Prioritizing alerts: exploitation evidence and exposed assets

Combine KEV, vulnerability records and vendor guidance into an asset-based remediation queue.

Contents of this article

Severity and exploitation are different

KEV identifies vulnerabilities with exploitation evidence, while CVSS base scores describe technical severity. Prioritize an exploited, exposed entry point for investigation, but do not interpret absence from KEV as proof of safety.

Reconcile records by identifier

Match vendor, NVD, CNNVD and CERT/CC records by CVE identifier. Record the product branch, affected configuration, fix and revision date. Keep attribution for differing assessments and follow the vendor’s instructions for the installed branch.

Four questions for the work queue

Check whether the asset is affected, whether it is reachable from untrusted networks, whether exploitation evidence exists, and which identities or services are at risk. Put ownership, temporary containment and completion criteria in one ticket; do not present federal deadlines as universal customer obligations.

Close the ticket with evidence

Retain before-and-after versions, node coverage, restart results and regression checks. Track credential or session recovery where relevant. Blocking records can support containment; they do not prove the host is clean or the patch effective.

References

CISA KEV catalog

FIRST CVSS v4 user guide

NVD vulnerability detail guidance

CNNVD

Continue reading

Read related content

Back to industry insights Contact technical support