Patch priority
Why a CVSS 10 can wait and a KEV 7.5 cannot
Updated 2026-08-28
CVSS measures severity in a lab. CISA KEV measures exploitation in the world. Patch priority for a SaaS-first company should follow known exploitation, not the bigger number.
The score was never a calendar
CVSS is a useful language for “how bad is this if it applies.” It does not know whether anyone is using the bug, whether a patch exists, or whether the product is a SaaS vendor who will patch for you. Treating 9.8 as automatically more urgent than 7.5 is how teams burn a week on a theoretical RCE and miss a KEV on the VPN.
Known exploited is a different axis
CISA KEV is an exploitation flag with a required action. EPSS (from FIRST) is a probability model for exploitation. Recorded Future and others mix those with dark-web chatter. You do not need the full mix to beat “sort by CVSS.” You need one reliable exploited-class feed tied to the tools you named.
If a KEV entry is 7.5 and a fresh NVD critical is 10.0 on a product you do not run, the 7.5 wins. If both match your stack, do both — KEV first.
SaaS makes this sharper
On a self-hosted appliance, you patch. On Salesforce or Okta, the vendor often patches. Your job is awareness, customer questions, and compensating control — MFA, session revoke, vendor status. A briefing that stops at the CVSS number does not tell a founder what to say to the board. A KEV briefing with CISA’s required action does.
Watch the SaaS that holds your data.
Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.