CVSS 4.0 Is Here, But Prioritizing Patches Still a Hard Problem
CVSS Version 4 arguably performs better, but companies also need to tailor any measure of threat to their own environment to quickly evaluate new software bugs for patching order.
Scott Walsh Dustin Childs Sasha Romanosky Infrastructure Security Agency Forum Of Incident Response Coalition Exploit Scoring System
Source: darkreading.com