Prioritizing alerts: exploitation evidence and exposed assets
Combine KEV, vulnerability records and vendor guidance into an asset-based remediation queue.
Contents of this article
Severity and exploitation are different
KEV identifies vulnerabilities with exploitation evidence, while CVSS base scores describe technical severity. Prioritize an exploited, exposed entry point for investigation, but do not interpret absence from KEV as proof of safety.
Reconcile records by identifier
Match vendor, NVD, CNNVD and CERT/CC records by CVE identifier. Record the product branch, affected configuration, fix and revision date. Keep attribution for differing assessments and follow the vendor’s instructions for the installed branch.
Four questions for the work queue
Check whether the asset is affected, whether it is reachable from untrusted networks, whether exploitation evidence exists, and which identities or services are at risk. Put ownership, temporary containment and completion criteria in one ticket; do not present federal deadlines as universal customer obligations.
Close the ticket with evidence
Retain before-and-after versions, node coverage, restart results and regression checks. Track credential or session recovery where relevant. Blocking records can support containment; they do not prove the host is clean or the patch effective.
References
NVD vulnerability detail guidance
