top of page
Search

It's Not about CVE Volume: The Government Just Put a Number on Vulnerability Noise

  • Writer: Jacob Hughes
    Jacob Hughes
  • 5 days ago
  • 3 min read

While developing the security framework that is foundational to LARCK (Endpoint Capability Risk), I came across two universal asks when I was getting product feedback from CyberSecurity Engineers: First, why do they need another tool to tell them CVE’s when they already have several. Second, and most importantly, each of their tools report basically the same thing: Thousands of CVE’s with most of them flagged as Critical. A resounding “How do we know what to really pay attention to if everything is Critical?”


I knew they were right, because, well… I’ve been there and had the same issue when I was remediating vulnerabilities. There had to be a better way.


It was then that I added a second layer to LARCK: Vulnerability Intelligence that not only answered what they should be focusing on, but also told them in the case of software updates, which update was the safest version to update to. Only Vulns that mattered, and patch guidance.


Trust Me, Bro.


There was one issue though. Everyone is used to chasing these thousands of CVE’s. Now that you’re given only a handful to really focus on… is that accurate? “There has to be something I’m now missing” was the feedback then received. I myself, had that same knee-jerk reaction. I tested the data, over and over, and the methodology was sound.


I added reasoning in LARCK for users to see, but still, it just seemed… untrustworthy and weird to be seeing a dashboard that had 10 things to laser-focus on out of 5,000 CVE’s.


“Trust me guys. This is why LARCK exists. I’ve been spending countless hours upon hours researching and testing the methodology. This works - I even gave you the reasoning in the system”



I didn’t like saying that. It’s hard to gain momentum and traction on a “Trust me.” Then, finally, I no longer had to say that.


The Government Agrees


On June 10, 2026, the federal government made its position official. CISA's Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk," retired severity scores as the basis for deciding what to fix and replaced them with a risk model built on four questions: Is the asset publicly exposed? Is the vulnerability actively exploited (on the KEV catalog)? Can the exploit be automated? Does it hand an attacker real control?


The directive supersedes both BOD 22-01 and BOD 19-02, and it arrives with a finding worth sitting with.


The 1% number

In CISA's own analysis at one large civilian agency, only about 1% of vulnerability instances landed in the top three-day emergency tier, while more than 60% could be deferred entirely to the next system upgrade.



And there it is. On a real backlog, roughly one in a hundred findings needed out-of-cycle emergency action.


This is not a claim that 99% of vulnerabilities are harmless. It is a claim that severity alone has almost no relationship to urgency. A CVSS 9.8 on an internal, non-exploited, non-automatable flaw is not a fire. A lower-scored bug that is exploited in the wild on an exposed asset is. The government just spent a binding directive to say so.


What this looks like in practice

Using LARCK, looking at a small sample of roughly 30 Windows machines, for 3rd party software: there were 1,517 open vulnerability instances, 657 unique CVEs. Filtered through the SSVC decision model that underpins CISA's new approach, the picture collapsed:


Emergency, out-of-cycle action required: 0


Accelerated attention: 0


Monitor for change: 3


Routine, clear on the normal patch cycle: 194


Present on CISA's KEV catalog: 0


More than a thousand raw findings reduced to three items worth a second look, and zero real emergencies.


Get rid of the CVE's that don't matter. Focus on the ones that do.


This is what LARCK does

LARCK was built on exactly this principle, and it was built before the directive made it federal policy. It reads your existing asset and vulnerability data on premises, read-only, and applies risk-based prioritization aligned with the SSVC methodology CISA now points to.



I can now say “Don’t take my word for it, the Government’s just codified it into directives”


Does your security tool do that? Probably not. LARCK does.



-Jacob Hughes



Sources: CISA BOD 26-04, "Prioritizing Security Updates Based on Risk" (June 10, 2026); CISA, "Patch Smarter, Not Harder" (June 10, 2026).

 
 
 

Recent Posts

See All

Comments


Contact

3056 S Camino Lagos

Grand Prairie, TX 75054

info@zilllabs.com

Be in the Know

Be notified of product additions, feature updates, promotions, and news/articles.  No spam. No selling. No sharing.

Follow us on

© 2026 by Zill IT Labs, LLC

bottom of page