Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Editorial illustration: monitoring workstation and digital asset review
Editorial illustration

Cyber monitoring guide · reading advisories

Prioritise a CVE with the asset context.

A widely reported CVE is not automatically applicable to your environment. Start with the product and version, then combine severity, known exploitation, exposure and business impact to prepare a verifiable remediation decision.

Published 6 October 2026Updated 6 October 2026

At a glance

Four rules for a useful review.

  • Check applicability against the vendor advisory.
  • Separate severity, exploitation and impact.
  • Record the dates of the signals used.
  • Validate remediation on the affected asset.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Connect the CVE to an asset

    Record product, version, component, owner and business role. Check the vendor advisory and exploitation prerequisites. An old public banner does not establish the currently installed version.

  2. 2

    Read severity with its vector

    Retain CVSS version, vector, score source and prerequisites such as privileges or user interaction. A context-free number is insufficient for comparing cases.

  3. 3

    Review exploitation signals

    Consult KEV for known exploitation and EPSS for a thirty-day estimate. Record their dates. An EPSS percentile is a rank, distinct from probability.

  4. 4

    Assess exposure and consequences

    Work with the authorised team to establish component accessibility, prerequisites and affected data or operations. Defensive assessment does not require trying an exploit against a public target.

  5. 5

    Select and verify the measure

    Apply the patch or vendor-recommended temporary mitigation through the change process. Retain validation, functional tests, owner and the review date for temporary measures.

CVSS, KEV and EPSS answer different questions

CVSS describes technical severity. KEV lists vulnerabilities with known real-world exploitation. EPSS estimates exploitation probability over the next thirty days. None alone describes the consequences for your asset.

A low EPSS score does not cancel known exploitation. A CVE missing from KEV may still be exploited. CISA catalog deadlines belong to a US federal framework; define organisational deadlines using your context and obligations.

Document affected and unaffected assets

Preserve the inventory used, actually installed version and advisory passage supporting applicability. An assumption based only on a search result remains unconfirmed.

If the version or prerequisite cannot be checked, retain a pending-verification status. To close as not applicable, record the technical reason and source instead of silently dismissing the alert.

Explain the decision rather than combining scores

Review exploitation, component accessibility, existing controls and business consequences separately. An exposed application handling sensitive data may warrant different action from an isolated component with the same severity score.

Document planned remediation, temporary containment, incident investigation or demonstrated non-applicability. A compensating control needs an owner, effectiveness limits and a review deadline.

Verify after the change

Check the corrected version, actually loaded component and service availability. A closed ticket or downloaded package does not prove every affected asset has been updated.

If compromise indicators exist, patching alone does not close the incident. Preserve available logs and initiate response with the responsible team.

Common pitfalls

Four shortcuts that weaken the result.

Sorting only by CVSS

Technical severity is not complete business risk.

Confusing percentile and probability

Keep the EPSS fields separate.

Assuming a version

Confirm the installed product before concluding.

Closing without validation

Check every asset and temporary control.

Practical questions

Frequently asked questions.

Does a CVSS score of 9 determine priority?

It indicates high severity within the vector conditions. Applicability, exploitation, exposure and consequences also need assessment.

Is absence from KEV reassuring?

It means the CVE was not in the consulted catalog. It does not establish absence of exploitation.

Must exploitation be tested before deciding?

Not necessarily. Vendor advisories and an authorised inventory often support a decision; technical testing requires an appropriate scope and permission.

Public references

NIST NVD — CVE / CVSS. Gravité technique et risque / Technical severity and risk.

CISA — KEV. Vulnérabilités exploitées / Known exploited vulnerabilities.

FIRST — EPSS. Probabilité sur trente jours et percentile / Thirty-day probability and percentile.

Editorial scope

Published by Internet Intelligence Service on 6 October 2026. Last content update: 6 October 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.

Find primary portals and their limitations