Episode

Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited

Podcast
Byte Sized Security
Published
Sep 10, 2026
Duration seconds
577
Processing state
not_requested
Canonical source
https://bytesizedsecurity.show/episode/ep46-vulnerability-prioritization-why-98-5-of-cves-are-never-exploited
Audio
https://pdcn.co/e/episodes.captivate.fm/episode/0d80418d-ac30-4432-a2c7-7ee6d5cd5df7.mp3
JSON
/v1/public/podcasts/byte-sized-security-6574623/episodes/ep46-vulnerability-prioritization-why-98-5-of-cves-are-never-exploited
Markdown
/podcast/byte-sized-security-6574623/ep46-vulnerability-prioritization-why-98-5-of-cves-are-never-exploited.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/byte-sized-security-6574623/episodes/ep46-vulnerability-prioritization-why-98-5-of-cves-are-never-exploited/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/byte-sized-security-6574623/ep46-vulnerability-prioritization-why-98-5-of-cves-are-never-exploited.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Roughly 98.5% of all known CVEs have never been exploited. We break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, hosted by Raphael Mudge on Down the Rabbit Hole, and what it means for how you prioritize a patch queue: CVSS score vs. exploitation evidence vs. insurance-claims data, CISA's free KEV catalog, and why the vulnerability management industry has no incentive to tell you the truth.