SOLUTION 03 · For vulnerability management and platform engineering

Your CVE list is long. Your patch window isn't. Which forty?

Severity describes the wound. It says nothing about whether the shot is being fired. The distance between those two facts is where every "we knew about that one" post-mortem lives, and it is closed with exploitation evidence rather than with a bigger spreadsheet.

01Why it keeps happening

The four places the current answer runs out

Everything is critical, so nothing is

A quarter's worth of CVSS 9.x findings arrives with no ordering inside the tier. The team patches by whatever the scanner sorted first, which is a proxy for nothing.

KEV tells you it is too late

A KEV listing is confirmation that exploitation is already happening in the wild. It is authoritative, and by the time it lands the window has been open for weeks.

The scanner does not read the forums

The strongest early signal, someone selling a working exploit for the appliance on your edge, appears in a language and a venue your vulnerability stack has no access to.

Nobody signs off on "I feel it is urgent"

Moving a patch out of the maintenance window costs political capital, and "trust me" is not an argument that survives a change-advisory board. Evidence is.

02How it got here

How prioritization learned about the real world

Each signal was an improvement, and each one is still blind to the layer below it. The market prices exploitation before any public catalogue records it.

THREAT EVOLUTION

EACH ERA STACKED ON THE LAST

  1. 2005-2018

    Severity as destiny

    CVSS assigns a number to how bad exploitation would be, and the industry sorts by it. Everything scoring 9.8 is equally urgent, which in a year with thousands of them means nothing is.

  2. 2019-2023

    Probability and proof

    EPSS estimates the chance of exploitation in the wild; CISA KEV records that it happened. Both are enormous improvements, and both are lagging indicators of a market that moves first.

  3. YOU ARE HERE

    2024-2026

    The exploit market sets the clock

    A private exploit is offered, priced and escrowed; then it is bundled into a kit; then a partnerka ships it to affiliates. Each stage is visible in the channels, and each one moves your patch window before any catalogue notices.

  4. Next

    Machine-speed weaponization

    The interval between an advisory and a working exploit keeps shortening as tooling automates the derivation. The scoring cadence stays the same, so the gap the evidence has to cover keeps growing.

03What we do about it

Four plays, and the window each one runs in

Every play names the module that does the work. Nothing here is a capability we describe without shipping.

Four signals on one page

EPSS probability, KEV membership, exploit maturity and ransomware linkage, merged per CVE. Severity is shown last, deliberately, because it is the least predictive thing on the page.

CVEKIT

The score history, not the snapshot

EPSS is kept as a time series rather than a single number, so a CVE climbing from 0.04 to 0.61 over a fortnight reads differently from one that has sat still. You sort by the movers, which is the thing a nightly score dump cannot tell you.

CVEKIT

Evidence you can attach to the ticket

When your own name or your vendor's appliance turns up in a listing, that post is the argument. The change board is not being asked to trust a feeling; it is reading the thing that made the case, with its screenshot and its timestamp.

DRAGNET

From decision to detection

Where a CVE is on the KEV list and tied to a campaign we track, that campaign carries ATT&CK techniques and Sigma rules, converted on request for Splunk, Sentinel or QRadar. It does not cover every CVE, because the link runs through the campaign rather than the advisory; where it exists, the compensating control ships while the maintenance window is still three weeks out.

MALVEINE

Also drawn onJabbernautTelepathy

Also searchedGuildwire

04In practice

From feed panic to patch plan

Mon 09:00

A new edge-device CVE trends on social feeds. CVSS 9.8, as were four hundred others this year.

Mon 09:04

Cvekit shows EPSS at 0.31 and climbing, no KEV listing yet, and a proof-of-concept published overnight. On the public evidence, this is not yet an emergency.

Tue 14:20

The EPSS movers view has it near the top: the score has crossed 0.80 and exploit maturity has flipped to weaponized. A forum search on the appliance name returns a thread.

Tue 15:00

The patch moves from "next cycle" to "this week". The change ticket carries the score history and the thread, and the board approves it in four minutes.

05What changes

The move, stated plainly

No customer logos and no invented percentages: we have not deployed long enough to have honest ones. What we can state is what the workflow becomes.

Sort by CVSS, patch top-down, hope

Sort by exploitation evidence, and defend the order to the change board

A score is a number you were handed today

A score is a curve, and the ones bending upward are the ones you act on

"It feels urgent"

A dated artefact from a named source, attached to the ticket

Questions

Vulnerability triage, honestly answered

Your competitors will learn about the leak from the invoice.

Learn about it from the log batch.

NDA-friendly briefings · global coverage · no slideware