Episode
Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited
- Podcast
- Byte Sized Security
- Published
- Sep 10, 2026
- Duration seconds
- 577
- Processing state
not_requested
Actions
POST https://stenobird.com/v1/public/podcasts/byte-sized-security-6574623/episodes/ep46-vulnerability-prioritization-why-98-5-of-cves-are-never-exploited/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/byte-sized-security-6574623/ep46-vulnerability-prioritization-why-98-5-of-cves-are-never-exploited.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Roughly 98.5% of all known CVEs have never been exploited. We break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, hosted by Raphael Mudge on Down the Rabbit Hole, and what it means for how you prioritize a patch queue: CVSS score vs. exploitation evidence vs. insurance-claims data, CISA's free KEV catalog, and why the vulnerability management industry has no incentive to tell you the truth.