
News Summary:
A record-breaking 20,130 software vulnerabilities were reported in 2021 - 55 a day on average. However, only 4% of them pose a high risk to organizations.
An organization can greatly reduce its chance of breach, or exploitability score, by up to 29 times by first fixing high-risk vulnerabilities with public exploit code and having a high remediation capacity.
Using Twitter mentions to prioritize software fixes is twice as effective at reducing exploitation as the industry-standard Common Vulnerability Scoring System (CVSS).
SAN JOSE, Calif., Jan. 19, 2021 - New research has quantified the success of various strategies for vulnerability management and the exploitability of entire organizations, expanding the risk-based playbook for cybersecurity practices.
With an average of 55 new software vulnerabilities published every day in 2021, even the best staffed and resourced IT teams cannot fix all of the vulnerabilities across their infrastructures. Fortunately, there is a better solution.
The research conducted by, Kenna Security, now part of Cisco and a market-leader in risk-based vulnerability management, and the Cyentia Institute, shows that properly prioritizing vulnerabilities to fix is more effective than increasing an organizations' capacity to patch them, but having both can achieve a 29 times reduction in an organizations' measured exploitability.
The findings are explained in Kenna's latest report, Prioritization to Prediction, Volume 8: Measuring and Minimizing Exploitability.
Exploitations in the wild used to be the best indicator for which vulnerabilities security teams should prioritize. Now we can show the likelihood of a particular organization being exploited, which is what we've always wanted to do, said Ed Bellis, co-founder and chief technology officer of Kenna Security, now part of Cisco. This gives organizations a much better chance at combating potential cyber threats effectively and the research shows that our customers are successfully managing their vulnerability risk every day.
Exploitability was determined using the open Exploit Prediction Scoring System (EPSS); a cross-industry effort including Kenna Security and the Cyentia Institute that is maintained by FIRST.org.
The research confirms a recent Cybersecurity and Infrastructure Security Agency (CISA) directive that suggests it's wiser to move away from prioritizing fixing of vulnerabilities based on CVSS scores and instead focus on high-risk vulnerabilities. Analysis shows that factors like exploit code and even Twitter mentions are better signals than CVSS scores.
Its clear that a shift to exploitability is going to make a huge difference based on the data and findings in this report. An analysis of CISAs published vulnerabilities suggests that they may also be moving course away from CVSS scores as we were conducting this research, said Wade Baker, partner and co-founder of Cyentia Institute. We took it a step further to account for remediation velocity when making our calculations, which should better inform security teams.
The research also suggests that:
Nearly all (95%) IT assets have at least one highly exploitable vulnerability.
Prioritizing vulnerabilities with exploit code is 11 times more effective than CVSS in minimizing exploitability.
Most (87%) organizations have open vulnerabilities in at least a quarter of their active assets, and 41% of them show vulnerabilities in three of every four assets.
A strong 62% majority of vulnerabilities have less than a 1% chance of exploitation. Only 5% of CVEs exceed 10% probability.
Additional Resources
Read the full report, Prioritization to Prediction, Volume 8: Measuring and Minimizing Exploitability, the latest installment of Kenna Security's series
Read the blog
Engage with Kenna on Twitter, Facebook, and LinkedIn.
About Cisco
Cisco (NASDAQ: CSCO) is the worldwide leader in technology that powers the Internet. Cisco inspires new possibilities by reimagining your applications, securing your data, transforming your infrastructure, and empowering your teams for a global and inclusive future. Discover more on The Network and follow us on Twitter.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. A listing of Ciscos trademarks can be found at www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
06/09/2026
June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
19/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
19/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
19/06/2026
SMPTE , the home of media professionals, technologists and engineers, has announced that its entire Standards catalog is now freely available to the global medi...
19/06/2026
nsign, the digital signage SaaS platform built around its core principle of Simplify Complexity, has announced a partnership with BrightSign , expanding the dep...
19/06/2026
Visual Productions announces the availability of its new RdmRelay2 at InfoComm 2026 (ACT Entertainment, Booth N6813). A networked, four-channel DMX relay, it is...
19/06/2026
Adobe Unveils Major Expansion of Creative Agent Across Firefly and Creative Clou...
19/06/2026
Immersive Studio Metaverse Stage Innovates Storytelling with URSA Cine Immersive
Brie Clayton June 18, 2026
0 Comments
Two new narrative short films c...
19/06/2026
Lab studies explain how new cancer drug works as it enters patient testing Immunologists at Scripps Research show how a new, experimental drug revives immune ce...
18/06/2026
Ratings Roundup is a rundown of recent rating news and is derived from press rel...
18/06/2026
PTZOptics has unveiled new Visual Reasoning demonstrations at InfoComm 2026 (Boo...
