#vulnerability-management — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulnerability-management, aggregated by home.social.
-
CVSS is a severity label the industry treats like a priority list. A 9.8 tells you how bad a bug could be. It cannot tell you which 9.8 to do first.
This year 4,719 CVEs carry a CVSS v3 score of 9.0 or higher. Half of them, 2,493, land on the identical 9.8, the arithmetic result of a remote, unauthenticated, full-impact vector. Nine distinct scores exist in the entire critical band. There is no 9.5 and no 9.7. That is the resolution you are triaging with.
Rank the same 4,719 by EPSS percentile and the median lands at the 37th, so half the drop-everything tier ranks below 63% of all CVEs. Cut at the 90th percentile and 211 CVEs hold 49 of the 54 now on CISA's KEV list. One caveat: EPSS reads exploitation signal, and all 54 were listed before these scores were computed, so that is two sources agreeing, not a prediction. It still gives you an order. 9.8 does not.
2,493 CVEs this year share one score. If your tooling had to put them in a fix order tomorrow morning, what field would it sort on, and who would argue with you about it?
-
CVSS is a severity label the industry treats like a priority list. A 9.8 tells you how bad a bug could be. It cannot tell you which 9.8 to do first.
This year 4,719 CVEs carry a CVSS v3 score of 9.0 or higher. Half of them, 2,493, land on the identical 9.8, the arithmetic result of a remote, unauthenticated, full-impact vector. Nine distinct scores exist in the entire critical band. There is no 9.5 and no 9.7. That is the resolution you are triaging with.
Rank the same 4,719 by EPSS percentile and the median lands at the 37th, so half the drop-everything tier ranks below 63% of all CVEs. Cut at the 90th percentile and 211 CVEs hold 49 of the 54 now on CISA's KEV list. One caveat: EPSS reads exploitation signal, and all 54 were listed before these scores were computed, so that is two sources agreeing, not a prediction. It still gives you an order. 9.8 does not.
2,493 CVEs this year share one score. If your tooling had to put them in a fix order tomorrow morning, what field would it sort on, and who would argue with you about it?
-
Beginning in September 2026, finding a vulnerability in your commercial software won’t be just an internal issue — it will trigger a tight regulatory countdown under the #CRA.
Building these response networks requires months of architectural preparation. Start now.
❗Review the precise #VulnerabilityManagement expectations: https://cra.orcwg.org/faq/official/reporting/
-
🔴 New security advisory:
CVE-2026-16232 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-16232-check-point-smartconsole-auth-bypass-exploited -
Stop chasing every 9.8 CVSS score! 🛡️ In our latest tutorial, we dive deep into a practical framework for CVE prioritization. Learn how to leverage EPSS, CISA KEV, and asset criticality mapping to focus on real risk. Read more: https://cvedatabase.com/blog/beyond-the-score-a-practical-guide-to-prioritizing-cve-remediation-2026-07-20 #Infosec #CyberSecurity #VulnerabilityManagement #CVE #RiskAssessment
-
282,000+ VEX records are now in Vulnerability-Lookup 🎉
🔎 https://vulnerability.circl.lu/vex
SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.
VEX statements are attached directly to each vulnerability and available via the open API.
🧑💻 https://github.com/vulnerability-lookup/vulnerability-lookup
#VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
-
282,000+ VEX records are now in Vulnerability-Lookup 🎉
🔎 https://vulnerability.circl.lu/vex
SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.
VEX statements are attached directly to each vulnerability and available via the open API.
🧑💻 https://github.com/vulnerability-lookup/vulnerability-lookup
#VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
-
🔴 New security advisory:
CVE-2026-63030 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-63030-wordpress-rest-api-unauth-rce-poc -
🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA)
Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference.
Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry.
If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss!
🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community.
#FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement
https://media.first.org/podcasts/FIRST_Impressions-butera26.mp3 -
🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA)
Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference.
Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry.
If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss!
🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community.
#FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement
https://media.first.org/podcasts/FIRST_Impressions-butera26.mp3 -
📦 gcve 0.12.1 is out — a small maintenance release with updated dependencies.
gcve is a Python client and CLI for the Global CVE Allocation System (GCVE), a decentralized approach to vulnerability identification where multiple GCVE Numbering Authorities can allocate IDs independently, with a cryptographically signed registry.
