By Cyber Defense Technologies October 4, 2026 4 min read
A single vulnerability scan of a medium-sized network can return thousands of findings. Even with every finding labeled "critical" or "high," a team cannot fix them all at once. Organizations that patch strictly in order of severity often spend weeks on vulnerabilities nobody is exploiting while an actively exploited flaw on an internet-facing device waits in the queue.
Good prioritization asks three questions: Is this being exploited? Can an attacker reach it? How much would it hurt?
What CVSS does and does not tell you
The Common Vulnerability Scoring System, maintained by FIRST, scores the technical characteristics of a vulnerability on a scale from 0 to 10. Version 4.0, released in November 2023, refined the metrics and added more context about the vulnerable system and its impacts.
CVSS is useful for understanding how bad a vulnerability could be. But the base score most tools display does not account for whether exploit code exists, whether attackers are using it, or whether the vulnerable system is exposed or important in your environment. Large numbers of vulnerabilities score high or critical, and most of them are never exploited in the wild.
The KEV catalog: exploitation already observed
In November 2021, CISA launched the Known Exploited Vulnerabilities catalog alongside Binding Operational Directive 22-01. The catalog lists vulnerabilities with reliable evidence of active exploitation and a clear remediation action. Federal civilian executive branch agencies must remediate KEV entries within set deadlines. For everyone else, KEV is one of the most useful free sources of prioritization data available.
If a vulnerability in your environment is in the KEV catalog, attackers are already using it somewhere. That should put it near the top of the list, especially on systems reachable from the internet. Many recent entries affect edge devices such as VPNs, firewalls and file-transfer appliances, which attackers target because they sit at the boundary and are often less closely monitored.
EPSS: the likelihood of exploitation
The Exploit Prediction Scoring System, also maintained by FIRST, estimates the probability that a vulnerability will be exploited in the wild in the next 30 days, using data about exploitation activity and vulnerability characteristics. Scores are updated daily.
EPSS complements KEV. KEV tells you what is already being exploited; EPSS helps you anticipate what is likely to be exploited soon, across the much larger set of vulnerabilities that are not yet in the catalog.
Fix what attackers will use first
-
1
Known exploited and exposed
In CISA's KEV catalog and reachable from the internet: act within days and look for prior compromise.
-
2
Known exploited, internal
KEV entries on internal systems: fix quickly, before an intruder can use them.
-
3
Likely to be exploited
High EPSS scores or public exploit code: schedule urgent remediation.
-
4
Severe but unlikely
High CVSS with no exploitation evidence and limited exposure: normal patch cycle.
-
5
Everything else
Track, bundle into maintenance, and document accepted risk.
Adding your own context
Public data describes the vulnerability. Only you know your environment:
- Exposure. Is the system reachable from the internet, from partner networks, or only from a segmented internal network?
- Asset importance. Does it support a critical mission, hold sensitive data, or provide administrative access to other systems?
- Compensating controls. Is the vulnerable feature disabled, blocked by a firewall rule or monitored closely?
- Attack paths. Could this vulnerability be chained with others to reach something important?
CISA and Carnegie Mellon's CERT Coordination Center developed Stakeholder-Specific Vulnerability Categorization (SSVC), a decision-tree approach that combines exploitation status, exposure and impact into clear actions such as track, attend or act.
A practical prioritization model
- Known exploited and exposed. Vulnerabilities in the KEV catalog on internet-facing or otherwise exposed systems. Act immediately, within days, and hunt for signs of prior compromise.
- Known exploited, internal. KEV vulnerabilities on internal systems. Fix quickly, because attackers who get inside will use them.
- Likely to be exploited. High EPSS scores, public exploit code, or vulnerabilities in widely targeted products. Schedule urgent remediation.
- Severe but unlikely. High CVSS scores with no exploitation evidence and limited exposure. Fix through normal patch cycles.
- Everything else. Track, bundle into routine maintenance, and accept documented risk where appropriate.
Measuring what matters
Count less and measure better:
- Time to remediate KEV vulnerabilities, especially on exposed systems.
- Number of exposed systems with known exploited vulnerabilities at any point in time.
- Percentage of assets with up-to-date inventory and scan coverage.
- Age of the oldest unremediated high-risk vulnerability.
Frequently asked questions
Should we stop using CVSS? No. CVSS remains the common language for severity. Use it alongside exploitation evidence and context rather than on its own.
What if we cannot patch a KEV vulnerability quickly? Apply the vendor's mitigations, restrict access to the vulnerable service, increase monitoring, and plan replacement if the product is no longer supported.
Does a penetration test help with prioritization? Yes. A test shows which vulnerabilities actually lead to meaningful access in your environment, which is the most direct evidence of risk.
How CDT can help
CDT helps organizations focus remediation where it counts. Our penetration testing and Penetration Testing as a Service show which vulnerabilities lead to real access, our cyber hunt teams look for signs that exposed vulnerabilities were already used, and our hardening engineers close the gaps and reduce exposure.