← All threats
MEDIUM
Critical Vulnerability Disclosure
New CVE or zero-day disclosure with active exploitation potential. Calls for emergency patch management, compensating controls (WAF, segmentation) and SBOM-driven impact assessment.
New CVE or zero-day disclosure with active exploitation potential. Calls for emergency patch management, compensating controls (WAF, segmentation) and SBOM-driven impact assessment.
MITRE ATT&CK
Tactics, Techniques & Procedures
TA0001 Initial Access
tactic
TA0004 Privilege Escalation
tactic
Defensive mapping
Mapped controls
The audit will verify each of these controls is in place and effective.
| Control | Confidence | Why it matters |
|---|---|---|
| Patch management suggested | 75% | Recommended control for vulnerability |
| Vulnerability scanning suggested | 75% | Recommended control for vulnerability |
| CVE-driven prioritisation suggested | 75% | Recommended control for vulnerability |
| Web application firewall suggested | 75% | Recommended control for vulnerability |
| Network segmentation between user and server tiers suggested | 75% | Recommended control for vulnerability |