How to Find the Last Detected Date in Defender Vulnerability Management
Question details
The user needs to clarify the meaning of vulnerability timestamps (such as First Detected and Updated On) and determine how to find the most recent detection date in Microsoft Defender Vulnerability Management.

- Product
- Microsoft Defender Vulnerability Management
- Device & OS
- not provided
- Scenario
- Reviewing security reports to determine the exact latest date a specific vulnerability was detected by the system scanner.
- Observed behavior
- The dashboard displays Published On, First Detected, and Updated On dates, causing confusion over which field accurately represents the latest vulnerability detection scan.
Ensure you have the necessary Security Reader or Security Administrator permissions in the Microsoft 365 Defender portal to access vulnerability inventory and device scan records.
Analyze Defender Timestamp Fields
Understand how Microsoft Defender categorizes its vulnerability dates to interpret the latest detection activity.
Microsoft Defender Vulnerability Management tracks vulnerabilities using three primary time fields. To understand recent scan activity, you must interpret how the system updates these specific columns.
While 'Published On' refers to the global CVE release date and 'First Detected' marks the initial discovery on your network, the 'Updated On' field is generally the closest indicator of recent status changes or subsequent scan confirmations.
Log in to the Microsoft 365 Defender portal and navigate to 'Vulnerability management' > 'Weaknesses' in the left-hand navigation menu.
Locate the specific CVE (Common Vulnerabilities and Exposures) record. Look at the 'Updated On' column, which reflects the last time the vulnerability's status or details were modified by a scanner update.
For more granular data, click on a specific exposed device, navigate to the 'Timeline' tab, and filter by 'Vulnerability' to see the precise timestamp of the last scanner detection event for that machine.

Consult the Microsoft Defender Community
Seek direct clarification from Microsoft engineers regarding complex backend scanner activity and timestamp updates.
Manage Your Security Reports with WPS Office
While you manage your organization's security with Microsoft Defender, you may also need a lightweight, cost-effective solution for handling exported vulnerability reports and daily business documents. WPS Office is a powerful, free alternative to Microsoft Office.
- 1. Download WPS Office: Visit the official WPS website and download the free installation package for your operating system.
- 2. Install the Software: Run the installer and follow the on-screen prompts to set up WPS Office on your device.
- 3. Open Your Reports: Launch WPS Spreadsheet to instantly open, format, and analyze CSV vulnerability exports with advanced filtering tools.

Frequently Asked Questions
What is the difference between 'Published On' and 'First Detected'?
'Published On' refers to the date the vulnerability (CVE) was publicly disclosed by security researchers worldwide. 'First Detected' indicates the exact date and time the vulnerability was initially found on a device within your specific organizational network.
Can I export vulnerability detection dates for reporting?
Yes. In the Microsoft 365 Defender portal, you can select your vulnerabilities or exposed devices list and click the 'Export' button. This generates a CSV file containing all timestamps, which you can easily analyze using spreadsheet software like WPS Spreadsheet.
Why does the 'Updated On' date change even if no patch was applied?
The 'Updated On' field can change if the backend threat intelligence receives new metadata regarding the CVE (such as a change in the CVSS score) or if a routine background scan simply re-verifies the ongoing presence of the vulnerability.