🔗 https://gcve.eu
🐍 pipx install gcve
💻 https://github.com/gcve-eu/gcve#GCVE #CVE #VulnerabilityManagement #CyberSecurity #Python #OpenSource
-
📦 gcve 0.12.1 is out — a small maintenance release with updated dependencies.
gcve is a Python client and CLI for the Global CVE Allocation System (GCVE), a decentralized approach to vulnerability identification where multiple GCVE Numbering Authorities can allocate IDs independently, with a cryptographically signed registry.
🔗 https://gcve.eu
🐍 pipx install gcve
💻 https://github.com/gcve-eu/gcve#GCVE #CVE #VulnerabilityManagement #CyberSecurity #Python #OpenSource
-
📦 gcve 0.12.1 is out — a small maintenance release with updated dependencies.
gcve is a Python client and CLI for the Global CVE Allocation System (GCVE), a decentralized approach to vulnerability identification where multiple GCVE Numbering Authorities can allocate IDs independently, with a cryptographically signed registry.
🔗 https://gcve.eu
🐍 pipx install gcve
💻 https://github.com/gcve-eu/gcve#GCVE #CVE #VulnerabilityManagement #CyberSecurity #Python #OpenSource
-
🔴 New security advisory:
CVE-2026-15409 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-15409-sma1000-appliance-ssrf-exploited-in-wild -
CISA added 154 CVEs to its Known Exploited Vulnerabilities list so far in 2026. Over half landed within a month of publication, but a stubborn 16% were more than three years old at listing.
I measured the gap from a CVE.org record being published to that CVE landing on KEV. Most move fast: about three-quarters are listed within a year of publication. That tracks with how we picture exploitation: a new bug, a quick confirmation, onto the list.
But 16% break the pattern, more than three years old when CISA lists them, including a 2008 Windows bug (nearly 18 years) and a 2009 Office bug (about 17). Listing dates cannot tell us whether that exploitation is new or long-running, only that CISA confirmed it years after disclosure.
-
Security Tip: Visibility is the first step in supply chain defense. 🛡️
Implementing a Software Bill of Materials (SBOM) allows your team to maintain a machine-readable inventory of all components. When a new vulnerability breaks, you won't be left guessing if you're affected—you'll have the data to act immediately.
Track the latest threats and vulnerabilities at https://cvedatabase.com
#CyberSecurity #InfoSec #SBOM #SupplyChain #CVE #VulnerabilityManagement
-
💣 Un despliegue 100% técnico y sin rodeos... explotación real de vulnerabilidades críticas 👨💻 🌟 Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio 📈 De 8:00 pm a 11:00 pm (UTC -05:00) 🗨️ WhatsApp: https://wa.me/51949304030 🔈 Info: https://www.reydes.com/e/Curso_de_Hacking_Aplicaciones_Web #EthicalHacking #EthicalHacking #AppSec #PenetrationTesting #OWASP #WebDev #VulnerabilityManagement -
PURL was supposed to be the upgrade. A package-native identifier built to describe the open-source packages CPE never handled well. Here is where it actually landed in the CVE feed: about 2% of 2026 CVEs, and most of that from a single third-party CNA.
As CNAs write them, 75% of CVEs carry neither CPE nor PURL. Then NVD and CISA go to work: they backfill CPEs and cut that no-ID pile to 41%. Every point of that improvement is CPE. They add zero PURLs, and not by choice. NVD has no PURL field to fill.
Here is the strange part. PURL is alive and well outside this pipeline, in OSV, GitHub Security Advisories, and every SBOM and SCA tool. It just never made it into the CVE and NVD pipeline that most of the industry still triages from. The problem is not PURL. It is that the feed everyone relies on structurally cannot see it. How long do we keep matching CVEs to assets through a format that cannot name a package?
-
Security Tip: Effective patch management starts with visibility. 🛡️
You can't protect what you don't know exists. Maintain a continuous, automated asset inventory to identify "shadow IT" and legacy systems. Without a clear map of your attack surface, critical vulnerabilities will inevitably go unpatched.
Stay ahead of the threats with real-time intelligence: https://cvedatabase.com
#InfoSec #CyberSecurity #VulnerabilityManagement #CVE #SysAdmin
-
The bugs that get exploited are not the bugs you see most.
I mapped every CVE on CISA's Known Exploited Vulnerabilities list back to its weakness class. Two things stood out.
