TL;DR: Enterprises are publishing 48,185 CVEs in 2025, up 20.6% from 2024, and manual triage cannot keep pace with the volume, context and remediation handoffs required for effective vulnerability management, according to Torq. Prioritization now depends on combining severity, exploitability, asset criticality and automation so security teams can focus on exposure that truly changes risk.
NHIMG editorial — based on content published by torq: Vulnerability prioritization is becoming an automation problem
By the numbers:
- In 2025, 48,185 CVEs were published, a 20.6% increase from 2024's 39,962.
Questions worth separating out
Q: How should security teams prioritise vulnerabilities after an external scan?
A: Prioritise vulnerabilities by exposure, exploitability, and the identity path they can reach.
Q: Why do high CVSS scores often fail to reflect real business risk?
A: CVSS measures technical severity, but it does not know whether a vulnerable system is business-critical, internet-facing or protected by segmentation.
Q: What breaks when vulnerability prioritization stays manual?
A: Manual prioritisation breaks at scale because analysts cannot keep up with scanner volume, data silos and handoff delays.
Practitioner guidance
- Build an exposure-weighted prioritisation model Rank vulnerabilities using CVSS, exploitability, asset criticality, internet exposure and compensating controls before assigning remediation order.
- Connect prioritisation to source systems Feed scanner output into CMDB, asset inventory, threat intelligence and ticketing platforms so findings arrive with enough context to make a decision.
- Automate triage before automating remediation Start with rule-based classification, false-positive suppression and routing before moving to ticket creation or patch orchestration.
What's in the full article
Torq's full article covers the operational detail this post intentionally leaves for the source:
- Workflow design examples for translating scanner output into triage, escalation and remediation steps
- Specific integration points for CMDBs, SIEMs, ticketing platforms and patch management systems
- Practical examples of how business context changes the priority of the same CVE across different assets
- The article's own staged rollout approach for moving from manual triage to automated remediation
👉 Read Torq's analysis of vulnerability prioritization and agentic SOC automation →
Vulnerability prioritization and agentic automation: are your workflows keeping up?
Explore further
Vulnerability prioritization is now a governance problem, not just a scanning problem. The article correctly shows that severity scores do not resolve the central issue, which is deciding what to fix first when context is fragmented across tools and teams. In practice, the control gap is not visibility alone but decision quality at scale. Practitioners should treat prioritisation as a governed workflow that links technical risk, asset value and business impact.
A question worth separating out:
Q: How do automation workflows improve vulnerability remediation governance?
A: Automation improves governance when it makes prioritisation consistent, auditable and faster without removing human judgment from exceptions. It can enrich findings, create tickets, notify owners and update status automatically. That reduces the gap between identifying a risky vulnerability and actually getting it fixed.
👉 Read our full editorial: Vulnerability prioritization is becoming an automation problem