Vulnerability management is a continuous process, not a one-off project. It starts with a complete asset inventory, because only known systems can be assessed – including cloud resources, containers and internet-facing services. This is followed by regular, ideally authenticated scans from inside and outside, risk-based prioritization of the findings, remediation through patches, configuration changes or compensating controls, and verification via re-scan. Only this closed loop, with documented turnaround times, makes the process manageable and auditable.
Vulnerability & Zero-Day Management
How to steer technical vulnerabilities across their entire lifecycle – and use CVSS 4.0, EPSS and the CISA KEV catalog to close the gaps that are actually under attack first.
119new vulnerabilities per day (avg., BSI 2025 report)
+38%exploitation attacks measured at BSI honeypots
30days: EPSS forecast window per CVE (estimated daily)
3days: shortest deadline in the CISA BOD 26-04 reference model
According to the BSI's 2025 report on the state of IT security in Germany, an average of 119 new vulnerabilities per day became known during the reporting period from July 2024 to June 2025 – around 24 percent more than in the same period a year earlier; exploitation attacks measured at BSI honeypots rose by 38 percent. At these volumes, “patch everything immediately” is not a strategy: what matters is reliably identifying the small subset of vulnerabilities that are actually exploitable or already being exploited – and remediating those first. To do so, modern programs combine a closed lifecycle with risk-based prioritization built on CVSS 4.0, EPSS and CISA's KEV catalog. For zero-days, for which no patch yet exists, compensating controls and systematic advisory monitoring are needed on top.
The Essentials at a Glance
Six topic blocks — tap to expand.
Three Signals for Prioritization
CVSS 4.0, EPSS and CISA KEV compared – tap a tab.
- Available in version 4.0 since November 2023, with four metric groups: Base, Threat, Environmental and Supplemental.
- The Threat metric “Exploit Maturity” reflects whether exploit code is available or the flaw is already being actively exploited.
- FIRST itself makes clear: CVSS measures technical severity and should not serve as the sole measure of risk.
BaseThreatEnvironmentalSupplementalExploit MaturityCVSS-B/-BT/-BE/-BTEFIRST
- FIRST's machine-learning model estimates daily, for every published CVE, the probability of active exploitation within the next 30 days.
- The scores are freely available via CSV and API.
FIRSTmachine learningCVE30 daysCSVAPI
- The Known Exploited Vulnerabilities catalog of the US cybersecurity agency CISA lists vulnerabilities whose exploitation has already been proven.
- KEV-listed findings on reachable systems belong at the top of the queue regardless of their Base score.
CISAKEVKnown Exploited VulnerabilitiesBase score
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Common Vulnerability Scoring System version 4.0 Specification Document
Official CVSS 4.0 specification: four metric groups (Base, Threat, Environmental, Supplemental), the Exploit Maturity metric and the CVSS-B/-BT/-BE/-BTE nomenclature; the accompanying User Guide clarifies that CVSS-B measures severity, not risk.
Exploit Prediction Scoring System (EPSS)
Daily updated probability scores for the exploitation of every published CVE within the next 30 days, freely available via CSV and API.
BOD 26-04: Prioritizing Security Updates Based on Risk
Replaces BOD 22-01 as of June 10, 2026: risk-based remediation deadlines (3/14/60 days or the next upgrade) derived from four criteria, including KEV status and internet exposure.
ISO/IEC 27001:2022 – Information security management systems – Requirements
Annex A control 8.8 requires obtaining information about technical vulnerabilities, evaluating the organization's own exposure and taking appropriate measures.
Die Lage der IT-Sicherheit in Deutschland 2025
Reporting period 07/2024–06/2025: an average of 119 new vulnerabilities per day (+24%), exploitation attacks +38%, and a continuing trend toward attacks on perimeter systems such as VPN gateways.
Virtual Patching Cheat Sheet
Continuously maintained cheat sheet: defines virtual patching as an upstream protection layer against exploitation attempts (WAF/IPS) and classifies it as an interim measure that does not replace the code fix.
How robust is your vulnerability management?
In a no-obligation initial consultation, we benchmark your process against ISO 27001 A.8.8 – from prioritization to patch SLAs. For the continuous monitoring of newly disclosed vulnerabilities, VamiSec additionally offers zero-day monitoring as a managed service.