Dataminr BLOG

CVSS Is Telling You the Wrong Thing

CVSS scores alone can't tell security teams what actually matters. Dataminr's 2026 Mid-Year Threat Landscape Report exposes why patching speed is losing to attacker speed, and why prioritizing by exploitability, exposure, and business impact is the only way to close that gap.

CVSS Is Telling You the Wrong Thing
DATE August 3, 2026
AUTHOR Jeanette Miller-Osborn, Field Cyber Intelligence Officer, Dataminr
SHARE
CYBER DEFENSE

Every six months, we sit down and ask the same question: what actually changed in the threat landscape? I’m less interested in headlines than in the underlying mechanics of risk. Our 2026 Mid-Year Threat Landscape Report pulled together roughly 4,500 tracked threat actors, some 73,000 vulnerability alerts, and more than two million alerts a month to answer that question for the first half of the year. One finding stood out to me more than the rest, because it’s the one practitioners feel every single day: the patching math has stopped working, and CVSS is a big part of why.

The Gap Between Disclosure and Exploitation Just Got Wider

Median time-to-patch stretched from 32 to 43 days since the start of the year, according to the 2026 Verizon DBIR; and that same report found vulnerability exploitation has now overtaken stolen credentials as the top breach entry point for the first time. Meanwhile, CrowdStrike puts average attacker breakout time at 29 minutes.

Read those numbers together and the picture is stark: attackers are moving in under half an hour, and defenders are averaging over six weeks to patch. No team is going to out-patch a 30-minute breakout window. The only lever left is deciding which vulnerabilities are worth chasing at all.

CVSS Was Never Built to Answer “Should I Panic?”

A CVSS score tells you about the technical severity of a flaw. It tells you almost nothing about whether that flaw is being actively exploited, whether it’s reachable in your environment, or what it would actually cost you if someone got through it.

In the Dataminr 2026 Mid-Year Threat Landscape Report, we put together a small table of real CVEs from the first half of the year, scored side by side on likelihood of exploitation, potential financial impact, and likelihood of targeting. A few of them share the same 9.8–10.0 CVSS score. Almost none of them carry the same real-world risk. A critical CVE sitting behind segmented networks and strict access controls is a different problem than the same CVE exposed on a flat, internet-facing network. And CVSS alone can’t tell you which one you’re looking at.

If your patching queue is still sorted by CVSS score first, you’re not prioritizing. You’re guessing with extra steps.

The reframe I’d push every team toward is a progression: start with all your vulnerabilities, narrow to the ones without compensating controls, then narrow again to the ones with real material impact if exploited. The product matters less than the fact that “all → uncompensated → material” only survives past a spreadsheet with something built to operationalize it. This is exactly the logic behind what we’re building into Dataminr’s Predictive Threat Exposure Management (PTEM).

AI Is About to Make the Backlog Worse

This is the part that should change how security leaders think about the next 12 months. AI-assisted vulnerability discovery is accelerating fast. Anthropic reported that its Mythos model alone surfaced 1,752 high- or critical-severity vulnerabilities in open-source code within its first months of existence, and that figure doesn’t even include what Project Glasswing organizations found independently. Our own proprietary models assessed roughly 300 highly critical vulnerabilities in the first half of the year as having widespread, major potential impact.

More findings doesn’t automatically translate to more protection. Without a way to triage that volume, it just buries the handful of vulnerabilities that actually matter under a backlog of ones that don’t. Detection isn’t the bottleneck anymore; most teams already have plenty of it. What they’re missing is prioritization: mapping severity against exploitability, exposure, and business impact so teams remediate what adversaries can actually reach, instead of working a queue in the order it was generated.

To be clear, none of this is cause for panic. The threat these numbers describe predates any single model release; what’s changed is the math, and the doctrine has to catch up to it. That’s a planning conversation, not a fire drill.

What I’d Tell a CISO Right Now

Stop asking “is this a critical CVE?” and start asking “is this specific flaw being targeted in my sector, and can an attacker actually reach my crown jewels through it?” That reframing is the only thing that makes a five-figure vulnerability backlog manageable, and it’s the difference between a patching program that reduces risk and one that just generates busywork.

The organizations that come out ahead in the second half of 2026 won’t be the ones that patch the most. They’ll be the ones that patch the right things first. And that means putting those same three factors — exploitability, exposure, and business impact — ahead of a bare CVSS number when deciding what to fix.

Dataminr 2026 Mid-Year Threat Landscape Report

Read the 2026 Mid-Year Threat Landscape Report for the complete data on threat actor activity and the geopolitical spillover into cyber operations, plus where financial losses are trending for the year.

Get the report
Aug 3, 2026

SHARE
  • Cyber Defense
  • Cyber Risk
  • Blog