Vulnerability Prioritization Matrix

Select exploitability, business impact, exposure, and four other factors to get a suggested priority, a plain-language explanation, and a remediation timeline — the same reasoning covered in the Vulnerability Prioritization article, made interactive.

Seven Factors

How easy is this to exploit given what's currently known about it?

What happens if this is successfully exploited?

Is the affected component reachable from the public internet?

Does the affected component handle credentials, PII, or other sensitive data?

Does exploitation require an authenticated session?

Is there confirmed evidence of active, in-the-wild exploitation (e.g. a CISA KEV listing)?

How critical is the affected asset to the business?

Answer all seven factors above to see a suggested priority.