The Dilemma
Your vulnerability management program faces a pivotal decision: should you continue patching every disclosed CVE, or focus on those vulnerabilities attackers actually exploit?
This isn't just theoretical. With CVE disclosures expected to reach 66,000 by 2026 and the NVD analyzing only 28% of these in 2025, the volume-based approach is unsustainable. Yet, the instinct for completeness persists. The board sees rising counts, audits highlight "unpatched vulnerabilities," and your team measures success by closure rates.
The real question is whether this metric still offers protection.
Comprehensive Patching: The Case for Coverage
Patching broadly addresses the unknown. Just because a vulnerability isn't on the CISA KEV catalog today doesn't mean it won't be exploited tomorrow. While the share of critical vulnerabilities fell from 13% in 2024 to 7% in 2025, thousands of potential entry points remain. Narrowing your focus too much assumes your threat intelligence is complete and current.
Comprehensive patching also aligns with compliance frameworks like SOC 2, which prioritize documented SLAs over EPSS scores. Cyber insurance applications focus on how long vulnerabilities remain open, not how many KEV entries are closed. The regulatory environment still rewards volume metrics.
Practically, patching everything fosters organizational discipline. It ensures asset inventory accuracy, tests deployment pipelines, and builds emergency response readiness. Teams that patch routinely don't panic when a zero-day hits; they execute.
Moreover, the "patch what's exploited" model assumes you'll know when exploitation starts. If attackers move from disclosure to weaponization in hours, your threat feed might lag. The only guaranteed protection is closing the window before it's opened.
Exploitability-Focused Triage: The Case for Precision
The counterargument is clear: you're losing the volume game, and pretending otherwise wastes resources.
EPSS data shows only about 5% of published CVEs are exploited. The CISA KEV catalog grew by 245 new exploited vulnerabilities in 2025 against 48,185 total disclosures. If you treat all CVEs equally, 95% of your efforts target theoretical risks, while actual attacks focus on the 5% you might miss.
The surge in volume is due to AI-assisted discovery surfacing long-standing bugs. For instance, the Linux kernel now accounts for over 5,800 CVEs, with a real-world exploitation rate near 0.02%. You're not patching vulnerabilities; you're patching the discovery process.
Exploitability triage aligns resources with real threats. The window between disclosure and exploitation is shrinking. CISA's shift to a risk-based model, demanding action in as little as three days for high-risk vulnerabilities, underscores that speed matters more than coverage.
Compliance arguments also pivot. If your audit reports "523 open vulnerabilities," but 518 have an EPSS score below 1%, you're documenting noise, not risk. Mature programs focus on actionable threats: KEV entries, high-EPSS flaws in internet-facing systems, and vulnerabilities on your actual attack surface. That's the conversation your board and auditors should have.
The Hybrid Approach
Most security programs are adopting a hybrid model, though few formalize it. Teams patch KEV entries urgently, apply EPSS scoring to others, and use virtual patching or network segmentation to manage high-risk systems while vendor patches lag.
Tooling is a constraint. If your vulnerability scanner only exports raw CVE counts and your patch management system queues everything equally, you're stuck in volume-based workflows. Teams making the shift invest in enrichment platforms that add exploitability intelligence to asset context, feeding into automated triage rules.
Organizational inertia is another hurdle. If your metrics and SLAs focus on "days to patch" and "percent closed," changing the approach requires executive buy-in and process reengineering.
Our Take
Focus on what's exploited, contain what's exploitable, and stop treating everything as urgent.
The volume-based model worked when disclosure counts were manageable and exploitation timelines were longer. That era is over. The NVD can't keep up, your team can't keep up, and attackers aren't waiting.
This doesn't mean ignoring the long tail. Address it during standard maintenance, bundle it with planned releases, and accept that some vulnerabilities will age out before you address them. This isn't negligence; it's resource allocation.
The tradeoff is real. You'll have open CVEs, and questions will arise. Your response should be that you're optimizing for actual risk, not audit aesthetics. If challenged, present the EPSS data and KEV catalog. Ask which vulnerabilities they'd prefer you miss while chasing the 95% that won't be weaponized.
Success in 2026 won't come from patching the most. It'll come from knowing exactly what to patch first.



