Vulnerability management changed in 2026. Since April 15, NIST’s NVD risk-triages CVEs instead of enriching every record. A CVE may lack a complete score or affected-product list, so CVSS alone cannot be your queue.
Start with CISA’s KEV Catalog: vulnerabilities with evidence of exploitation and a clear fix. Its JSON/CSV feeds had 1,662 entries on August 8, 2026. Prioritize KEV status and internet exposure, then consider exploit automation. CISA’s BOD 26-04 is binding on federal agencies, not private companies, but its logic is useful: fix urgent systems within days and defer lower-risk work to upgrades. The SSVC Calculator helps classify decisions as Track, Attend, or Act.
Use this loop: inventory exposed assets; subscribe to KEV and NVD 2.0 feeds; record decisions; patch and verify. Per Verizon’s 2026 DBIR, cited by CISA, only 26% of KEV vulnerabilities were remediated in 2025; median resolution was 43 days. Harden configurations, segment systems, and use phishing-resistant MFA. Patch what matters now; schedule the rest, with dated exceptions and an owner. Review each exception often.
Related What I Do
Related What I Do
These What I Do pages are matched from the subject matter of this article, creating a cleaner path from educational content to implementation work.
Continue reading
Related articles
Based on shared categories first, then the strongest overlap in tags.