Field Notes

Severity is not priority

September 15, 2026 · Nick Strupp

Every vulnerability scanner I have ever run hands back the same thing: a list, sorted by CVSS, with the 9s and 10s at the top glowing red. It feels like a priority list. It is not one. It is a severity list, and severity is not priority.

CVSS answers one question well: if this flaw were exploited, how bad could it be? That is worth knowing. But it is a property of the flaw in isolation. It does not know whether the vulnerable service faces the internet or sits on a segment no attacker can reach. It does not know whether working exploit code exists. It does not know that a particular CVE is being used in live intrusions this week while a scarier-looking one has never once been weaponized.

So a queue sorted by CVSS will rank a frightening score that nobody has ever exploited above a middling one that is on CISA's Known Exploited Vulnerabilities list, being used in live attacks right now, on a system anyone on the internet can reach. The second one is the fire. Exploited and exposed comes first. CVSS is one input, not the whole score.

What to sort by instead

The order that held up for me was not one number. It was a short stack of questions, taken together:

  1. Is it on CISA KEV? Known exploitation is the strongest signal there is, but it is not the whole answer by itself. An exploited flaw on an internet-facing system goes to the front. An exploited flaw on a segmented box that reaches nothing is ranked by what it can actually touch.
  2. What does EPSS say? The Exploit Prediction Scoring System estimates the probability a flaw will be exploited in the next 30 days. It catches the things heading toward KEV before they land there.
  3. Is the asset exposed, and does it matter? An internet-facing crown-jewel system and a lab box that reaches nothing do not deserve the same urgency, even for the identical CVE.
  4. Then, and only then, CVSS. As a tie-breaker among things that are otherwise equal. Not as the sort key.

None of this makes CVSS useless. It makes it the last input instead of the first.

Why this is hard to adopt

The honest obstacle is not technical. It is that the CVSS-sorted list looks like work getting done. You can show a chart of "criticals closed" and it looks like progress. Re-sorting by real exploitability usually means telling someone that the 9.8 they have been chasing can wait, and that a 6.5 they had ignored needs to ship a patch tonight. That conversation is the whole job.

Get the sort order right and the queue stops being a backlog you can never finish. It becomes a short list of things that are actually on fire, which is a list a real team can actually clear.