CVSS is mathematically obsolete. We didn't argue it — we ran the formula and published the math.
Nearly every security program prioritizes remediation by CVSS score. We showed — with the actual calculation, before and after — how the number misranks the risk that will actually get you breached. It became the highest-engagement piece in its category.
A single number decides what thousands of teams fix first.
CVSS is the lingua franca of vulnerability management. It drives SLAs, audit findings, and remediation queues. Treated as objective truth, it quietly decides which risks get attention and which wait — and the math underneath it has not kept pace with how systems actually get attacked.
Same vulnerability. Two very different truths.
AV:N / AC:L / PR:N / UI:N
→ static base metrics only
→ no exploit-in-the-wild input
→ no environmental context
Ranked "High," it lands mid-queue behind a stack of other Highs and Criticals — and waits.
+ actively exploited in the wild
+ sits on an internet-facing asset
+ reachable path to CUI / crown jewels
= the breach vector, not a "High"
Weight the factors CVSS omits and the same finding jumps the entire queue. The score didn't just undersell it — it actively buried it.
Three things the score can't see — and they're the three that matter.
A base score doesn't know if it's being exploited today.
Two findings with the same 7.5 are worlds apart if one has weaponized exploit code in the wild and the other has none. The base number treats them as equals.
It doesn't know what the asset is worth to you.
The same flaw on a test box and on your CUI enclave scores identically. Business impact is exactly what a universal score can't encode.
It doesn't know if an attacker can actually get there.
A "Critical" behind five segmentation layers may be less urgent than a "Medium" one hop from the internet. Path matters; the score ignores it.
If your remediation queue is sorted by CVSS, the math itself is telling your team to fix the wrong thing first.
Stop remediating by a number that can't see your risk.
Three ways in, matched to how ready you are to re-rank.
Risk re-ranking calculator
Enter a CVSS score plus exploit, context, and reachability — see the real priority.
Try the calculator →Queue review workshop
We re-rank a slice of your live remediation queue against real-world risk factors.
Book a workshop →Risk prioritization program
Rebuild remediation prioritization around exploitability, context, and reachability.
Start the engagement →