OpenVAS in 2026: how the open-source vulnerability scanner works, its ties to Greenbone, feed pricing tiers, and how it compares to Nessus and Qualys.
OpenVAS is a free, open-source vulnerability scanner used to find security weaknesses, missing patches, and misconfigurations across networked systems. It began as a fork of the Nessus engine after Nessus went proprietary in 2005, and has been developed since 2006 primarily by the German company Greenbone.
Greenbone, founded in Osnabruck, Germany, in 2008, layers commercial products, appliances, and support on top of the free OpenVAS core, branding the overall framework Greenbone Vulnerability Management (GVM) since 2017, while OpenVAS remains the name of the open-source scan engine at its heart.
OpenVAS scans network targets against a continuously updated feed of vulnerability tests covering thousands of known CVEs, supporting both unauthenticated network scans and authenticated (credentialed) scans that check for missing patches and misconfigurations at the OS and application level. Results are reported with CVE references and CVSS severity scoring to help teams prioritize remediation.
The broader Greenbone Vulnerability Management framework adds a web-based interface (Greenbone Security Assistant), scan scheduling and reporting, compliance-oriented scan policies, and REST/OSP APIs for integrating scan results into SIEM, ticketing, and other security tooling.
The core OpenVAS scanner and the Greenbone Community Edition are free and open source, giving anyone access to vulnerability scanning without a license fee, though the community feed of vulnerability tests updates on a slight delay compared to paid feeds.
Greenbone also sells commercial tiers on top of the open-source core: OPENVAS BASIC is an entry-level licensed product for small businesses priced below comparable competitor tools, while Greenbone Enterprise appliances and enterprise feed subscriptions for larger organizations are quoted individually; exact pricing for both is only available by contacting Greenbone sales.
Yes, the core OpenVAS scanner and the Greenbone Community Edition are free and open source. Greenbone also sells paid Basic and Enterprise tiers with additional features and faster feed updates.
OpenVAS is the open-source vulnerability scanning engine; Greenbone is the German company that develops it and sells commercial products, appliances, and support built around it, branded as Greenbone Vulnerability Management (GVM).
Yes, OpenVAS originated as a fork of the Nessus scanner after Tenable Network Security made Nessus proprietary in October 2005.
Greenbone AG is headquartered in Osnabruck, Germany, where it was founded in 2008.
Both scan for vulnerabilities using CVE/CVSS-based reporting, but OpenVAS's core is open source and free, while Nessus is a proprietary, commercially licensed product; Greenbone's paid tiers compete directly with Nessus's commercial pricing.
Yes, it includes pre-built scan policies aligned with common compliance and security hardening benchmarks in addition to general vulnerability scanning.
Security teams, penetration testers, and managed security service providers who need CVE/CVSS-based network vulnerability scanning without the licensing cost of a fully proprietary scanner.