NEONIX SECURITY FABRICEXPOSURE / APPLICATION / IDENTITY
Security research

Research note · CVE research

CVE research

Why a severity score is not a priority, and how to decide which vulnerabilities to fix first.

Type
Overview and practical guidance
Related products
Cybrmonk, CybrWAF

Overview

A CVE is an identifier for a publicly known vulnerability. CVSS scores describe how severe a flaw is in the abstract. Neither says whether the flaw matters in your environment this week.

Most teams have more vulnerabilities than time. The skill is ordering them.

Key concepts

  1. 01

    Severity is not risk

    A high score on an internal system with no path to it can matter less than a medium score on an internet-facing system that is being exploited.

  2. 02

    Exploitation evidence

    Inclusion in the CISA Known Exploited Vulnerabilities catalog, public exploit code and exploit prediction models such as EPSS indicate which flaws attackers actually use.

  3. 03

    Exposure

    Whether a vulnerable system is reachable from the internet, and by whom, changes urgency more than almost any other factor.

  4. 04

    Business context

    Asset criticality and the data or access behind an asset decide the cost of being wrong.

What good looks like

  • Rank by exploitation evidence and exposure first, then by CVSS.
  • Maintain an accurate inventory, since you cannot rank what you cannot see.
  • Set target times by tier, with exploited and exposed flaws first.
  • Use compensating controls such as virtual patching when a fix cannot ship immediately.
  • Track exceptions with an owner and an expiry date.

Common pitfalls

  • Sorting purely by CVSS.
  • Counting findings instead of reduced exposure.
  • Letting exceptions become permanent.

How Neonix helps

Cybrmonk provides CVE and vulnerability intelligence with exposure context, so findings are ordered by whether they are reachable and actively used.

CybrWAF virtual patching covers web applications while a code fix is prepared.

This note is an overview of the topic and of how Neonix approaches it. It does not report original incident data.