Your CVE list is long. Your patch window isn't. Which forty?
Severity describes the wound. It says nothing about whether the shot is being fired. The distance between those two facts is where every "we knew about that one" post-mortem lives, and it is closed with exploitation evidence rather than with a bigger spreadsheet.
The four places the current answer runs out
Everything is critical, so nothing is
A quarter's worth of CVSS 9.x findings arrives with no ordering inside the tier. The team patches by whatever the scanner sorted first, which is a proxy for nothing.
KEV tells you it is too late
A KEV listing is confirmation that exploitation is already happening in the wild. It is authoritative, and by the time it lands the window has been open for weeks.
The scanner does not read the forums
The strongest early signal, someone selling a working exploit for the appliance on your edge, appears in a language and a venue your vulnerability stack has no access to.
Nobody signs off on "I feel it is urgent"
Moving a patch out of the maintenance window costs political capital, and "trust me" is not an argument that survives a change-advisory board. Evidence is.
How prioritization learned about the real world
Each signal was an improvement, and each one is still blind to the layer below it. The market prices exploitation before any public catalogue records it.
THREAT EVOLUTION
EACH ERA STACKED ON THE LAST
2005-2018
Severity as destiny
CVSS assigns a number to how bad exploitation would be, and the industry sorts by it. Everything scoring 9.8 is equally urgent, which in a year with thousands of them means nothing is.
2019-2023
Probability and proof
EPSS estimates the chance of exploitation in the wild; CISA KEV records that it happened. Both are enormous improvements, and both are lagging indicators of a market that moves first.
YOU ARE HERE
2024-2026
The exploit market sets the clock
A private exploit is offered, priced and escrowed; then it is bundled into a kit; then a partnerka ships it to affiliates. Each stage is visible in the channels, and each one moves your patch window before any catalogue notices.
Next
Machine-speed weaponization
The interval between an advisory and a working exploit keeps shortening as tooling automates the derivation. The scoring cadence stays the same, so the gap the evidence has to cover keeps growing.
Four plays, and the window each one runs in
Every play names the module that does the work. Nothing here is a capability we describe without shipping.
Four signals on one page
EPSS probability, KEV membership, exploit maturity and ransomware linkage, merged per CVE. Severity is shown last, deliberately, because it is the least predictive thing on the page.
CVEKITThe score history, not the snapshot
EPSS is kept as a time series rather than a single number, so a CVE climbing from 0.04 to 0.61 over a fortnight reads differently from one that has sat still. You sort by the movers, which is the thing a nightly score dump cannot tell you.
CVEKITEvidence you can attach to the ticket
When your own name or your vendor's appliance turns up in a listing, that post is the argument. The change board is not being asked to trust a feeling; it is reading the thing that made the case, with its screenshot and its timestamp.
DRAGNETFrom decision to detection
Where a CVE is on the KEV list and tied to a campaign we track, that campaign carries ATT&CK techniques and Sigma rules, converted on request for Splunk, Sentinel or QRadar. It does not cover every CVE, because the link runs through the campaign rather than the advisory; where it exists, the compensating control ships while the maintenance window is still three weeks out.
MALVEINEAlso drawn onJabbernautTelepathy
Also searchedGuildwire
From feed panic to patch plan
A new edge-device CVE trends on social feeds. CVSS 9.8, as were four hundred others this year.
Cvekit shows EPSS at 0.31 and climbing, no KEV listing yet, and a proof-of-concept published overnight. On the public evidence, this is not yet an emergency.
The EPSS movers view has it near the top: the score has crossed 0.80 and exploit maturity has flipped to weaponized. A forum search on the appliance name returns a thread.
The patch moves from "next cycle" to "this week". The change ticket carries the score history and the thread, and the board approves it in four minutes.
The move, stated plainly
No customer logos and no invented percentages: we have not deployed long enough to have honest ones. What we can state is what the workflow becomes.
Sort by CVSS, patch top-down, hope
Sort by exploitation evidence, and defend the order to the change board
A score is a number you were handed today
A score is a curve, and the ones bending upward are the ones you act on
"It feels urgent"
A dated artefact from a named source, attached to the ticket
Vulnerability triage, honestly answered
The other four
Credential exposure
We do not stop the login. We hold the record that would have made it work, and you can search it today.
Ransomware early warning
The ransom note is the last message in the thread. We read the earlier ones.
Brand & executive exposure
Your executives are discussed in channels they cannot open, in languages your feed does not read.
Fraud & abuse
The chargeback is the symptom. The breach that caused it happened somewhere upstream.
Your competitors will learn about the leak from the invoice.
Learn about it from the log batch.
NDA-friendly briefings · global coverage · no slideware