Cybersecurity Guide — Vulnerability Management

Not all flaws are equal,
stop treating them the same

CVSS, EPSS, the KEV catalog, MTTR: the vocabulary for turning a long vulnerability list into an actually prioritized — and measurable — remediation plan.

What is vulnerability management?

The continuous cycle of detecting, assessing, prioritizing, and fixing security flaws in an information system. Unlike a one-off audit, it's an ongoing process: new vulnerabilities are discovered every day in software already in production.

CVSS (Common Vulnerability Scoring System)

The reference score (0 to 10) measuring a flaw's intrinsic technical severity — independent of whether it's actually being exploited. Version 3.1 remains the most widely used today; version 4.0 (published late 2023) fixes a known flaw of 3.x: too many vulnerabilities ended up scored 9.8, making the score less useful for prioritization. The two versions aren't directly comparable for the same CVE.

Check a specific CVE's CVSS score

EPSS (Exploit Prediction Scoring System)

Unlike CVSS, which measures theoretical severity, EPSS estimates the real-world probability (0 to 100%) that a flaw will be exploited within the next 30 days, based on threat intelligence signals and CVE characteristics. A CVSS 9.8 flaw with an EPSS near 0% is, in practice, often less urgent than a CVSS 7.0 flaw with an 80% EPSS.

Our built-in EPSS scoring on every scan

The CISA KEV catalog (Known Exploited Vulnerabilities)

A list maintained by the US CISA agency recording flaws whose active exploitation has been confirmed in the wild — not a prediction like EPSS, a fact. A CVE listed here deserves immediate priority, regardless of its CVSS score.

Combining CVSS, EPSS, and KEV to prioritize

CVSS describes technical severity. EPSS estimates what's likely to be exploited next. KEV records what already has been. None of the three alone is enough to prioritize well — combining them gives a far more reliable picture than severity alone for deciding what to fix first.

MTTR and MTTD: the metrics that actually matter

MTTD (Mean Time to Detect) measures the time between a flaw appearing and it being discovered. MTTR (Mean Time to Remediate) measures the time between discovery and it actually being fixed. In practice, MTTR remains the most telling measure of an organization's real risk: a known flaw left unpatched for months is still an open door, no matter how early it was detected.

Patch management

The operational process that actually applies the security fixes vendors publish — testing, scheduling, deploying, verifying. This is often where the real risk lives, not in detection: the gap between a patch being released and it actually being installed is almost always longer than the gap between a flaw's disclosure and its first exploitation.

Setting a remediation SLA by criticality

Rather than handling every flaw at the same pace, a remediation SLA sets differentiated deadlines — for example 48 hours for a critical, actively exploited flaw (KEV), 7 days for a high-severity flaw with a high EPSS score, 30 days for the rest. This is what turns a list of vulnerabilities into an actual, measurable action plan.

See your real vulnerabilities, already scored and prioritized

← Also see: attack surface management

Discover your real vulnerabilities, already prioritized

A free scan, in a few minutes, no credit card required.

Free scan