CVSS (Common Vulnerability Scoring System)
The Common Vulnerability Scoring System is an open industry standard for assessing the severity of software vulnerabilities, maintained by the Forum of Incident Response and Security Teams (FIRST). CVSS scores range from 0 to 10, with higher scores indicating greater severity. Black Kite uses CVSS scores in calculating findings severity within its Cyber Rating and in prioritizing remediation guidance across vendor assessments.
How Is a CVSS Score Calculated?
The scale of the problem is real. More than 48,000 CVEs were published in 2025, and only about 800 were exploited in the wild, according to Black Kite's 2026 Supply Chain Vulnerability Report. A high score alone doesn't tell you which of your vendors are running the affected software, or whether anyone has noticed the flaw yet.
CVSS 4.0, the current version, defines four metric groups: Base, Threat, Environmental, and Supplemental. The scoring organization, often a CVE Numbering Authority or NVD, combines them into one number.
Base Metrics Set the Starting Severity
The Base group asks how easy the flaw is to reach and what happens if someone exploits it. Attack vector, attack complexity, privileges required, and the impact on confidentiality, integrity, and availability all factor in. This is the score most vendors publish, and it reflects the flaw's built-in characteristics, so it doesn't change as the threat around the flaw changes.
Threat Metrics Track Real-World Exploit Activity
The Threat group, called Temporal in earlier versions, reflects whether exploit code exists or the flaw is being exploited in the wild. CVSS 4.0 simplified this layer to a single metric, Exploit Maturity, because a flaw with public exploit code circulating is a different problem than one that's still theoretical.
Environmental Metrics Adjust for Where the Flaw Sits
The Environmental group lets an organization adjust the score for its own setup, including whether the vulnerable service is reachable from outside or sits behind other controls. Almost nobody outside the affected organization has the access to calculate this layer. That's exactly why an outside-in view of a vendor's actual exposure matters more than the published number alone.
What Do the CVSS Severity Ranges Mean?
CVSS scores map to five qualitative ratings, and most vulnerability programs triage by rating before they ever look at the raw number.
FIRST defines five bands on the 0.0 to 10.0 scale:
- None (0.0): the flaw carries no meaningful impact on its own.
- Low (0.1 to 3.9): exploitation needs unusual conditions or yields minimal impact.
- Medium (4.0 to 6.9): exploitation is plausible and the impact is moderate.
- High (7.0 to 8.9): exploitation is straightforward and the impact is serious.
- Critical (9.0 to 10.0): exploitation is often trivial and the impact is severe, frequently full system compromise.
Exposure and attacker attention matter more than the raw count. A vendor with one High-rated flaw on an internet-facing login page, actively discussed by attackers, usually needs a call before a vendor simply sitting on a stack of Critical-rated software that nobody's targeting yet.
How Is CVSS Different From a CVE?
A CVE is the name of a flaw. A CVSS score is how bad that flaw could be. A CVE Numbering Authority assigns a CVE identifier so everyone is talking about the same vulnerability. The CNA or the National Vulnerability Database then attaches a CVSS score, using the standard FIRST maintains, to describe its theoretical severity. The two travel together in almost every vulnerability feed, but they answer different questions, and neither one tells you whether the flaw is being actively exploited or which of your vendors are running the affected version.
Does a High CVSS Score Mean a Vendor Will Get Breached?
No. CVSS measures how bad a flaw could theoretically be. Exploitation activity and whether your specific vendor is actually exposed are two separate questions a CVSS score alone can't answer. A 9.8 on a vendor's isolated test environment is a lower priority than a 6.5 on a system with an open port facing the internet, but the Base score treats both the same.
Black Kite Research Group™'s 2025 review of high-priority CVEs shows how rare a truly urgent flaw actually is:
- Only 58 of 1,200+ manually reviewed CVEs cleared the bar for both OSINT discoverability and an exploitation probability above 60%, the threshold the Supply Chain Vulnerability Report calls "Code Red."
- The gap between disclosure and exploitation hit negative seven days in 2025, down from positive five days in 2023, per Mandiant data cited in the same report. Attackers now routinely weaponize a flaw before a patch or advisory even exists.
The 2025 AI copilot flaw EchoLeak (CVE-2025-32711) shows that gap in practice. It carried a CVSS score of 9.3 and still needed OSINT and exploitability context to prioritize correctly against thousands of other Critical-rated flaws published the same year. A high number demands attention. It doesn't tell a risk team which vendor to call first.
How Does Black Kite Use CVSS Data?
Black Kite treats a CVSS score as one input among several within its standards-based ratings methodology, an approach covered across its TPRM and TPCRM glossary. When deciding which vulnerabilities warrant a FocusTag®, Black Kite's research team weighs CVSS alongside EPSS, KEV status, exploit PoC availability, threat actor exploitation, and community mentions to separate a theoretical high score from an active one. Vulnerability Intelligence Briefs™ (VIB™) then show which vendors in a portfolio are exposed. FocusTags® map that filtered signal to the vendors whose external assets appear to run the affected software.
This is where continuous, non-intrusive vendor risk monitoring earns its place in a TPCRM program. A questionnaire captures a vendor's patch posture once a year. Continuous outside-in monitoring can flag, between assessments, whether a vendor's internet-facing systems appear to still run a version affected by the flaw. Pairing severity data with threat actor monitoring adds a third layer, since it shows whether an adversary known to target the vendor's industry is actively working with that flaw at all.
A zero-day vulnerability carries no CVSS score at all until it's disclosed, which is exactly why exposure monitoring has to look past score-based triage alone. A vulnerability assessment that only checks CVSS thresholds will miss it entirely.
See also: Stop Drowning in CVEs