Internet exposure
Publicly reachable systems and identity services receive immediate attention.

Known exploited vulnerabilities ranked with EPSS, CVSS, deadlines, and concrete response guidance.
The board starts with confirmed CISA KEV exploitation, then considers ransomware evidence, EPSS probability, and CVSS severity. Asset exposure and business context still determine the final action.
Publicly reachable systems and identity services receive immediate attention.
EPSS adds probability context to confirmed exploitation and severity.
Closure requires evidence that the patch or compensating control works.
| RANK | CVE / PRODUCT | CVSS | EPSS | WHY PRIORITIZED | CISA DEADLINE | ACTION |
|---|
Every applicable item needs an accountable owner, an exposure decision, an implemented control, and retained evidence.