18/06/2026
IBC2026 will take place at the RAI Amsterdam from September 11-14, bringing toge...
18/06/2026
InfoComm 2026 held its first-ever Media Day on June 17, providing journalists an...
18/06/2026
FOR-A America has announced a Trade Agreements Act (TAA)-compliant LED display solution combining Alfalite's Litepix LED displays and Brompton Technology...
18/06/2026
In-venue and creative video staffers at the professional and collegiate level have one major thing in common: the intensity and attention to detail ramps up dur...
18/06/2026
The International Federation of American Football (IFAF) and TMRW Sports have an...
18/06/2026
AJA Video Systems has unveiled Io Xpand, a Thunderbolt 5-enabled PCIe expansion ...
18/06/2026
ESPN has announced its coverage plans for the 30th anniversary of the WNBA's...
18/06/2026
FOX Sports' Big Noon Kickoff will broadcast live from Wembley Stadium in Lon...
18/06/2026
InfoComm 2026 opened on Wednesday at the Las Vegas Convention Center, bringing t...
18/06/2026
As media companies look to deliver more live, VOD, and snackable sports content ...
18/06/2026
Top L-R: Take Me Home, The Lake
Bottom L-R: TheyDream, Union County
Free Summer Screening Series Announced
Screenings for the Local Utah Community at...
18/06/2026
Improvements & new IR content
iamReverb Audio have just launched a free update that kits their convolution reverb plug-in out with some new features and int...
18/06/2026
Modelling suite gains improved captures, iOS support & more
Two notes Audio Engineering have just announced the launch of Genome 2.0, a significant update t...
18/06/2026
New AI assistance feature, video overhaul & more
VSL have just announced the launch of Vienna Ensemble Pro 8.1 and 8.1V, a pair of major updates to their ev...
18/06/2026
The average daily TV screen time in May was 3 hours and 36 minutes, marking a clear decrease of 15 minutes compared to April. This trend proved to be much stron...
18/06/2026
Integration embeds Gracenote content intelligence, including contextual segments...
18/06/2026
AJA Video Systems unveiled Io Xpand, a high-performance Thunderbolt 5-enabled PCIe expansion chassis for AJA KONA and Corvid video and audio I/O cards. As dema...
18/06/2026
New NVRT-driven workflow enables on-demand traffic mirroring and guided troubleshooting for AV teams, integrators, and support organizations ahead of InfoComm 2...
18/06/2026
At InfoComm 2026, Mavis announced a major update to Mavis Studio, its live production app for the iPad, with new features designed to make professional AV produ...
18/06/2026
Transaction Positions Harmonic as a Pure-Play Broadband Company
Harmonic Inc. (NASDAQ: HLIT), the worldwide leader in virtualized broadband solutions, today a...
18/06/2026
ACT Entertainment and NETGEAR have announced a strategic partnership that establishes verified interoperability between NETGEAR Switches and key technologies fr...
18/06/2026
IBC2026 is set to bring the global media, entertainment and technology community together at the RAI Amsterdam from 11 14 September, enabling industry players f...
18/06/2026
Pliant Technologies is proud to introduce CrewCom Flex , the world's first frameless matrix intercom system and the only complete matrix IP-based intercom s...
18/06/2026
The XR Sports Alliance (XRSA) has announced that a new cohort of members has joined the strategic initiative: ActionStreamer, Antigravity, Creative Artists Agen...
18/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
18/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
18/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
18/06/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
18/06/2026
Linda May Han Oh Receives Guggenheim Fellowship The Berklee professor, bassist, and composer will use the fellowship to debut Dreams of Knowing, an interdisci...
18/06/2026
In a consequential grid infrastructure decision, the Federal Energy Regulatory C...
18/06/2026
Techtel delivers Haivision live streaming system for TAFE NSW St Leonards, enabl...
18/06/2026
New study reveals 10 hidden data drainers costing Brits hundreds abroad - and the holiday hotspots where you could get rinsed the mostThursday 18 June 2026
The...
18/06/2026
Thursday 18 June 2026
How to watch the 2026/27 Scottish Premiership season on Sky Sports
Which matches are Sky Sports showing on the 2026/27 Scottish Premiers...
18/06/2026
Thursday 18 June 2026
Sky Sale: Latest deals now on, with discounts on iPhone Air & 2.5Gbps speeds
The latest deals have dropped from Sky Mobile, the award-wi...
18/06/2026
FOX Advertising and Toonstar Team to Create New Opportunities for Brands in Digi...
18/06/2026
Arqiva's Crawley Court and Chalfont Grove teleports re-certified at highest World Teleport Association standard
18 June 2026, Winchester, UK - Arqiva, the ...