CVE Triage Rubric
Assign priority:
| Priority | Criteria |
|---|---|
| P1 | CVSS ≥ 9.0, or known exploited (KEV), internet-facing asset |
| P2 | CVSS 7.0–8.9 with public PoC, or KEV on internal asset |
| P3 | CVSS 4.0–6.9, no known exploitation |
| P4 | CVSS < 4.0, or not applicable to our stack |
Always check: is the vulnerable component actually reachable in our deployment? If not, downgrade one level and note why.