Book an Appointment

Vulnerability & Zero-Day Management

How to steer technical vulnerabilities across their entire lifecycle – and use CVSS 4.0, EPSS and the CISA KEV catalog to close the gaps that are actually under attack first.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

119new vulnerabilities per day (avg., BSI 2025 report)
+38%exploitation attacks measured at BSI honeypots
30days: EPSS forecast window per CVE (estimated daily)
3days: shortest deadline in the CISA BOD 26-04 reference model

According to the BSI's 2025 report on the state of IT security in Germany, an average of 119 new vulnerabilities per day became known during the reporting period from July 2024 to June 2025 – around 24 percent more than in the same period a year earlier; exploitation attacks measured at BSI honeypots rose by 38 percent. At these volumes, “patch everything immediately” is not a strategy: what matters is reliably identifying the small subset of vulnerabilities that are actually exploitable or already being exploited – and remediating those first. To do so, modern programs combine a closed lifecycle with risk-based prioritization built on CVSS 4.0, EPSS and CISA's KEV catalog. For zero-days, for which no patch yet exists, compensating controls and systematic advisory monitoring are needed on top.

The Essentials at a Glance

Six topic blocks — tap to expand.

Three Signals for Prioritization

CVSS 4.0, EPSS and CISA KEV compared – tap a tab.

Severity
  • Available in version 4.0 since November 2023, with four metric groups: Base, Threat, Environmental and Supplemental.
  • The Threat metric “Exploit Maturity” reflects whether exploit code is available or the flaw is already being actively exploited.
  • FIRST itself makes clear: CVSS measures technical severity and should not serve as the sole measure of risk.
BaseThreatEnvironmentalSupplementalExploit MaturityCVSS-B/-BT/-BE/-BTEFIRST

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

FIRST.org · 2023

Common Vulnerability Scoring System version 4.0 Specification Document

Official CVSS 4.0 specification: four metric groups (Base, Threat, Environmental, Supplemental), the Exploit Maturity metric and the CVSS-B/-BT/-BE/-BTE nomenclature; the accompanying User Guide clarifies that CVSS-B measures severity, not risk.

FIRST.org · 2026

Exploit Prediction Scoring System (EPSS)

Daily updated probability scores for the exploitation of every published CVE within the next 30 days, freely available via CSV and API.

CISA · 2026

BOD 26-04: Prioritizing Security Updates Based on Risk

Replaces BOD 22-01 as of June 10, 2026: risk-based remediation deadlines (3/14/60 days or the next upgrade) derived from four criteria, including KEV status and internet exposure.

ISO/IEC · 2022

ISO/IEC 27001:2022 – Information security management systems – Requirements

Annex A control 8.8 requires obtaining information about technical vulnerabilities, evaluating the organization's own exposure and taking appropriate measures.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2025

Die Lage der IT-Sicherheit in Deutschland 2025

Reporting period 07/2024–06/2025: an average of 119 new vulnerabilities per day (+24%), exploitation attacks +38%, and a continuing trend toward attacks on perimeter systems such as VPN gateways.

OWASP Cheat Sheet Series · 2026

Virtual Patching Cheat Sheet

Continuously maintained cheat sheet: defines virtual patching as an upstream protection layer against exploitation attempts (WAF/IPS) and classifies it as an interim measure that does not replace the code fix.

How robust is your vulnerability management?

In a no-obligation initial consultation, we benchmark your process against ISO 27001 A.8.8 – from prioritization to patch SLAs. For the continuous monitoring of newly disclosed vulnerabilities, VamiSec additionally offers zero-day monitoring as a managed service.