Triage Room
0%

of today actively exploited vulnerabilities looked harmless when they appeared

Anyone who prioritizes patching by the score on release day is looking at the wrong snapshot. Most vulnerabilities under real-world attack today entered the database with low risk — and matured in silence. Look at the numbers.

Of the vulnerabilities under active attack today (CISA KEV), 86% had low risk (EPSS < 10%) in their first week of life.

Meaning: filtering by initial score would have missed 8 out of 10.

6.7%avg risk on arrival
48.2%avg risk today
7.3×
The ones that fooled everyone
born nearly invisible · under active attack today
The arrival queue
0 / new vulnerabilities per day (last 60 days)
Triage
of recent vulnerabilities, by real severity (Vexday Risk Score)
Code red 0%Urgent 0%Watch 11%Stable 89%
The patient who worsens
the EPSS of each CVE measured on arrival and over time
0.17%
on arrival
0.39%
+7 days
0.53%
+30 days
0.79%
+90 days

A CVE average risk (EPSS) grows 4.5× times between arrival and +90 days. 1% jumped from quiet to elevated risk within 90 days. That is why a low score on a freshly published CVE is provisional — not safe.

Tracking this triage by hand, every day, is unfeasible. That is exactly what TrueHacking does for you.