Artwork for podcast Byte Sized Security
Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited
Episode 4610th September 2026 • Byte Sized Security • Marc David
00:00:00 00:09:36

Share Episode

Shownotes

Roughly 98.5% of all known CVEs have never been exploited. In this episode I break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, and host Raphael Mudge, on the Down the Rabbit Hole podcast, and what it means for how you prioritize a patch queue. I cover CVSS score versus exploitation evidence, how to use CISA's free KEV catalog, why the vulnerability management industry has no incentive to tell you the truth, and what separates a junior-sounding answer from a senior one in a security interview.

In this episode:

  • (00:00) The scan report that isn't as urgent as it looks
  • (01:03) The 98.5% number and the mechanic analogy
  • (02:01) Why the industry defaulted to patch everything
  • (03:00) The 36-hour outage from a perfect-10 patch
  • (03:48) CVSS score vs. exploitation evidence vs. insurance-claims data
  • (05:08) What it sounds like when someone understands this in an interview
  • (06:15) Why the industry has no brakes, and the AI-hype myth
  • (07:49) Your homework

Links:

Not financial or legal advice. Figures cited reflect Root Evidence's analysis as discussed on the source podcast episode.

I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

--

Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

Listen to Byte Sized Security

--

Support this Podcast with a Tip:

Support Byte Sized Security

--

If you have questions for the show, feedback or topics you want covered. Please send a short email to [email protected] with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

Links

Chapters

Video

More from YouTube