CVE-2026-93952: CVSS 10.0 vulnerability in Arista VeloCloud Orchestrator
🔗 https://cybersecurefox.com/en/cve-2026-93952-arista-velocloud-orchestrator-cvss-10-active-exploitation
#CVE-2026-93952 #VeloCloud #Orchestrator #Arista #CVSS #10.0 #SD-WAN
#cvss
5 posts · Last used 13d
CVE-2026-85889: CVSS 10.0 vulnerability in Azure AI Foundry
🔗 https://cybersecurefox.com/en/cve-2026-85889-azure-ai-foundry-cvss-10-privilege-escalation
#CVE-2026-85889 #Azure #AI #Foundry #Microsoft #CVSS #10.0 #privilege #escalation
CVE-2026-76460: Cisco ISE authentication bypass with CVSS 10.0
🔗 https://cybersecurefox.com/en/cve-2026-76460-cisco-ise-authentication-bypass-cvss-10-0
#CVE-2026-76460 #Cisco #ISE #authentication #bypass #CVSS #10.0 #CISA #KEV
Adobe Patches Critical CVE-2026-48449 in Campaign Classic
🔗 https://cybersecurefox.com/en/adobe-campaign-classic-cve-2026-48449-update
#Adobe #Campaign #Classic #Adobe #Bridge #CVE-2026-48449 #CVE-2026-48448 #CVSS #10.0
What does CVSS actually measure? Jay Jacobs, who built EPSS, asked exactly that on LinkedIn and admitted he has never gotten an authoritative answer. 87 comments agreed it is "not risk." None could define "severity."
That is not a CVSS problem. It is a language problem. Our field runs on load-bearing words it never defined.
Held against FAIR, a real risk ontology, CVSS has no frequency term at all, so it structurally cannot be risk. As Sasha Romanosky (@SashaRomanosky@techhub.social) put it, we have "fundamentally lacked that capability as an industry." FAIR and CVSS even use "vulnerability" to mean opposite things: a probability versus the flaw itself.
But CVSS is not fake. It is Ptolemaic: coherent, useful, quietly wrong about its own ontology, like epicycles that predicted the sky for 1400 years on a false model. It is dangerous only when we read severity as risk and build clocks and contracts on the reading.
The fix is already here: CVSS for severity, EPSS for likelihood, KEV for live exploitation, FAIR for loss. CISA's new BOD 26-04 does exactly this. Stop asking one number to be four things.
The Magic Number: https://infosecstoic.substack.com/p/the-magic-number-what-does-cvss-actually
#cybersecurity #vulnerabilitymanagement #CVSS
You've seen all posts
