CVSS
Common Vulnerability Scoring System (CVSS) is an open industry standard for describing the characteristics of security vulnerabilities. It provides a quantitative measure of the severity of a vulnerability, enabling organizations to prioritize remediation efforts.
Core Components
- Base Metrics: Inherent characteristics of a vulnerability that are constant over time and across user environments.
- Temporal Metrics: Characteristics that change over time, such as the availability of exploits or remediation.
- Environmental Metrics: Characteristics specific to a particular organization’s computing environment.
Current Status and Evolution
As of mid-2026, the relevance and application of CVSS are undergoing significant scrutiny due to the emergence of Open-Weight AI and complex threat landscapes.
- Limitations in AI Context: Traditional CVSS scoring struggles to quantify risks associated with model weights, prompt injection, and data poisoning in large-language-models.
- CISA Prioritization Shifts: The Cybersecurity and Infrastructure Security Agency (CISA) is moving beyond static CVSS scores toward dynamic prioritization models that account for exploitability and asset criticality in real-time.
- Industry Discourse: Recent discussions suggest a potential “end of CVSS” as a standalone metric, advocating for hybrid models that integrate contextual risk data. See Open-Weight AI Security Risks and CISA’s Vulnerability Prioritization Model for detailed analysis on how open-weight AI risks are reshaping vulnerability assessment frameworks.