Which vulnerabilities should be prioritised for patching?
- A Those actively exploited on internet-facing systems
- B Those with the longest CVE identifiers
- C Those in the oldest software
- D Those affecting the fewest systems
Answer
Those actively exploited on internet-facing systems
CISA's Known Exploited Vulnerabilities catalogue lists what is actually being used in attacks, which is more actionable than severity alone.