First, a data-quality one. The organization that reports a bug fills in the weakness class only about a third of the time. On the exploited list, roughly two-thirds of the CNA-authored records leave the CWE blank, and it only reaches about 90% coverage because NVD and CISA's enrichment program (ADP) go back and add it. Pull the class from the CNA feed alone and it is nearly empty. Pull it from NVD or CISA and it is nearly complete. Same bugs, very different picture depending on who you ask.
Now the finding. Using the enriched data, exploitation concentrates in two families. Memory corruption: out-of-bounds writes, use-after-free, buffer errors, type confusion. And code execution: OS command injection, code injection, deserialization. Add improper input validation and broken authentication, and you have most of the list.
Notice what is missing. Cross-site scripting is the single most common weakness on the internet, tens of thousands of CVEs, and it barely registers here. CSRF does not make the top 12 at all. The classes that flood your feed by volume are not the ones attackers reach for.
So "most common" and "most exploited" are nearly different lists, and the CWE data is only as complete as the source you pull it from. Ranking a backlog by volume, or by raw CVSS, points you at the wrong shelf.
Which of these classes is your program actually resourced to find?
-
The bugs that get exploited are not the bugs you see most.
I mapped every CVE on CISA's Known Exploited Vulnerabilities list back to its weakness class. Two things stood out.
First, a data-quality one. The organization that reports a bug fills in the weakness class only about a third of the time. On the exploited list, roughly two-thirds of the CNA-authored records leave the CWE blank, and it only reaches about 90% coverage because NVD and CISA's enrichment program (ADP) go back and add it. Pull the class from the CNA feed alone and it is nearly empty. Pull it from NVD or CISA and it is nearly complete. Same bugs, very different picture depending on who you ask.
Now the finding. Using the enriched data, exploitation concentrates in two families. Memory corruption: out-of-bounds writes, use-after-free, buffer errors, type confusion. And code execution: OS command injection, code injection, deserialization. Add improper input validation and broken authentication, and you have most of the list.
Notice what is missing. Cross-site scripting is the single most common weakness on the internet, tens of thousands of CVEs, and it barely registers here. CSRF does not make the top 12 at all. The classes that flood your feed by volume are not the ones attackers reach for.
So "most common" and "most exploited" are nearly different lists, and the CWE data is only as complete as the source you pull it from. Ranking a backlog by volume, or by raw CVSS, points you at the wrong shelf.
Which of these classes is your program actually resourced to find?
-
🕸️ Curso Hacking Aplicaciones Web 2026 🪓 Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio 🛜 De 8:00 pm a 11:00 pm (UTC -05:00) 👀 WhatsApp: https://wa.me/51949304030 🆗 Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Aplicaciones_Web.pdf #WebSecurity #AppSec #EthicalHacking #PenetrationTesting #VulnerabilityManagement -
🔴 New security advisory:
CVE-2026-56291 affects Balbooa Forms.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-56291-balbooa-forms-unauthenticated-rce-exploited -
🆕 Vulnerability-Lookup now imports Microsoft CSAF VEX documents from MSRC — joining the Red Hat VEX feed as a vendor VEX enrichment source.
Per-CVE VEX statements (product status, severity) are attached directly to CVE records, visible on the vulnerability page and via the API with the full CSAF documents.
Example with both Red Hat and Microsoft VEX:
https://vulnerability.circl.lu/vuln/CVE-2026-53359#vex -
🆕 Vulnerability-Lookup now imports Microsoft CSAF VEX documents from MSRC — joining the Red Hat VEX feed as a vendor VEX enrichment source.
Per-CVE VEX statements (product status, severity) are attached directly to CVE records, visible on the vulnerability page and via the API with the full CSAF documents.
Example with both Red Hat and Microsoft VEX:
https://vulnerability.circl.lu/vuln/CVE-2026-53359#vex -
Stop triaging by bug class.
Here are the 10 most common weakness types, lined up by the CVSS scores they actually get. The ranking looks sensible: injection and memory corruption up in the 7s and 8s (stack buffer overflow tops out at a median 8.5), the high-volume web classes down in the 5s and 6s. Folk wisdom, confirmed.
Then look at the grey band in the middle. Every one of these ten classes, top to bottom, has a stack of vulnerabilities in the same 6.3 to 7.1 window. Pull a CVE scored 6.5 and it could be any of them. The class does not pin the score, and the score does not pin the class.
