Use this checklist when a vulnerability has active exploitation, KEV inclusion, material external exposure or another reason for accelerated handling. Adapt timings and escalation paths to your organisation.
1. Validate the alert
- Confirm the CVE, affected products and versions.
- Check vendor guidance and authoritative references.
- Verify scanner confidence and remove obvious false positives.
- Record when the assessment started and who is leading it.
2. Establish exposure
- Identify affected assets and accountable service owners.
- Confirm internet reachability and network paths.
- Check identity, privilege and user-interaction requirements.
- Identify critical services, sensitive data and dependent systems.
- Check whether telemetry shows attempted or successful exploitation.
3. Decide the response
- Assign an evidence-based priority and deadline.
- Choose patch, mitigation, isolation, removal or temporary containment.
- Confirm change, outage and rollback requirements.
- Escalate blockers to the risk owner, not only the technical team.
- Notify incident response if exploitation cannot be ruled out.
4. Apply interim controls
- Restrict external access where possible.
- Disable affected features or services where supported.
- Apply vendor-recommended mitigations.
- Increase logging, alerting and threat hunting.
- Document the protection provided and its limitations.
5. Remediate and validate
- Apply the approved update or permanent treatment.
- Rescan or retest the affected assets.
- Confirm the vulnerable version or attack path has been removed.
- Review logs for compromise during the exposure period.
- Capture closure evidence and residual risk.
6. Learn
- Identify why the vulnerable asset was exposed.
- Review discovery, ownership and escalation gaps.
- Track recurrence across similar technology.
- Update playbooks, controls and asset records.
A ticket status is not evidence of remediation. Close the response only when the technical outcome has been validated.