Out of 48,000 Vulnerabilities Only 1% Are Dangerous: How to Find Them Using CVSS 4.0, EPSS, KEV and FSTEC Methodology
The article is part 10 of the “Vulnerability Management for Beginners” series and focuses on the core challenge of prioritization: out of 48,185 vulnerabilities published in 2025, only about one percent showed signs of real-world exploitation.
Verizon DBIR 2026 reports that exploitation of vulnerabilities overtook stolen credentials as the leading initial access method at 31 percent. Effective prioritization requires complete asset inventory and categorization of every node in the infrastructure.
CVSS alone is insufficient because it measures technical severity rather than actual risk in a specific environment. In 2025 roughly 39 percent of vulnerabilities received high or critical scores, yet the vast majority are never exploited. Additional factors include possible consequences of exploitation, asset criticality, presence of public exploits, attacker accessibility, and trending actively exploited vulnerabilities.
CVSS 4.0, released by FIRST in November 2023, introduced explicit nomenclature such as CVSS-B, CVSS-BT, CVSS-BE and CVSS-BTE, the new Attack Requirements metric, more granular User Interaction values, and a dual impact model separating vulnerable and subsequent systems. However, only 25.9 percent of 2025 vulnerabilities received CVSS 4.0 scores because major sources like NVD still rarely publish them.
In April 2026 NIST announced that NVD would enrich only vulnerabilities in the actively exploited catalog, federal U.S. software, or critical software lists. Approximately 29,000 accumulated records were moved to “not planned for processing,” forcing organizations to rely on vendor scores or calculate their own.
EPSS answers whether a vulnerability will be exploited within the next 30 days using machine learning. Version 4 released in March 2025 added malware telemetry and now observes activity across roughly 12,000 vulnerabilities monthly. A threshold of EPSS greater than 0.1 achieves 63.2 percent coverage with 65.2 percent precision, dramatically better than the common CVSS 7+ approach.
CISA KEV contains vulnerabilities with confirmed exploitation in real attacks. By July 2026 the catalog reached approximately 1,650 entries. The new BOD 26-04 directive introduced risk-based timelines, with the hottest issues required to be remediated within three days. Commercial alternatives such as VulnCheck KEV contain over 3,600 records and detect exploitation on average 27 days earlier.
The article also introduces the experimental LEV metric from NIST CSWP 41 that aggregates historical EPSS scores to highlight older vulnerabilities that were likely exploited but never catalogued. Both EPSS and KEV depend on CVE identifiers, creating limitations for Russian infrastructure where many vulnerabilities lack CVE entries and must be assessed using FSTEC BDU data instead.
Related articles
Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution
GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.
WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM
WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.
Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings
Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.
Google Releases Chrome Update Fixing 11 Vulnerabilities Including Critical WebGL Flaw
Google has issued an update for its Chrome browser that addresses 11 security vulnerabilities across Windows, macOS, and Linux platforms. The release includes Chrome 154.0.8037.98 and 154.0.8037.97 for Windows and macOS, along with version 154.0.8037.97 for Linux. One vulnerability, CVE-2026-103628, received a Critical rating due to an out-of-bounds memory write in WebGL that was originally reported in August. Nine additional issues rated High severity affect components such as FileSystem, Compositing, Skia, FedCM, SVG, MediaStream, and WebRTC, including a buffer overflow tracked as CVE-2026-103631. The update also resolves a type confusion flaw in the V8 scripting engine and one Medium-severity issue. Google plans a gradual rollout over the coming days and weeks.