<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Severity Tiers on CVE Explained</title>
    <link>https://cveexplained.com/categories/</link>
    <description>Recent content in Severity Tiers on CVE Explained</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>2026 Rietta Inc. All Rights Reserved.</copyright>
    <atom:link href="https://cveexplained.com/categories/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Critical</title>
      <link>https://cveexplained.com/categories/critical/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://cveexplained.com/categories/critical/</guid>
      <description>CVSS 9.0–10.0. In Rietta&amp;rsquo;s practice, a Critical-tier vulnerability is treated as an emergency: patch immediately, out of cycle, especially if the CVE is listed in CISA&amp;rsquo;s Known Exploited Vulnerabilities catalog. Federal civilian agencies are held to specific, often short remediation deadlines for KEV-listed vulnerabilities under CISA&amp;rsquo;s Binding Operational Directive 22-01; private-sector organizations aren&amp;rsquo;t bound by that directive, but treating it as the floor, not the ceiling, is good practice.</description>
    </item>
    <item>
      <title>High</title>
      <link>https://cveexplained.com/categories/high/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://cveexplained.com/categories/high/</guid>
      <description>CVSS 7.0–8.9. A High-tier vulnerability generally does not require dropping everything the way a Critical one does, but it does warrant an accelerated patch timeline, typically within days, rather than waiting for the next regular maintenance window. Whether that&amp;rsquo;s justified depends on exploitability and exposure, which is exactly the judgment call each explainer on this site is written to help with.</description>
    </item>
    <item>
      <title>Medium</title>
      <link>https://cveexplained.com/categories/medium/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://cveexplained.com/categories/medium/</guid>
      <description>CVSS 4.0–6.9. A Medium-tier vulnerability is usually fine to fold into your normal patch cadence rather than an emergency change, unless something about the specific exploit path (public proof-of-concept code, unusual exposure in your own environment) changes that calculus.</description>
    </item>
    <item>
      <title>Low</title>
      <link>https://cveexplained.com/categories/low/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://cveexplained.com/categories/low/</guid>
      <description>CVSS 0.1–3.9. Low-tier findings are worth tracking in your inventory, but on their own they rarely justify an unscheduled change. We cover a Low-tier CVE here when it&amp;rsquo;s notable for some other reason: it&amp;rsquo;s frequently misreported as more severe than it is, or it becomes dangerous only when chained with another issue.</description>
    </item>
  </channel>
</rss>
