#cvss

2 posts · Last used 10d

Back to Timeline
Infosec Stoic @infosecstoic@infosec.exchange · Jul 07, 2026
What does CVSS actually measure? Jay Jacobs, who built EPSS, asked exactly that on LinkedIn and admitted he has never gotten an authoritative answer. 87 comments agreed it is "not risk." None could define "severity." That is not a CVSS problem. It is a language problem. Our field runs on load-bearing words it never defined. Held against FAIR, a real risk ontology, CVSS has no frequency term at all, so it structurally cannot be risk. As Sasha Romanosky (@SashaRomanosky@techhub.social) put it, we have "fundamentally lacked that capability as an industry." FAIR and CVSS even use "vulnerability" to mean opposite things: a probability versus the flaw itself. But CVSS is not fake. It is Ptolemaic: coherent, useful, quietly wrong about its own ontology, like epicycles that predicted the sky for 1400 years on a false model. It is dangerous only when we read severity as risk and build clocks and contracts on the reading. The fix is already here: CVSS for severity, EPSS for likelihood, KEV for live exploitation, FAIR for loss. CISA's new BOD 26-04 does exactly this. Stop asking one number to be four things. The Magic Number: https://infosecstoic.substack.com/p/the-magic-number-what-does-cvss-actually #cybersecurity #vulnerabilitymanagement #CVSS
0
0
0

You've seen all posts