Preview draft · Pending review by the publication’s editor.

Use each signal for its purpose

NVD provides vulnerability information, while CISA’s KEV catalog highlights evidence of exploitation. Neither alone tells you whether a specific asset in your organization is exposed.

Ask about your environment

Record the affected product, installed version, reachable interface and business role. Check official vendor guidance before deciding whether a mitigation applies.

Keep the reasoning visible

Our proposed triage record separates technical severity, observed exploitation, local exposure and remediation status. That makes exceptions easier to explain and revisit when circumstances change.

Sources & further reading

Our practical suggestions are editorial guidance. Verify applicability against current source and vendor instructions.

Suggest a correction →