Vulnerability Management · eBook
ForshTec Systems

Beyond
CVSS

Designing a Threat-Informed Vulnerability Program

From static severity scores to real-world exploitability-driven remediation — a masterclass guide for security leaders navigating the modern vulnerability crisis.

CVSS · EPSS · CISA KEV Asset Criticality Risk Triage Patch Prioritization
~66K
Projected annual vulnerability disclosures in 2026
57%
Asset footprint flagged as emergency by severity-only logic
3%
Vulnerabilities representing true business risk
Complimentary Access
Download the eBook
Share a few details to receive instant access to the full guide.
Something went wrong. Please try again or contact us.

By submitting, you agree to ForshTec's Privacy Policy.

Your download is ready.

Thank you. Your eBook is downloading now. If it does not start automatically, use the button below.

Download the eBook PDF

A copy will also be sent to your email shortly.

The Problem

The Vulnerability Paradox Facing Enterprise Security

Enterprise security teams are caught in a classic red-queen race — running faster than ever, spending more human capital, and exhausting infrastructure teams to patch software, yet the corporate attack surface is not becoming demonstrably safer.

Following a massive 46.3% spike in mid-year disclosures, FIRST revised its full-year projection to approximately 66,000 new CVEs. For a standard enterprise, this translates to evaluating, routing, and remediating roughly 180 new vulnerabilities every single day.

Filtering by high technical severity alone flags roughly 57% of an enterprise's entire asset footprint as an emergency — triggering intense alert fatigue, severe patch burnout, and unnecessary operational downtime.

Crucially, the percentage of vulnerabilities experiencing real-world exploitation remains flat. Attackers don't look at static spreadsheets — they look for the path of least resistance: exploitability, convenience, and reachability.

The Metric Burden — 2026
~66,000
CVEs per year
~180
CVEs per day requiring evaluation
~7.5
CVEs per hour — every hour, every day
~66K
Projected annual vulnerability disclosures in 2026 — a historic high driven by AI-assisted bug hunting
Source: FIRST Mid-Year Vulnerability Forecast, 2026
57%
Of an enterprise's asset footprint flagged as an emergency by severity-only CVSS filtering
Source: ForshTec threat-informed analysis framework
3%
Critical vulnerabilities that represent true business risk when filtered by EPSS, KEV, and asset criticality
Source: EPSS Model v3, FIRST; CISA KEV Catalog
<20%
Remediation effort required using EPSS prioritization to achieve 85–90% threat coverage
Source: EPSS Efficiency Curve, FIRST EPSS User Guide
The Framework

Three Signal Layers That Replace Severity-Only Logic

A threat-informed vulnerability program overlays three complementary data sources to filter operational noise and surface the vulnerabilities that actually threaten the business.

Layer 01

CVSS: Technical Severity

CVSS provides the theoretical blast radius of a vulnerability — the maximum potential damage if exploited. It is a necessary foundation but an insufficient standalone prioritization signal. The framework treats CVSS as Axis 01: Technical Impact from 0.0 to 10.0.

Severity Baseline
Layer 02

EPSS: Exploit Probability

Managed by FIRST, EPSS uses a machine learning model to estimate the mathematical probability (0–100%) that a newly disclosed CVE will be exploited within its first 30 days. EPSS analyzes honeypot activity, deep web discussions, PoC releases, and active attack framework metadata.

Predictive Threat Signal
Layer 03

CISA KEV: Confirmed Exploitation

Where EPSS is predictive, the CISA Known Exploited Vulnerabilities catalog is reactive — tracking CVEs already confirmed to be exploited in the wild. Any vulnerability on the KEV list represents a non-negotiable emergency regardless of its CVSS score. This is ground truth from the US government's threat intelligence apparatus.

Confirmed Active Exploitation
Layer 04

Asset Criticality: Business Context

The final and most important component. A vulnerability's threat profile changes based on the value, exposure, and role of the underlying host. Three dimensions matter: perimeter exposure (internet-facing?), data tier access (production databases, PII?), and identity and control value (domain controllers, jump boxes?).

Internal Business Context
The Engine
Technical Impact
CVSS 0.0 to 10.0
×
Threat Probability
EPSS 0% to 100% + CISA KEV

Critical note: Do not simply multiply CVSS × EPSS scores. Because EPSS scores typically cluster near the low end, simple multiplication artificially depresses the risk profile of dangerous vulnerabilities. Instead, plot them on a coordinate matrix — two separate axes that must intersect to trigger a patch action.

