CVSS vulnerability triage: 5 failures, 5 fixes

TL;DR AI
2 min readKey summary
A new analysis says CVSS-only triage can miss real exploit chains, causing critical flaws to slip past patch queues until they are actively abused.
The Palo Alto Operation Lunar Peek case shows how linked vulnerabilities such as CVE-2024-0012 and CVE-2024-9474 can create greater risk than either score suggests.
CVSS v3.1 and v4.0 can assign different severities to the same flaw, but neither reliably captures context like chaining, exposure, or active exploitation.
The article argues organizations should prioritize with context-aware methods such as CISA KEV, EPSS, and SSVC instead of relying on standalone severity scores.
