What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
What happened
Cohesity's Global Field CISO outlines a vulnerability prioritization framework that ranks active exploitation (KEV) above exploit likelihood (EPSS) and technical severity (CVSS). The guidance recommends a 24 to 72-hour remediation window for exploited, internet-facing assets, noting that organizations must often rely on compensating controls when immediate patching is not feasible.
Why it ranks #1
Cohesity's Global Field CISO published a vulnerability prioritization framework that ranks active exploitation (KEV) above exploit likelihood (EPSS) and technical severity (CVSS), recommending a 24 to 72-hour remediation window for exploited, internet-facing assets.
Who should care
CISOs and security leaders
What to do
Prepare compensating controls, such as restricting access, disabling vulnerable features, or isolating systems, when immediate patching is not possible.
- Impact
- moderate
- Urgency
- immediate
- Confidence
- high
- Scope
- enterprise
- Status
- emerging