It’s 2026. It’s faster to fix CVEs than argue about them

There is a lot of buzz regarding reachability and exploitability. Also, following latest Black Hat, there are ~1000 new CVEs reported against Linux kernel (a lot of them relate to privilege escalation). Additionally, a lot of our assumptions, such as those about network isolation, may not hold true in reality.

With that, today frequently it is much faster to point an AI agent against code based on some policies and controlling gate (i.e. ReARM can work as one of those as shown in my video here – https://www.youtube.com/watch?v=kzMzQK511JU , but other tools can be used just as well here).

So there is no need for that old approach where we would cherry-pick CVEs, assign them to teams and wait for resolution. What should be going is bulk clean up all the way with certain restrictions for looking at malware (such as cooldown periods and SBOM diffing). This bulk processing is much faster and more efficient that reachability / exploitability shenanigans which may not even be true in the end of a day.

Leave a comment

Your email address will not be published. Required fields are marked *