Tag
#cvss
5 posts tagged #cvss.
-
Analysis · Jun 30, 2026 · Colten Anderson
The patch queue is being rebuilt around the asset, not the score
In the same month, CISA and Microsoft both demoted CVSS as the thing that decides what to patch first. The order of operations is inverting: asset context is becoming the queue.
-
Analysis · Jun 19, 2026 · Colten Anderson
A 6.1 read European government email for two years
Two medium-severity Roundcube XSS bugs let Russian state actors read government email with no click required. The CVSS score said monitor. The KEV listing said move.
-
Analysis · Jun 3, 2026 · Colten Anderson
Everything is critical, so nothing is critical
A third of last year's CVEs were rated High or Critical, but only a few percent ever get exploited. The severity score was never a risk score, and the queue that treats it like one is the reason confirmed-exploited bugs sit unpatched for 43 days.
-
Analysis · May 14, 2026 · Colten Anderson
Does this CVE actually apply to you? Three filters before you patch
Single-score triage fails in both directions: 10.0s that don't apply, 4.3s that get exploited for 13 days. Three filters reduce the queue.
-
Analysis · May 5, 2026 · Colten Anderson
The 6.5 that enabled 400 compromises: authentication bypasses and the CVSS blind spot
CVE-2025-49706 scored CVSS 6.5. It enabled unauthenticated RCE across 400+ SharePoint servers. Authentication bypasses are consistently underscored, and consistently the vulnerability class that turns a bad bug into a mass-exploitation campaign.