Wednesday , October 7 2026

CVSS 4.0 released: The New Standard for Vulnerability Scoring

FIRST has unveiled the latest version of its Common Vulnerability Scoring System (CVSS 4.0). CVSS is important for the connection between suppliers and consumers. It helps identify the main characteristics of security vulnerabilities and gives them a score that shows how serious they are. This helps businesses; service providers, government, and the public understand and deal with the vulnerabilities better.

CVSS 4.0

Contract and server dispute brought down Bangladesh’s digital payment

Bangladesh's digital payments system remains severely disrupted after a technology conflict forces core card and interbank services offline for millions...
Read More
Contract and server dispute brought down Bangladesh’s digital payment

Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Atlassian has fixed CVE-2026-21589, a serious flaw in Atlassian Data Center with a score of 9.3. This bug allows an...
Read More
Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The scores can be classified as low, medium, high, or critical to help organizations evaluate their vulnerability management processes and defend against cyber-attacks. This system lets consumers assess real-time threat and impact, giving them important information to defend against an attack.

ALSO READ:

Only 45% of cloud data is currently encrypted

Common Vulnerability Scoring System

CVSS 4.0 is a widely used standard for vulnerability assessment. It aims to provide accurate vulnerability assessment for organizations and the public. The program improves metrics for consumers, removes scoring ambiguity, simplifies threat metrics, and enhances the assessment of security requirements and controls.

Moreover, various additional characteristics have been incorporated into vulnerability assessment, such as Automatable, Recovery, Value Density, Vulnerability Response Effort, and Provider Urgency. There is also additional applicability to OT/ICS/IoT, with Safety metrics and values added to both the Supplemental and Environmental metric groups.

The road to CVSS 4.0

The sector will transform with the new CVSS 4.0, which will improve its ability to handle threats. Prior to 2005, custom, incompatible rating systems were used to define severity before a need for standardized vulnerability measurements across software and platforms was identified.

CVSS version 1 was released in February 2005 with the goal of being adopted by the industry. FIRST was appointed in April to drive future development of CVSS.

Over a dozen FIRST members of the CVSS Special Interest Group (SIG) collaborated extensively. Throne CVSS version 1 was revised and improved in 2006 and 2007. This was done by testing and re-testing hundreds of real-world vulnerabilities. The result was the release of version 2 in June 2007.

In 2015, a third version of the tool was developed. It introduced the concept of ‘Scope’ to manage the scoring of vulnerabilities. These vulnerabilities may be present in one software component but affect a different software, hardware, or networking component.

A new version, 3.1, was released in June 2019. This version clarified and improved upon version 3.0. It did not add new metrics or values but focused on improving the clarity of concepts and making the standard easier to use. One new addition was the CVSS Extensions Framework.

This release is an important advancement. It has added capabilities that are crucial for teams. These capabilities help with threat intelligence and environmental metrics for accurate scoring.

Another function of note is the nomenclature. CVSS is not just the Base Score, so to further highlight this new nomenclature has been adopted in version 4.0:

CVSS-B: CVSS Base Score

CVSS-BT: CVSS Base + Threat Score

CVSS-BE: CVSS Base + Environmental Score

 CVSS Base + Threat + Environmental Score

Testing CVSS 4.0

Many of the 900 industry leaders, from across the globe, are now testing CVSS version 4.0 in real-time before public launch. Cyber security issues are increasing worldwide. Global coordination is crucial to make the internet safe for everyone. Programs like CVSS 4.0 are important for both the sector and the public.

The CEO of FIRST, Chris Gibson, said that the CVSS system has been developing quickly for the past 18 years. Each new version improves our ability to protect against cyber criminals.

I am immensely proud of the CVSS-SIG for the hard work and dedication it has taken to produce version 4.0. And it is timely as we continue to see a significant rise in threats across the world.”

 

 

Check Also

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. …