Guide
How to triage a new vulnerability
A practical sequence for deciding whether an advisory affects your environment and what to do next.
Identify the exact product
Record the vendor, product, affected versions and deployment context. A product-name match is not version detection and should never trigger a blind patch claim.
Check urgency
Look for exploitation status, required access, public proof of concept and the vendor's remediation or mitigation. Keep those facts separate from severity labels.
Close the loop
Assign an owner, capture the evidence and verify the fix or mitigation in the environment. If the advisory does not say, record the unknown instead of treating it as safe.
What this guide does not cover
This is a triage workflow, not a substitute for your incident-response plan.
Links checked
- CISA Known Exploited Vulnerabilities Catalog — https://www.cisa.gov/known-exploited-vulnerabilities-catalogchecked
- NIST National Vulnerability Database — https://nvd.nist.gov/checked