Workflow for new vulnerability that has no remediation

Would like the ability to trigger a workflow/process if a new vulnerability (detected on an asset) appears that has no remediation (A server has been detected as being vulnerable but there is no remediation to auto map to)


Possibly allowing an incident/email/TSO integration to be generated when a new CVE of a specified severity appears.

For example:

- run a TSO workflow that updates the patch catalogs in TSSA then auto-maps the vulnerabilities

- send an email to the TSSA admins

- create an incident when sev4 or sev5 vulnerabilities appears that don't auto-map


