Blog post

Vulnerability Management for Small Ops Teams in 2026

The 2026 vulnerability-management reset: NVD now triages CVEs by risk, CISA's KEV list is the priority signal, and small ops teams can patch what matters in days instead of drowning in CVSS scores.

Vulnerability management changed in 2026. Since April 15, NIST’s NVD risk-triages CVEs instead of enriching every record. A CVE may lack a complete score or affected-product list, so CVSS alone cannot be your queue.

Start with CISA’s KEV Catalog: vulnerabilities with evidence of exploitation and a clear fix. Its JSON/CSV feeds had 1,662 entries on August 8, 2026. Prioritize KEV status and internet exposure, then consider exploit automation. CISA’s BOD 26-04 is binding on federal agencies, not private companies, but its logic is useful: fix urgent systems within days and defer lower-risk work to upgrades. The SSVC Calculator helps classify decisions as Track, Attend, or Act.

Use this loop: inventory exposed assets; subscribe to KEV and NVD 2.0 feeds; record decisions; patch and verify. Per Verizon’s 2026 DBIR, cited by CISA, only 26% of KEV vulnerabilities were remediated in 2025; median resolution was 43 days. Harden configurations, segment systems, and use phishing-resistant MFA. Patch what matters now; schedule the rest, with dated exceptions and an owner. Review each exception often.

Related What I Do

These What I Do pages are matched from the subject matter of this article, creating a cleaner path from educational content to implementation work.

Continue reading

Based on shared categories first, then the strongest overlap in tags.