Tenable Research built a directed graph model linking 600+ threat actor groups to vulnerabilities detected across 7,800 U.S. and Canadian organizations. Key findings: 68% of organizations carry at least one CVE previously exploited by a named adversary; 321 tracked threat groups can reach at least one customer environment through an active vulnerability. A subset of 242 'Elite Arsenal' CVEs — meeting all three criteria of critical VPR (≥9), CISA KEV listing, and documented threat group exploitation — are nearly universally present, with 241 of 242 actively detected. More than half are five or more years old, and 78% are simultaneously weaponized by nation-state APTs, commodity malware, and ransomware gangs. Non-CVE exposures (misconfigurations, weak credentials, end-of-life software) are present in virtually 100% of studied organizations, with 60% mapping to tracked threat actor techniques. The post argues that per-CVE scoring alone is insufficient and that adversary-aware, graph-based prioritization is necessary to focus finite remediation capacity on the highest real-world risk.

16m read timeFrom securityboulevard.com
Post cover image
Table of contents
Key takeawaysUnderstanding the vulnerability and remediation landscapeBuilding the threat-exposure graphTenable findingsClosing the loop
80 Impressions