Rank by KEV (exploited in the wild) > EPSS (likelihood) > CVSS (severity), then by asset
criticality and exposure. A medium CVSS on a KEV-listed, internet-facing asset outranks a
high CVSS on an isolated host.
| Severity | Remediation window |
|---|---|
| Critical | 7 days |
| High | 30 days |
| Medium | 90 days |
| Low | 365 days |
| KEV match | Automatic uplift (treat as Critical) |
See the vulnerability SLA article.
Kernel updates require a reboot to take effect. A host that installs but does not reboot
remains vulnerable. Always verify the running kernel matches the installed one, and monitor
reboot-required fleet-wide.
silently expire - exceptions must be explicit, owned, and time-boxed.