Focus on containment around the exploit behaviour itself. If the vulnerability is being actively abused, use blocking, isolation, or compensating controls against the runtime action instead of waiting for a full remediation cycle. The aim is to reduce exposure before exploitation can continue or recur.
What to do before a patch exists
When there is no fix yet, the right response is to treat the CVE as an exposure problem, not a ticketing problem. Focus on the exploit condition, the affected asset path, and the controls that can prevent the vulnerable behaviour from being reached, repeated, or scaled. If the issue is already being used in the wild, containment should move ahead of waiting for vendor remediation.
The practical question is what can be interrupted right now: network reachability, exposed functionality, dangerous defaults, unsafe inputs, weak trust boundaries, or the runtime action that the exploit depends on. That may mean removing access, isolating the system, disabling the vulnerable feature, tightening allowlists, or applying a compensating control that reduces blast radius while preserving business continuity.
For active exploitation, the priority is to break the attack path before trying to perfect remediation. Security teams should preserve enough telemetry to understand whether the exploit is still active, because containment that destroys visibility can make re-entry or lateral movement harder to detect later.
How containment should be chosen
Containment should match the exploit behaviour, not just the product name. A patchless vulnerability that depends on remote access may be reduced by network filtering or isolation, while a flaw that depends on a specific function, API, or file path may be better handled by disabling that route, limiting who can invoke it, or placing a compensating control in front of it. The control should be strong enough to stop recurrence, not just slow it down.
Where the exploit path involves credentials, sessions, tokens, or service access, the response should also include reducing what those identities can reach. That can mean revoking or rotating the material that grants access, constraining privilege, or severing trust links that let an intruder reuse the same path after an initial foothold. NHIMG’s State of NHI and AI Agent Breach Report 2026 is useful here because it shows how quickly exposed access material can turn a single flaw into broader compromise.
When the issue resembles known exploitation patterns, threat context matters. Security teams can use MITRE ATT&CK Enterprise Matrix to map what the attacker is likely doing after initial exploitation, then align containment to the next expected step rather than only the original CVE.
What good practice looks like while waiting for remediation
Good practice is to run a short, explicit decision loop: confirm whether the CVE is actively exploited, determine which systems are exposed, select the smallest containment that meaningfully breaks the exploit path, and document what business function is being traded off. That is more effective than keeping the issue open and hoping for a near-term patch.
If the exposure is being tracked in official vulnerability feeds, cross-check the record before deciding how much urgency to apply. NIST National Vulnerability Database helps anchor the affected product and severity context, while CISA Known Exploited Vulnerabilities Catalog is the stronger signal when active exploitation has already been confirmed.
Where teams need to prioritise a queue of unpatched CVEs, exploit likelihood and external pressure should shape sequencing. FIRST EPSS is useful for prioritisation, but it should complement, not replace, evidence that the vulnerable path is actually exposed in your environment.
Risk and Threat Considerations
An unpatched CVE is risky because exposure can widen faster than remediation cycles. If the flaw is already being abused, the main danger is not only initial compromise but repeat exploitation, persistence, and lateral movement through the same weak path before a patch becomes available.
Failure mechanism: The attacker relies on an unchanged runtime condition, exposed interface, or permissive trust boundary, then keeps using that same condition until containment breaks the path or the vendor ships a fix.
Impact: Systems can be re-compromised, adjacent services can be reached, and defenders may lose the chance to control blast radius if they wait for remediation instead of suppressing the exploit behaviour itself.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1068 — Exploitation for Privilege Escalation | Active CVE abuse often leads to escalation after initial exploitation. |
| T1190 — Exploit Public-Facing Application | Patchless CVEs are often abused through exposed services or apps. | |
| Recommendation — Map the exploit chain and block the follow-on escalation path. Hunt exposed services and constrain public-facing exploit reachability. | ||
| CIS Controls v8 | CIS-12 — Network Infrastructure Management | Containment commonly depends on segmentation, filtering, and isolation. |
| Recommendation — Apply network controls to isolate the vulnerable asset and restrict exploit traffic. | ||
| NIST CSF 2.0 | PR.AA-05 — Network Integrity | Containment relies on limiting hostile paths and preserving trusted boundaries. |
| RS.MA-01 — Incident Mitigation | Actively exploited CVEs require mitigation actions before full remediation exists. | |
| Recommendation — Enforce network integrity controls to reduce exploit reachability. Execute mitigation steps that suppress exploitation and limit spread. | ||
Practitioner Guidance
What to prioritise: Prioritise the exploit path over the existence of the CVE record. If the vulnerability is actively abused, treat reachability, privilege, and recurrence prevention as the first-order problem.
Decision rule: If you can block the abusive behaviour without breaking a critical service, do that first and defer deeper hardening until the patch or vendor workaround is available. If you cannot contain safely, escalate the business risk explicitly rather than leaving the asset exposed by default.
What to verify: Verify that the containment actually stops the vulnerable action, not just the alert. A good test is whether the same attack can still be repeated from another host, session, or route.
Practitioner takeaway: A missing patch is not a reason to wait, it is a reason to narrow exposure aggressively and prove the exploit path no longer works.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org