How prioritisation works
The VA module pulls CVE data, then re-ranks against:
- Active OTM exploitation telemetry
- Sector-specific attack campaigns (e.g. SACCO mobile-banking exploits)
- Asset criticality from your CMDB
- Reachability — is the vulnerable service even exposed?
A CVSS 9.8 on an air-gapped lab box drops below a CVSS 6.4 on the customer-facing payment gateway. Engineers patch the right things.