And the ranking itself is soft. Within a single weakness type the middle 80% of scores spans three to four and a half points, so knowing a bug is "an XSS" or "a path traversal" tells you little about its severity. The category is not destiny either: out-of-bounds read is a memory bug like the top-ranked stack overflow, yet it sits near the bottom.
So a "critical CWE" is not really a thing. The class shifts the odds, but severity lives in the specific bug.
Which weakness class do you think your program over-weights, and which does it wave through?
-
Here we go. Product updates - the June edition.
This month your coverage got a LOT wider.
80 new detections landed in the Network Scanner, including pre-auth RCE in Oracle PeopleSoft and an auth bypass in Palo Alto PAN-OS. If any are in your scope, you know where to look.
The rest of June:
🌐 Our research team found two authentication flaws in phpBB, one buried in the code for over a decade. There's a working PoC for each, and the Network Scanner now detects the most critical one - CVE-2026-48611 (9.4).
🤖 AI where it earns its place in the Website Scanner and URL Fuzzer: smarter logins, deeper crawling, fewer fake 200 pages.
🎯 the XSS Exploiter now gives you two delivery options: script tag or fetch plus eval.
🔌 API: a new info_text key on /scans tells you why a scan didn't start.
☁️ We're now on the Microsoft Azure Marketplace, so you can add us to your existing Azure billing.
Our colleague Stefan Perju walks you through all of it in the video.
Until next time: stay sharp. Stay human.
Everything that shipped can be found in the change-log: https://pentest-tools.com/change-log
The phpBB PoCs and full write-up: https://pentest-tools.com/research/phpbb-authentication-bypass
#offensivesecurity #vulnerabilitymanagement #infosec #penetrationtesting
-
Here we go. Product updates - the June edition.
This month your coverage got a LOT wider.
80 new detections landed in the Network Scanner, including pre-auth RCE in Oracle PeopleSoft and an auth bypass in Palo Alto PAN-OS. If any are in your scope, you know where to look.
The rest of June:
🌐 Our research team found two authentication flaws in phpBB, one buried in the code for over a decade. There's a working PoC for each, and the Network Scanner now detects the most critical one - CVE-2026-48611 (9.4).
🤖 AI where it earns its place in the Website Scanner and URL Fuzzer: smarter logins, deeper crawling, fewer fake 200 pages.
🎯 the XSS Exploiter now gives you two delivery options: script tag or fetch plus eval.
🔌 API: a new info_text key on /scans tells you why a scan didn't start.
☁️ We're now on the Microsoft Azure Marketplace, so you can add us to your existing Azure billing.
Our colleague Stefan Perju walks you through all of it in the video.
Until next time: stay sharp. Stay human.
Everything that shipped can be found in the change-log: https://pentest-tools.com/change-log
The phpBB PoCs and full write-up: https://pentest-tools.com/research/phpbb-authentication-bypass
#offensivesecurity #vulnerabilitymanagement #infosec #penetrationtesting
-
A CVSS score is not a fact about a bug. It is an opinion with a decimal point.
Cross-site scripting is the most common bug on the internet. Here it is scored by 13 different organizations: the same weakness averages about a 3.4 at VulDB and about a 6.7 at Microsoft. Same bug class, same scoring system, more than a full severity band apart.
Most of that spread is really one organization. VulDB sits alone at the bottom while the other twelve cluster between 5.5 and 6.7. So the real question is why VulDB reads the same bugs so much lower.
The biggest reason is not the metric people argue about. It is whether an XSS leaks data at all. VulDB scores confidentiality impact as None on essentially every XSS, treating it as a bug that can alter a page but not read anything. Almost everyone else scores it Low: an XSS can read the page, lift a session token, scrape what the victim can see. That single call is worth about 1.4 points, the largest lever in the whole vector.
VulDB then stacks two more conservative calls on top: it marks XSS as not crossing a trust boundary (Scope:Unchanged) where most others mark it Changed, and it usually requires the attacker to already have some privilege. Each is worth about half as much as the confidentiality call. That is the twist: Scope is the metric the community argues about most for XSS, yet the quieter confidentiality call moves the score twice as far.
None of these orgs is being sloppy. They are applying the same defined metrics to a genuinely ambiguous bug and landing in different places, and no single dial orders them. The number just depends on who holds the pen.
When a CVE carries two different CVSS scores, which one does your program actually use?
-
A CVSS score is not a fact about a bug. It is an opinion with a decimal point.
