Episode 46

full
Published on:

10th Sep 2026

Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited

Roughly 98.5% of all known CVEs have never been exploited. In this episode I break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, and host Raphael Mudge, on the Down the Rabbit Hole podcast, and what it means for how you prioritize a patch queue. I cover CVSS score versus exploitation evidence, how to use CISA's free KEV catalog, why the vulnerability management industry has no incentive to tell you the truth, and what separates a junior-sounding answer from a senior one in a security interview.

In this episode:

  • (00:00) The scan report that isn't as urgent as it looks
  • (01:03) The 98.5% number and the mechanic analogy
  • (02:01) Why the industry defaulted to patch everything
  • (03:00) The 36-hour outage from a perfect-10 patch
  • (03:48) CVSS score vs. exploitation evidence vs. insurance-claims data
  • (05:08) What it sounds like when someone understands this in an interview
  • (06:15) Why the industry has no brakes, and the AI-hype myth
  • (07:49) Your homework

Links:

Not financial or legal advice. Figures cited reflect Root Evidence's analysis as discussed on the source podcast episode.

I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

--

Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

Listen to Byte Sized Security

--

Support this Podcast with a Tip:

Support Byte Sized Security

--

If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

Support Byte Sized Security

A huge thank you to our supporters, it means a lot that you support our podcast.

If you like the podcast and want to support it, too, you can leave us a tip using the button below. We really appreciate it and it only takes a moment!
Support Byte Sized Security
A
We haven’t had any Tips yet :( Maybe you could be the first!
Show artwork for Byte Sized Security

About the Podcast

Byte Sized Security
Snackable advice on cyber security best practices tailored for professionals on the go
In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go.

Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more.

Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out.

Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.
Support This Show

About your host

Profile picture for Marc David

Marc David

Marc David is a CISSP-certified Staff Security Engineer with 8+ years in dedicated security roles inside regulated healthcare, and the host of Byte-Sized Security. He describes his work in one line: "I get security tooling adopted by engineering teams who do not report to me." Most security programs fail at adoption, not at tool selection. Marc has driven API security monitoring, device trust, browser-based data loss prevention, and continuous mobile penetration testing to full coverage across engineering, IT, and platform groups where he holds no authority over anyone. His background spans HIPAA, HITRUST, and SOC 2 compliance, security automation, and awareness training built for people who never wanted training. Marc lives in the San Francisco Bay Area and speaks on security adoption, healthcare compliance, and automation.