Help4 Net
Risk decisions

Patch what is exposed and exploitable first.

A severity score is useful context, not a complete queue. Prioritize with real exploitation evidence, reachable attack paths, affected versions, business impact, available fixes, and the strength of temporary controls.

Six questions

  1. Is exploitation known? Check authoritative vendor notices and the CISA Known Exploited Vulnerabilities Catalog.
  2. Are we actually affected? Confirm the installed product, edition, configuration, and version rather than matching only a product name.
  3. Is the vulnerable path reachable? Internet-facing, unauthenticated, administrative, local-only, and disabled features have different urgency.
  4. What can an attacker gain? Consider code execution, authentication bypass, data exposure, privilege escalation, denial of service, and persistence.
  5. Is a supported fix ready? Prefer the vendor patch, supported upgrade, feature disablement, or component removal.
  6. What reduces risk meanwhile? Use narrow WAF rules, access restrictions, segmentation, monitoring, or isolation while scheduling the permanent fix.

Practical priority bands

Emergency

Known exploitation plus affected and reachable systems, especially unauthenticated code execution, authentication bypass, or sensitive-data access.

Urgent

High-impact exposure with credible exploitability, a public proof of concept, weak prerequisites, or important externally reachable services.

Scheduled

Affected systems with meaningful prerequisites, limited exposure, strong compensating controls, or lower operational impact.

Monitor or not affected

Version or configuration is not affected, the component is absent, or available evidence is insufficient. Record the reason and revisit when facts change.

Do not confuse these signals

Record the decision

CISA KEV Catalog · NIST NVD