Risk Routing

Four Actionable Risk Tiers

Every discovered vulnerability must automatically route into one of four operational tiers. These tiers dictate the strict remediation workflows for infrastructure teams — eliminating the endless backlog of undifferentiated emergencies.

Confirmed Active

Tier 1: Immediate Emergency

High or medium CVSS scores confirmed to be actively exploited via the CISA KEV catalog, residing on a public internet-facing asset. Non-negotiable emergency — standard maintenance windows are bypassed and remediation begins immediately.

Imminent Threat

Tier 2: High Priority

High technical severity with an EPSS score greater than 0.50, located on critical internal production networks. Not yet on the KEV list, but mathematical indicators suggest an exploit is imminent. Scheduled for the next rapid deployment cycle.

Low Threat Signal

Tier 3: Scheduled Remediation

CVSS critical (9.0–10.0) but with low real-world threat indicators — EPSS below 0.10 and absent from the CISA KEV catalog. High theoretical blast radius but no active exploit path. Handled during standard monthly or quarterly maintenance windows.

Negligible Threat

Tier 4: Defer and Monitor

Low or medium severity vulnerabilities with negligible threat indicators residing on isolated test environments, sandboxes, or non-production assets. Security operations logs these flaws, accepts the current risk, and monitors for future threat changes.

What's Inside

A Masterclass Guide for Security Leaders

Technical depth and strategic clarity for CISOs, vulnerability management teams, and security engineers ready to move beyond the legacy CVSS checklist.

The Crisis of the Legacy Playbook

Why CVSS-only prioritization causes structural gridlock, the 66K disclosure projection, and the mathematical breakdown of daily CVE burden facing security operations teams.

Chapter 1

The EPSS Efficiency Curve

How EPSS machine learning models achieve 85–90% threat coverage with under 20% of the remediation effort, compared to the large wasted footprint of CVSS-only patching programs.

Chapter 2

CISA KEV: The Ground Truth Layer

How the Known Exploited Vulnerabilities catalog functions as the reactive complement to EPSS's predictive model, and why KEV membership overrides CVSS severity in every triage decision.

Chapter 3

Asset Criticality Matrix

How to map vulnerability discoveries to a strict host criticality hierarchy across perimeter exposure, data tier access, and identity and control value — the internal business context layer.

Chapter 4

Dual-Axis Prioritization Matrix

Designing the coordinate model that plots technical severity against threat probability to separate high-impact actively-targeted vulnerabilities from high-impact unweaponized ones.

Chapter 5

Achieving True Operational Efficiency

How the combined framework narrows 57% asset emergency footprint down to the critical 3% representing true business risk — reducing alert fatigue and building a predictable remediation pipeline.

Chapter 6
The Outcome

From 57% Noise to 3% Signal

Transitioning from a legacy severity checklist to a threat-informed vulnerability program represents a fundamental shift in corporate defense. When an enterprise filters its daily scan telemetry through the combined lens of CISA KEV, EPSS probability, and asset reachability, the operational noise drops immediately.

Instead of forcing IT infrastructure teams to struggle with an unmanageable backlog flagging over half the company's assets as emergencies, this model narrows focus to the critical 3% of vulnerabilities that pose a real-world threat.

This targeted approach dramatically reduces alert fatigue, eliminates friction between security and IT teams, and ensures that limited engineering hours are spent where they will have the greatest impact on protecting the business.

A modern vulnerability program is not measured by the sheer volume of patches applied or the number of compliance checkboxes cleared. It is measured by the speed and efficiency with which an organisation can neutralize active, weaponized threats.

Remediation Focus Shift
57%
Asset footprint flagged as emergency by severity-only CVSS logic — creating an unmanageable daily backlog
3%
True business risk — vulnerabilities with confirmed exploitation, high EPSS, and critical asset exposure
Technical severity + live threat intelligence + asset reachability → predictable, scalable remediation that protects the business.

Ready to Build a Threat-Informed Vulnerability Program?

Download the complete eBook and get the framework, methodology, and prioritization matrix your security team needs to move beyond CVSS and focus on the vulnerabilities that truly threaten the business.