Join our Newsletter — 33% off our NHI Course
Home› FAQ› What should security teams do when a CVE…

What should security teams do when a CVE has no patch yet?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026

Focus on containment around the exploit behaviour itself. If the vulnerability is being actively abused, use blocking, isolation, or compensating controls against the runtime action instead of waiting for a full remediation cycle. The aim is to reduce exposure before exploitation can continue or recur.

What to do before a patch exists

When there is no fix yet, the right response is to treat the CVE as an exposure problem, not a ticketing problem. Focus on the exploit condition, the affected asset path, and the controls that can prevent the vulnerable behaviour from being reached, repeated, or scaled. If the issue is already being used in the wild, containment should move ahead of waiting for vendor remediation.

The practical question is what can be interrupted right now: network reachability, exposed functionality, dangerous defaults, unsafe inputs, weak trust boundaries, or the runtime action that the exploit depends on. That may mean removing access, isolating the system, disabling the vulnerable feature, tightening allowlists, or applying a compensating control that reduces blast radius while preserving business continuity.

For active exploitation, the priority is to break the attack path before trying to perfect remediation. Security teams should preserve enough telemetry to understand whether the exploit is still active, because containment that destroys visibility can make re-entry or lateral movement harder to detect later.

How containment should be chosen

Containment should match the exploit behaviour, not just the product name. A patchless vulnerability that depends on remote access may be reduced by network filtering or isolation, while a flaw that depends on a specific function, API, or file path may be better handled by disabling that route, limiting who can invoke it, or placing a compensating control in front of it. The control should be strong enough to stop recurrence, not just slow it down.

Where the exploit path involves credentials, sessions, tokens, or service access, the response should also include reducing what those identities can reach. That can mean revoking or rotating the material that grants access, constraining privilege, or severing trust links that let an intruder reuse the same path after an initial foothold. NHIMG’s State of NHI and AI Agent Breach Report 2026 is useful here because it shows how quickly exposed access material can turn a single flaw into broader compromise.

When the issue resembles known exploitation patterns, threat context matters. Security teams can use MITRE ATT&CK Enterprise Matrix to map what the attacker is likely doing after initial exploitation, then align containment to the next expected step rather than only the original CVE.

What good practice looks like while waiting for remediation

Good practice is to run a short, explicit decision loop: confirm whether the CVE is actively exploited, determine which systems are exposed, select the smallest containment that meaningfully breaks the exploit path, and document what business function is being traded off. That is more effective than keeping the issue open and hoping for a near-term patch.

If the exposure is being tracked in official vulnerability feeds, cross-check the record before deciding how much urgency to apply. NIST National Vulnerability Database helps anchor the affected product and severity context, while CISA Known Exploited Vulnerabilities Catalog is the stronger signal when active exploitation has already been confirmed.

Where teams need to prioritise a queue of unpatched CVEs, exploit likelihood and external pressure should shape sequencing. FIRST EPSS is useful for prioritisation, but it should complement, not replace, evidence that the vulnerable path is actually exposed in your environment.

Risk and Threat Considerations

An unpatched CVE is risky because exposure can widen faster than remediation cycles. If the flaw is already being abused, the main danger is not only initial compromise but repeat exploitation, persistence, and lateral movement through the same weak path before a patch becomes available.

Failure mechanism: The attacker relies on an unchanged runtime condition, exposed interface, or permissive trust boundary, then keeps using that same condition until containment breaks the path or the vendor ships a fix.

Impact: Systems can be re-compromised, adjacent services can be reached, and defenders may lose the chance to control blast radius if they wait for remediation instead of suppressing the exploit behaviour itself.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1068 — Exploitation for Privilege EscalationActive CVE abuse often leads to escalation after initial exploitation.
T1190 — Exploit Public-Facing ApplicationPatchless CVEs are often abused through exposed services or apps.
Recommendation — Map the exploit chain and block the follow-on escalation path. Hunt exposed services and constrain public-facing exploit reachability.
CIS Controls v8CIS-12 — Network Infrastructure ManagementContainment commonly depends on segmentation, filtering, and isolation.
Recommendation — Apply network controls to isolate the vulnerable asset and restrict exploit traffic.
NIST CSF 2.0PR.AA-05 — Network IntegrityContainment relies on limiting hostile paths and preserving trusted boundaries.
RS.MA-01 — Incident MitigationActively exploited CVEs require mitigation actions before full remediation exists.
Recommendation — Enforce network integrity controls to reduce exploit reachability. Execute mitigation steps that suppress exploitation and limit spread.

Practitioner Guidance

What to prioritise: Prioritise the exploit path over the existence of the CVE record. If the vulnerability is actively abused, treat reachability, privilege, and recurrence prevention as the first-order problem.

Decision rule: If you can block the abusive behaviour without breaking a critical service, do that first and defer deeper hardening until the patch or vendor workaround is available. If you cannot contain safely, escalate the business risk explicitly rather than leaving the asset exposed by default.

What to verify: Verify that the containment actually stops the vulnerable action, not just the alert. A good test is whether the same attack can still be repeated from another host, session, or route.

Practitioner takeaway: A missing patch is not a reason to wait, it is a reason to narrow exposure aggressively and prove the exploit path no longer works.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org