Overview
A CVE is an identifier for a publicly known vulnerability. CVSS scores describe how severe a flaw is in the abstract. Neither says whether the flaw matters in your environment this week.
Most teams have more vulnerabilities than time. The skill is ordering them.
Key concepts
- 01
Severity is not risk
A high score on an internal system with no path to it can matter less than a medium score on an internet-facing system that is being exploited.
- 02
Exploitation evidence
Inclusion in the CISA Known Exploited Vulnerabilities catalog, public exploit code and exploit prediction models such as EPSS indicate which flaws attackers actually use.
- 03
Exposure
Whether a vulnerable system is reachable from the internet, and by whom, changes urgency more than almost any other factor.
- 04
Business context
Asset criticality and the data or access behind an asset decide the cost of being wrong.
What good looks like
- Rank by exploitation evidence and exposure first, then by CVSS.
- Maintain an accurate inventory, since you cannot rank what you cannot see.
- Set target times by tier, with exploited and exposed flaws first.
- Use compensating controls such as virtual patching when a fix cannot ship immediately.
- Track exceptions with an owner and an expiry date.
Common pitfalls
- Sorting purely by CVSS.
- Counting findings instead of reduced exposure.
- Letting exceptions become permanent.
How Neonix helps
Cybrmonk provides CVE and vulnerability intelligence with exposure context, so findings are ordered by whether they are reachable and actively used.
CybrWAF virtual patching covers web applications while a code fix is prepared.
This note is an overview of the topic and of how Neonix approaches it. It does not report original incident data.