
Common Vulnerability Scoring System
Industry-standard 0-10 vulnerability severity scale; a high score alone does not mean active exploitation.
The Common Vulnerability Scoring System is the industry-standard 0-10 severity scale used by CISA, NCSC and NVD. A high score alone does not mean active exploitation: F5's CVE-2025-53521 sat at medium severity until reclassified to 9.8 on 28 March 2026, after exploitation was confirmed.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Is a CVSS 7.5 in active exploitation more dangerous than a 9.8 that is not?
Timeline for Common Vulnerability Scoring System
Mentioned in: Magento RCE forces 9-day patch race
Cybersecurity: Threats and DefencesMentioned in: UAT-8616 keeps Cisco SD-WAN under fire
Cybersecurity: Threats and DefencesMentioned in: CISA deadline for PAN-OS RCE lands four days early
Cybersecurity: Threats and DefencesMentioned in: Trump proposes $707m CISA cut, 860 jobs
Cybersecurity: Threats and DefencesMentioned in: F5 reclassifies DoS bug to 9.8 RCE
Cybersecurity: Threats and DefencesBackground
The Common Vulnerability Scoring System (CVSS) is the standard framework CISA, NCSC, NVD and vendors use to assign numerical severity scores to software vulnerabilities, from 0.0 (none) to 10.0 (critical). The current version, CVSS v4.0, was published by FIRST, the Forum of Incident Response and Security Teams, in 2023, and comprises base, threat and environmental metrics; most vendor advisories publish only the base score.
The scheme has a structural weakness: scores are assigned at disclosure but exploitation can change the risk picture afterwards. CVE-2026-3055 (CitrixBleed 3) was scored 9.3 at disclosure, while F5's CVE-2025-53521 was rated medium severity before being reclassified to 9.8 once active exploitation was confirmed.
A high base score is not the same as active threat-actor prioritisation, and a lower one does not mean SAFE. The June 2026 KEV batch made the point starkly: a maximum-severity Magento flaw drew the loudest coverage and the tightest Deadline, while an older, lower-scored Oracle WebLogic bug was already delivering ransomware payloads via honeypot-observed traffic before it reached the list. Security teams that treat CVSS as their only triage signal are systematically under-weighting vulnerabilities whose exploitation class shifts after initial assessment.