Observed arrival · 2026-09-13
WaiveWatch Puts an Expiry Date on Accepted Risk
A Jira-focused security tool that watches risk-accepted tickets and sends expired or newly exploitable exceptions back for review.
Field notes
The page separates discovery from exception lifecycle management: scanners such as DefectDojo or Tenable remain responsible for finding vulnerabilities, while the Jira ticket carries the risk decision. An illustrative record includes an accepted-until date, CVE ID, and ticket owner. The proposed nightly process comments on expired issues and transitions them out of the accepted state; a CISA KEV match can instead trigger reopening or escalation and owner notification.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue