What a CVSS Score Really Means — And Why “Critical” Isn’t Always Urgent
Every security advisory we publish leads with a number — “CVSS 9.6”, “CVSS 10”. CVSS, the Common Vulnerability Scoring System, is a standardised 0-to-10 rating of how severe a software flaw is, with anything 9.0 and above labelled “critical”. It’s the shorthand the whole industry uses, and it turns up in nearly every cybersecurity bulletin you’ll read.
Severity isn’t the same as urgency
Here’s the part the number doesn’t tell you: a high CVSS score on its own doesn’t decide whether you patch tonight or next fortnight. Two other things matter more. Is the flaw actually being exploited in the wild, and is the affected system reachable from the internet? That’s exactly why the US cyber agency maintains its Known Exploited Vulnerabilities catalogue — a shortlist of flaws attackers are genuinely using right now. A CVSS 7.5 that’s on that list and facing the internet is a far bigger problem than a CVSS 9.8 buried on an internal server nobody outside your office can reach.
How we triage it in Australian environments
Australia’s ACSC builds this thinking into the Essential Eight: patch internet-facing critical vulnerabilities within 48 hours, and everything else within two weeks. In practice, across our client environments we ask three questions before we even look at the CVSS number — is it on the KEV list, is it internet-facing, and can we actually reach the machine to patch it? That last one bites hardest at regional sites. A single-site office in Orange or Bathurst on thinner connectivity can’t always pull a box offline mid-shift, so “48 hours” becomes a scheduling problem, not just a technical one.
So next time an advisory quotes a frightening number, don’t panic on the score alone — ask whether it’s being exploited and whether it’s exposed. If you’d rather not decode every bulletin yourself, that triage is part of what our managed IT support team does every day.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