Cross-site scripting is the most common bug on the internet. Here it is scored by 13 different organizations: the same weakness averages about a 3.4 at VulDB and about a 6.7 at Microsoft. Same bug class, same scoring system, more than a full severity band apart.
Most of that spread is really one organization. VulDB sits alone at the bottom while the other twelve cluster between 5.5 and 6.7. So the real question is why VulDB reads the same bugs so much lower.
The biggest reason is not the metric people argue about. It is whether an XSS leaks data at all. VulDB scores confidentiality impact as None on essentially every XSS, treating it as a bug that can alter a page but not read anything. Almost everyone else scores it Low: an XSS can read the page, lift a session token, scrape what the victim can see. That single call is worth about 1.4 points, the largest lever in the whole vector.
VulDB then stacks two more conservative calls on top: it marks XSS as not crossing a trust boundary (Scope:Unchanged) where most others mark it Changed, and it usually requires the attacker to already have some privilege. Each is worth about half as much as the confidentiality call. That is the twist: Scope is the metric the community argues about most for XSS, yet the quieter confidentiality call moves the score twice as far.
None of these orgs is being sloppy. They are applying the same defined metrics to a genuinely ambiguous bug and landing in different places, and no single dial orders them. The number just depends on who holds the pen.
When a CVE carries two different CVSS scores, which one does your program actually use?
-
Here are two emails that landed in my inbox this morning.
Sent by the @circl Vulnerability-Lookup instance, notifying me about new KEV entries in the excellent @shadowserver KEV Catalog and in the #CISA KEV Catalog.The catalogs are available here (including the link to the original sources):
👉 https://vulnerability.circl.lu/kev-catalogs
As well available via API and RSS/Atom!
📬 And email subscriptions are free!
-
Here are two emails that landed in my inbox this morning.
Sent by the @circl Vulnerability-Lookup instance, notifying me about new KEV entries in the excellent @shadowserver KEV Catalog and in the #CISA KEV Catalog.The catalogs are available here (including the link to the original sources):
👉 https://vulnerability.circl.lu/kev-catalogs
As well available via API and RSS/Atom!
📬 And email subscriptions are free!
-
CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
#CISA #cybersecurity #infosec #patchnow #vulnerabilitymanagement #KEV
-
What does CVSS actually measure? Jay Jacobs, who built EPSS, asked exactly that on LinkedIn and admitted he has never gotten an authoritative answer. 87 comments agreed it is "not risk." None could define "severity."
That is not a CVSS problem. It is a language problem. Our field runs on load-bearing words it never defined.
Held against FAIR, a real risk ontology, CVSS has no frequency term at all, so it structurally cannot be risk. As Sasha Romanosky (@SashaRomanosky) put it, we have "fundamentally lacked that capability as an industry." FAIR and CVSS even use "vulnerability" to mean opposite things: a probability versus the flaw itself.
But CVSS is not fake. It is Ptolemaic: coherent, useful, quietly wrong about its own ontology, like epicycles that predicted the sky for 1400 years on a false model. It is dangerous only when we read severity as risk and build clocks and contracts on the reading.
The fix is already here: CVSS for severity, EPSS for likelihood, KEV for live exploitation, FAIR for loss. CISA's new BOD 26-04 does exactly this. Stop asking one number to be four things.
The Magic Number: https://infosecstoic.substack.com/p/the-magic-number-what-does-cvss-actually
-
CVSS scores are just the beginning. To truly protect your organization, you need a risk-based approach to vulnerability triage. 🛡️ Our new tutorial covers everything from EPSS to asset criticality. Mastering Vulnerability Triage: https://cvedatabase.com/blog/mastering-vulnerability-triage-a-practical-guide-to-assessing-and-prioritizing-c-2026-07-01 #Cybersecurity #VulnerabilityManagement #CVE #Infosec #EPSS #DevSecOps
-
Security teams don't lack visibility — they often lack clarity about which risks matter most. In our latest interview, Filigran's Neena Sharma explains why continuous threat exposure management (CTEM), AI-assisted analysis and human expertise are essential for helping organisations prioritise and respond to the threats most likely to be exploited.
Read the full interview with Neena Sharma here: https://www.techfinitive.com/interviews/neena-sharma-head-of-customer-and-product-marketing-at-filigran-ai-should-make-your-analysts-unstoppable-not-replace-them/
#AI #CISO #CyberThreatPredictions #Cybersecurity #VulnerabilityManagement