What the report models
This Vulnerability Detail Report pair contains three synthetic findings for the example reporting period. Each record includes a provider tracking identifier, detection time and source, a description, internet-reachability evaluation, likely-exploitability evaluation, evaluation completion time, and a current numeric rating.
Those fields demonstrate an important FedRAMP 2026 distinction: internet reachability and likely exploitability are separate contextual evaluations. A vulnerable resource does not have to be directly internet-accessible to process a triggering internet-originated payload, and a scanner finding alone does not establish that exploitation is likely in the actual cloud service offering. The three records exercise different combinations of reachability, exploitability, and rating in JSON and HTML.
How to evaluate the example
Use the pair to prototype ingestion, validation, reporting, or reviewer experiences. A reader should be able to identify when a vulnerability was found, understand the provider's contextual evaluation, and follow changes in Potential Agency Impact over time.
Current Vulnerability Evaluation and Reporting rules call for additional decision context where applicable, including historical and current ratings, evaluated reductions, expected next reductions, overdue status, supplementary risk information, and final disposition. Treat this compact sample as a starting point for gap analysis, not a complete production report. Public vulnerability content also requires responsible-disclosure review.
Synthetic example and current status
The CVEs, identifiers, scanner results, components, reachability decisions, exploitability decisions, ratings, and remediation narratives in these 2026-07-27 files are fictional. They do not describe live Boundera vulnerabilities or production security. Refer to the official FedRAMP Marketplace record for current status.