Thursday, 3 September 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Drowning in CVEs and thirsty for answers? Try CTEM

The Register ·
Drowning in CVEs and thirsty for answers? Try CTEM

A decade or two ago, board executives asked "why should I care about cybersecurity?" Five years ago, they were asking "Are you patching our software vulnerabilities?" Now, they're starting to ask: "Are we actually secure?" They might want a simple 'yes' or 'no' initially, but eventually they'll say the most dreaded thing of all, and it'll be a demand, not a question: "Prove it".

Traditional vulnerability management and patching, won't survive that conversation.

It's why a relatively new approach is gaining traction: Continuous Threat Exposure Management (CTEM).

What's wrong with vulnerability management We define security flaws using Common Vulnerabilities and Exposures (CVEs), and we tell each other how bad they are by assigning the Common Vulnerability Scoring System (CVSS) to them.

There are three problems with that.

There's a firehose of CVEs, the CVSS scores aren't helpful when triaging them, and AI is about to make the whole thing much worse.

CISOs are drowning in CVEs.

The industry has spent decades creating tools that churn out vulnerability data and others that consume it.

Few if any tell you which vulnerabilities an attacker could use to hurt you in your environment.

The volume of CVEs is making traditional vulnerability management (patch it and forget it) less tractable every year, says Drew Vanover, principal security strategist at Horizon3.

"Think about the last patch release that Microsoft put out," he says.

"There were over 500 fixes in one patch cycle.

That is incomprehensible.

Nobody is going to be able to go through, vet, prioritize, and deploy all of those in a way that is truly considered safe." The number of CVEs created each year has been soaring, putting more pressure on the US’ National Institute for Standards and Technology's National Vulnerability Database, which has now been backlogged for years.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›