Step-by-step method
A reproducible path from question to conclusion.
- 1
Connect the CVE to an asset
Record product, version, component, owner and business role. Check the vendor advisory and exploitation prerequisites. An old public banner does not establish the currently installed version.
- 2
Read severity with its vector
Retain CVSS version, vector, score source and prerequisites such as privileges or user interaction. A context-free number is insufficient for comparing cases.
- 3
Review exploitation signals
Consult KEV for known exploitation and EPSS for a thirty-day estimate. Record their dates. An EPSS percentile is a rank, distinct from probability.
- 4
Assess exposure and consequences
Work with the authorised team to establish component accessibility, prerequisites and affected data or operations. Defensive assessment does not require trying an exploit against a public target.
- 5
Select and verify the measure
Apply the patch or vendor-recommended temporary mitigation through the change process. Retain validation, functional tests, owner and the review date for temporary measures.
CVSS, KEV and EPSS answer different questions
CVSS describes technical severity. KEV lists vulnerabilities with known real-world exploitation. EPSS estimates exploitation probability over the next thirty days. None alone describes the consequences for your asset.
A low EPSS score does not cancel known exploitation. A CVE missing from KEV may still be exploited. CISA catalog deadlines belong to a US federal framework; define organisational deadlines using your context and obligations.
Document affected and unaffected assets
Preserve the inventory used, actually installed version and advisory passage supporting applicability. An assumption based only on a search result remains unconfirmed.
If the version or prerequisite cannot be checked, retain a pending-verification status. To close as not applicable, record the technical reason and source instead of silently dismissing the alert.
Explain the decision rather than combining scores
Review exploitation, component accessibility, existing controls and business consequences separately. An exposed application handling sensitive data may warrant different action from an isolated component with the same severity score.
Document planned remediation, temporary containment, incident investigation or demonstrated non-applicability. A compensating control needs an owner, effectiveness limits and a review deadline.
Verify after the change
Check the corrected version, actually loaded component and service availability. A closed ticket or downloaded package does not prove every affected asset has been updated.
If compromise indicators exist, patching alone does not close the incident. Preserve available logs and initiate response with the responsible team.
Common pitfalls
Four shortcuts that weaken the result.
Sorting only by CVSS
Technical severity is not complete business risk.
Confusing percentile and probability
Keep the EPSS fields separate.
Assuming a version
Confirm the installed product before concluding.
Closing without validation
Check every asset and temporary control.
Practical questions
Frequently asked questions.
Does a CVSS score of 9 determine priority?
It indicates high severity within the vector conditions. Applicability, exploitation, exposure and consequences also need assessment.
Is absence from KEV reassuring?
It means the CVE was not in the consulted catalog. It does not establish absence of exploitation.
Must exploitation be tested before deciding?
Not necessarily. Vendor advisories and an authorised inventory often support a decision; technical testing requires an appropriate scope and permission.
Public references
NIST NVD — CVE / CVSS. Gravité technique et risque / Technical severity and risk.
CISA — KEV. Vulnérabilités exploitées / Known exploited vulnerabilities.
FIRST — EPSS. Probabilité sur trente jours et percentile / Thirty-day probability and percentile.
Editorial scope
Published by Internet Intelligence Service on 6 October 2026. Last content update: 6 October 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.
