Tag

#CVSS

7 stories taggedCVSS.

Full-frame edge-to-edge photoreal news-editorial image of a modern laptop screen showing an abstract browser window with a glowing extension icon in the toolbar
AI Security

AI Found Thousands of Flaws in Days. Humans Can't Patch Them Fast Enough.

Anthropic's Claude Mythos model discovered more security holes in major software than years of human review had caught. That's exciting for defenders and terrifying for everyone else, because the gap between finding a flaw and fixing it is already dangerously wide.

4 min read
Close-up overhead shot of a dense rack of enterprise networking and telephony hardware, blinking amber and red indicator lights visible across multiple units, s
Vulnerabilities

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical

An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

3 min read
Full-frame 16:9 photoreal editorial shot of a dense server rack in a dim data centre, cool blue LEDs reflecting off polished floor tiles, one open chassis expos
Vulnerabilities

Veeam Console Bug Hands Over Agent Credentials; Terraform MCP Server Leaks Tokens Between Users

Eleven fixes across HashiCorp, Veeam and Django include a 9.5-rated Veeam flaw and a cross-tenant Terraform MCP Server bug that reuses one customer's cloud token for the next.

4 min read
Photoreal news-editorial shot of a rack of white networking access points and small gateway boxes mounted on a modern office ceiling, soft cool blue LEDs glowin
Vulnerabilities

What is a CVE and how does vulnerability scoring work?

CVEs are the universal ID system for software flaws, and CVSS scores tell you how bad each one actually is.

5 min read
Photoreal news-editorial photograph, 16:9 framing, edge-to-edge composition
Vulnerabilities

Security Debt Is Growing Faster Than Companies Can Fix It. Here Is What That Means.

Eight in ten organisations are sitting on a backlog of unresolved security flaws that stretch back more than a year. A practical framework, first outlined in CSO Online, explains how to turn that problem into a board-level conversation.

3 min read
Policy & Regulation

CISA's New Patching Directive Drops CVSS as the North Star

BOD 26-04 introduces a four-factor framework that prioritizes internet exposure, active exploitation, and attacker automation over raw severity scores — and gives agencies three days to act on the worst cases.

3 min read
Policy & Regulation

Inspector General Pins NVD Backlog on NIST Mismanagement — But the Real Problem Runs Deeper

A Commerce Department IG report calls out strategic failures, duplicated work, and severity scores that matched only 12% of the time. Budget cuts and genAI-driven vuln volume tell the rest of the story.

3 min read
© 2026 Threat Vectr