September 18th, 2026
Myth #6: Cyber Risk Is Determined Only by CVSS Scores

Break the Myth #6
Myth: Cyber Risk Is Determined Only by CVSS Scores
Reality: Cyber risk depends on context—not just vulnerability severity.
A common misconception in cybersecurity is that vulnerabilities with the highest Common Vulnerability Scoring System (CVSS) scores should always receive the highest remediation priority. CVSS provides an important measure of the technical severity of a vulnerability, but severity alone does not tell us how much risk that vulnerability creates within a specific organization.
Consider two vulnerabilities:
Vulnerability A: CVSS 9.8, located on an isolated, non-critical system with no evidence of active exploitation.
Vulnerability B: CVSS 7.5, located on an Internet-connected medical device, actively exploited in the wild, and potentially providing an attack path toward critical hospital systems.
Which one should be investigated first?
In many situations, Vulnerability B may represent the greater operational risk, despite having the lower CVSS score.
Within the AIAGENT4CYBER project, we are exploring how Knowledge Graphs, Multi-Agent AI, Graph Neural Networks (GNNs), Large Language Models (LLMs), and cyber threat intelligence can provide more dynamic and context-aware cyber risk assessment.
Instead of considering CVSS in isolation, cyber risk can be evaluated using multiple interconnected factors, including:
CVSS – How technically severe is the vulnerability?
EPSS – How likely is the vulnerability to be exploited?
Threat Intelligence – Is there evidence of active exploitation, malware, ransomware, or threat-actor activity?
Asset Criticality – Does the vulnerability affect a critical server, IoMT device, EHR system, or essential clinical service?
Exposure – Is the vulnerable asset Internet-facing or otherwise reachable by an attacker?
Attack Paths – Could exploitation provide a route toward other critical systems?
Business and Clinical Impact – Could exploitation disrupt healthcare delivery, compromise sensitive information, or affect patient safety?
Knowledge Graph Relationships – How is the vulnerable asset connected to users, applications, devices, services, vulnerabilities, and other infrastructure?
Knowledge Graphs are particularly valuable because cyber risk is relational. A vulnerability that appears moderate when examined independently may become critical when connected to an exposed IoMT device, privileged account, sensitive clinical database, or feasible lateral-movement path.
For example, instead of simply reporting:
“CVE-XXXX: CVSS 7.5 – High Severity”
a context-aware AI system could provide:
“High operational risk: the vulnerability affects an Internet-accessible IoMT device supporting a critical clinical workflow. Threat intelligence indicates increased exploitation probability, and Knowledge Graph analysis identifies a potential lateral-movement path toward critical hospital information systems. Immediate investigation is recommended.”
This transforms vulnerability management from severity-based ranking into evidence-based risk prioritization.
By combining vulnerability severity, exploitability, threat intelligence, asset importance, exposure, attack paths, and organizational context, AI systems can help cybersecurity teams answer the question that matters most:
Not simply “Which vulnerability has the highest CVSS score?” but “Which vulnerability represents the greatest risk to our organization right now?”
For healthcare and IoMT environments, this distinction is particularly important. Cybersecurity decisions must consider not only technical consequences but also service availability, sensitive health information, clinical workflow continuity, and potential patient-safety implications.
The future of vulnerability management is therefore not about replacing CVSS. It is about enriching CVSS with context to enable more intelligent, dynamic, and explainable cyber risk prioritization.
If two vulnerabilities have the same CVSS score, what factor would you consider most important for deciding which one to remediate first?
