An automated check of systems against a database of known weaknesses to identify missing patches and misconfigurations.
A vulnerability scan uses automated tools to compare systems, networks, or applications against a catalogue of known issues. It quickly surfaces missing patches, weak configurations, and exposed services across many assets.
Scanning is broad but shallow: it flags potential issues without proving exploitability, which is where a penetration test goes further. Regular scanning is a baseline hygiene practice.