a boardroom-ready HTML report + PDF automatically, every week.
It doesn't just list vulnerabilities. It ranks them by real risk (actively exploited first, not just CVSS), tells your engineers exactly which packages to upgrade to clear the most CVEs at once, and explains the risk in language a CISO can forward upward.
Private by design: the AI runs on your own hardware via Ollama. Your vulnerability data never touches the cloud, and there are zero per-token costs.
⚡ Import the JSON, attach your credentials, run. First report in ~15 minutes.
What's inside
- ✅ Complete n8n workflow (18 nodes, import-ready)
- ✅ Step-by-step setup guide (~15 min to live)
- ✅ Full configuration reference — filter by client, agent, severity, or detection window
- ✅ Sample report you can preview in your browser right now
- ✅ Bonus: client-facing threat-intel glossary + power-user recipes (Slack alerts, per-client MSP scoping, week-over-week deltas)
Built for
- MSPs reporting to clients
- SOC teams killing weekly toil
- security consultants adding recurring-revenue reporting
- homelabbers who want enterprise-grade output.
Requirements
- n8n (self-hosted or cloud)
- Wazuh 4.x with Vulnerability Detector
- Ollama
- Gmail or any SMTP
- All enrichment APIs are free
30-Day Guarantee
If it doesn't work for your setup, reach out and I'll help you troubleshoot. If we can't get it running, you get a full refund. No questions.