The technology businesses depend on every day also creates openings for attackers, and the vulnerability queue isn’t getting shorter. CVE submissions to NIST’s National Vulnerability Database increased 263% between 2020 and 2025, and submissions in the first three months of 2026 were nearly one-third higher than during the same period a year earlier. For security teams, that volume makes treating every newly disclosed flaw as an isolated problem increasingly difficult—and risks turning vulnerability management into an endless cycle of finding, prioritizing and patching.
Security leaders need to look beyond individual CVEs and address the recurring weaknesses that keep generating new vulnerabilities. Recent analysis of more than 39,000 CVE records highlights how identifying recurring root causes can inform security investments and development practices aimed at eliminating entire classes of defects. The challenge for security leaders is doing that longer-term work without losing sight of vulnerabilities that pose an immediate threat to the business.
Members of the Senior Executive Cybersecurity Think Tank bring deep experience in enterprise cybersecurity strategy, risk management, threat detection, secure architecture and breach prevention. Below, three of them share how security leaders can balance urgent remediation with a more systemic approach to vulnerability management—reducing today’s risk while working to prevent the same kinds of flaws from resurfacing tomorrow.
“Prioritization is essential given that many CVEs are simply never exploited.”
Pair Prioritization With Root Cause Analysis
Eoin Keary, CEO of Edgescan Inc., says two strategies are needed: strong prioritization of discovered CVEs and ongoing trend and root cause analysis.
“Prioritization is essential given that many CVEs are simply never exploited,” he explains. “We need to ask, for example, ‘Is there exploit code in the wild for that CVE? Is it in the CISA KEV?’”
Keary also argues that what organizations learn about vulnerabilities should shape how they approach similar risks going forward.
“Trending and root cause analysis can power problem-based awareness, focused prevention and training on both pre- and post-deployment measures,” he says. “Questions here include, ‘Which technology is problematic?’ and, ‘Which development teams are building insecure code?’”
Use Vulnerability Trends to Reduce Recurrence
Bhavya Bhandari, Cybersecurity Risk Management Leader, Financial Services at Ernst & Young US LLP, stresses the importance of looking beyond the vulnerabilities demanding immediate attention.
“Patching individual vulnerabilities remains important, but sustainable risk reduction comes from managing the conditions that create them,” he says.
OWASP’s current application security guidance similarly calls for analyzing vulnerability data for root causes and recurring patterns that can drive systemic improvements across an organization.
Bhandari notes that prevention, not just remediation, is an important goal.
“The more mature institutions leverage vulnerability trends to identify systemic weaknesses and drive improvements to prevent issues from recurring,” he says.
“Layering in malicious indicators and vectors turns a generic CVE list into a prioritized and personalized risk dossier.”
Build Two Tracks for Remediation and Prevention
Kumar Ritesh, Founder, Chairman and CEO of CYFIRMA, says security leaders need two tracks.
“Immediate remediation should move beyond CVSS, prioritizing by threat actor interest and intent, active exploitation campaigns, real exploitability, attack path to critical assets, and accessibility to attackers,” he explains. “Layering in malicious indicators and vectors turns a generic CVE list into a prioritized and personalized risk dossier.”
Turning to the longer-term view, Ritesh suggests strategies to reduce the volume of future vulnerabilities entering the pipeline.
“Track recurring defect classes across incidents and fix them structurally through secure coding standards, memory-safe languages and architecture reviews,” he says.
He concludes with a practical approach for bringing the two tracks together.
“Pair rapid response using live threat intel for actively targeted CVEs with preemptive external threat management that continuously monitors adversary activity, campaigns and exposure before exploitation ever reaches your perimeter.”
Turn Vulnerability Data Into Lasting Risk Reduction
- Prioritize vulnerabilities according to real-world risk. Consider factors such as evidence of exploitation and inclusion in CISA’s Known Exploited Vulnerabilities Catalog when deciding what requires immediate attention.
- Look for patterns behind individual CVEs. Trend and root cause analysis can reveal recurring problems with particular technologies, development practices or teams and inform future prevention efforts.
- Address the conditions that keep producing vulnerabilities. Patching individual flaws remains necessary, but reducing recurring risk also requires identifying and correcting systemic weaknesses.
- Use vulnerability trends to guide broader improvements. Patterns across past findings can help organizations identify where changes may prevent similar issues from recurring.
- Run remediation and prevention as parallel tracks. Security teams can respond quickly to immediate threats while also pursuing structural fixes such as secure coding standards, memory-safe languages and architecture reviews.
- Bring current threat intelligence into vulnerability decisions. Information about active campaigns, attacker interest, exploitability and exposure can help security leaders distinguish the vulnerabilities demanding immediate action from the broader backlog.
Move From an Endless Queue to a More Resilient Model
The steady flow of newly disclosed vulnerabilities means individual remediation is unavoidable—but it also exposes the limits of treating every CVE as a separate problem. Effective vulnerability management requires both prioritizing the flaws that pose the greatest immediate risk and identifying recurring patterns that point to deeper weaknesses.
Over time, that balance can shift vulnerability management from a largely reactive exercise toward one that reduces the conditions that allow familiar problems to keep resurfacing. Security leaders may never eliminate the vulnerability queue, but they can work to make each new disclosure less likely to represent the same old problem in a different package.
MOST POPULAR
Top 500 CTOs to Watch in America
9 Ways to Measure the Success of Your DEI Strategy in 2023
Inspiring Ideas. Actionable Insights.
Senior Executive's Email Newsletters Deliver Fresh Solutions to Today's Leadership Challenges.
Subscribe Free
How to Prevent Cascading Failures in Agentic AI
Leadership Development in a Changing World: Strategies for Growth
AI Meets Blockchain: Real Use Cases and Hidden Risks
