Skip to content

Vulnerability management: How to prioritize CVEs

Kevin Apolinario|September 30, 2026
Security3 2026
Security3 2026

TL;DR: Effective vulnerability management comes down to context, not chasing every high-severity CVE. Prioritize vulnerabilities based on factors like active exploitation, asset criticality, exposure, and exploit likelihood, then use automation to speed up remediation without skipping validation. The goal is a repeatable process that helps IT teams focus limited time on the vulnerabilities that pose the most meaningful risk.

Vulnerability management is an ongoing process of finding, prioritizing, and fixing security weaknesses. Patch management is part of that process, but keeping up also means knowing what to fix first, where automation can help, and how to verify that fixes worked.

In my previous role, I managed asset vulnerabilities as a senior security operations center (SOC) analyst at a managed service provider (MSP). Many of the companies we worked with relied on third-party tools for patch management. 

One of the biggest shifts I experienced was the rise of AI. It became a game changer because it helped me write and run PowerShell scripts more efficiently. We used an in-house AI tool and avoided external AI for sensitive work. 

The concern was always the same: What does AI do with your information or data? You have to assess what data is being shared and how it may be used, especially when it supports audits. 

Patch management has to be a priority. Between browsers, Windows, and applications, you’re always patching something. That is why we use tools like PDQ to assess our assets and identify what needs updating.

The beauty of using tools like PDQ is that you can run a report and give it to your auditors. During a SOC 2 audit, I was able to pull reports for our auditors, and the process was seamless. 

The challenge is managing time and keeping up with patch management. That is why we use automation scripts to help handle these vulnerabilities. 

What is a vulnerability in cybersecurity? 

A vulnerability in cybersecurity is a flaw in a computer system or a weakness in security practices that can be exploited. Vulnerabilities are not limited to software bugs; they can also involve weaknesses in how systems are configured or protected.

Software vulnerabilities can be tracked through Common Vulnerabilities and Exposures (CVE) identifiers. You can find CVE records and instructions for reporting vulnerabilities on the CVE Program website.

CVEs can relate to applications, Windows, or back-end components of a system. These vulnerabilities are discovered through methods such as testing, code audits, and incident analysis.

Organizations also use red teaming and penetration testing to simulate attacks and find weak spots. There are also bug bounty programs, where companies pay independent researchers to find and report security flaws. Some companies use third-party tools to scan networks and applications for insecure components or configurations.

  • Static application security testing (SAST): Analyzes code without running the program to find coding errors and security flaws early.

  • Dynamic application security testing (DAST): Tests running applications by simulating attacks without needing access to source code.

  • Vulnerability scanning: Checks systems for known vulnerabilities, outdated software, and misconfigurations.

  • Fuzz testing: Sends unexpected or malformed inputs to applications to uncover crashes and other defects that may indicate security vulnerabilities.

That is why it is important to keep machines patched and address vulnerabilities in your environment. We use tools like PDQ or other patch management tools to help with the patching work.

What is vulnerability management? 

Vulnerability management is an ongoing process of finding, prioritizing, and fixing security weaknesses in an organization’s computer systems and software before attackers can exploit them. Keeping systems updated and patched is an important part of that work.

A vulnerability could involve unpatched software, misconfigurations, or a weak password. To support vulnerability management, organizations use tools like Tenable, Qualys, and Wiz. 

Vulnerability assessments provide a snapshot of weaknesses at a specific moment. Vulnerability management, on the other hand, integrates discovery, prioritization, and remediation into everyday security operations. An assessment helps you identify weaknesses; vulnerability management is the ongoing work of addressing them.

CVE fatigue: What to do when everything looks critical 

Prioritizing CVEs and tuning your patch management tools can help you handle the workload and avoid CVE fatigue. It can be exhausting to patch a large set of systems, only to wake up the next day and have another wave of updates. 

I remember working at a company where I patched every machine, and the following day I had to update all the machines again. It was extremely frustrating. 

What helped was automating certain tasks and tuning Microsoft Defender to manage CVEs more effectively. I also adjusted our patch management tool since we kept receiving CVEs every day, and I created a script to update machines daily based on CVEs. 

As a senior SOC analyst, it is important to prioritize CVEs and learn how to tune your tools to handle them. Otherwise, it is easy to get overwhelmed. 

CVSS is useful, but it is not your priority list 

The Common Vulnerability Scoring System (CVSS) is a standard framework used in cybersecurity to assess the severity of security flaws. CVSS is useful, but a CVSS base score measures severity, not your organization’s overall risk.

To understand what is critical in your environment, consider these factors together: 

  • Confirmed exploitation: Whether there is evidence that a vulnerability is being exploited.

  • Asset criticality and data sensitivity: How important the affected asset is and what information it holds.

  • Internet exposure and technical reachability: Whether an attacker can reach the vulnerable system or component.

  • Exploit Prediction Scoring System (EPSS) scores: The estimated likelihood of exploitation.

  • CVSS scores and potential impact: The severity of the vulnerability and what an attacker could do.

  • Existing compensating controls: The protections already in place that may reduce the risk.

That is how you move beyond a severity score and understand what is critical in your environment. 

What does vulnerability management look like in the real world? 

A vulnerability management workflow means identifying vulnerabilities, deciding how to remediate them, and determining what is most important to patch. You also need to understand whether a patch will work and when it is appropriate to deploy it.

I would use PDQ to assess my server and see what needed to be patched. I love having a clear picture of what needs updating so I know what to address. 

After assessing a device for vulnerabilities, you need to figure out whether the affected machine needs to be updated or patched. The challenge is understanding whether the patch is safe to deploy and whether it will work as expected. 

You also need to understand when it is okay to patch the machine. In our environment, we updated machines during the night or outside working hours to avoid interruptions. The last thing you want is to run an update while someone is in a meeting or using their machine. 

Be careful and deliberate when running updates. Whether you use PDQ or another third-party application, it is important to understand the patch management workflow, identify the remediation, and decide what needs to be patched first. 

Automation vs. prioritization 

Automation helps with updating systems and patching, but it does not replace prioritization or checking the results. Even when we use automation, we still need to look at what is happening to make sure nothing gets messed up on the back end. We follow a vulnerability management program with four stages: 

  1. Discovery: Track hardware, software, cloud environments, and open-source dependencies to reduce blind spots.

  2. Prioritization: Focus on real-world exploitability and asset value rather than severity scores alone.

  3. Remediation: Apply patches, update configurations, or implement compensating controls within established service-level agreements (SLAs).

  4. Verification: Rescan systems to confirm that fixes were successful before closing tracking tickets.

That is how we handle vulnerability management. We don’t just run random scripts and assume that everything will work. We manually review what we run and make sure the scripts are running the way they are supposed to. 

Kevin Apolinario

Kevin Apolinario is an IT trainer and educator who helps people build careers in tech through practical, hands-on learning. He has worked across MSPs, education, hedge funds, and Apple, and has trained more than 34,000 students through his IT support course. Kevin is also a speaker and instructor for organizations including Jobskillshare, Merit America, Generation USA, and BSides events.

Related articles