Patch priority

Why a CVSS 10 can wait and a KEV 7.5 cannot

Updated 2026-08-28

CVSS measures severity in a lab. CISA KEV measures exploitation in the world. Patch priority for a SaaS-first company should follow known exploitation, not the bigger number.

The score was never a calendar

CVSS is a useful language for “how bad is this if it applies.” It does not know whether anyone is using the bug, whether a patch exists, or whether the product is a SaaS vendor who will patch for you. Treating 9.8 as automatically more urgent than 7.5 is how teams burn a week on a theoretical RCE and miss a KEV on the VPN.

Known exploited is a different axis

CISA KEV is an exploitation flag with a required action. EPSS (from FIRST) is a probability model for exploitation. Recorded Future and others mix those with dark-web chatter. You do not need the full mix to beat “sort by CVSS.” You need one reliable exploited-class feed tied to the tools you named.

If a KEV entry is 7.5 and a fresh NVD critical is 10.0 on a product you do not run, the 7.5 wins. If both match your stack, do both — KEV first.

SaaS makes this sharper

On a self-hosted appliance, you patch. On Salesforce or Okta, the vendor often patches. Your job is awareness, customer questions, and compensating control — MFA, session revoke, vendor status. A briefing that stops at the CVSS number does not tell a founder what to say to the board. A KEV briefing with CISA’s required action does.

All guides · SaaS KEV tracker

Watch the SaaS that holds your data.

Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.

Start watching — freePricing