Artificial intelligence is fundamentally changing how organizations should approach software vulnerabilities, forcing a shift from traditional CVE counting toward contextual risk management, according to a new analysis published by The New Stack. The report argues that the basic vulnerability-management model—scan software, identify CVEs, assign severity scores, prioritize findings, and send them to developers—was never a perfect representation of risk, but its limitations have become impossible to ignore in the AI era. Organizations now face a growing gap between the vulnerabilities security teams can identify and the number they can meaningfully investigate and remediate.

The core issue is that severity doesn't equal risk. The Common Vulnerability Scoring System (CVSS) is designed primarily to communicate technical severity and the potential impact if a vulnerability is successfully exploited, but it doesn't indicate whether an exploit exists, whether the vulnerability is being exploited in the wild, whether the vulnerable component is exposed, or whether the vulnerable code path is executed in a particular environment. Two organizations can have exactly the same CVE in their environments and face very different levels of risk—one might have the vulnerable component sitting behind multiple layers of protection with no external exposure and no relevant execution path, while another might have it running in an internet-facing production application supporting a critical business process. The amount of software being produced is expanding rapidly, vulnerability discovery is accelerating, and the time required to develop exploits is shrinking as AI-enabled attacks combine vulnerabilities in ways that create attack paths difficult to anticipate manually.

The report identifies what it terms "CVE theater"—measuring activity rather than meaningful risk reduction. According to the analysis, teams may spend significant effort closing large numbers of findings without necessarily reducing the organization's most consequential exposure when vulnerability programs are built around static severity scores. The report states that instead of asking "How many CVEs do we have?", organizations should be asking "Which vulnerabilities create meaningful risk in our environment?" The analysis emphasizes that production environments are the source of truth, since registries or repositories scanned before software reaches production reflect perceived risk rather than what is actually deployed, and production environments, images, and configurations change while new vulnerabilities are disclosed after deployment.

The report recommends a layered approach combining multiple strategies: starting with secure software foundations using hardened or curated base images and language libraries, scanning first-party code through Static Application Security Testing (SAST) and AI-assisted code scanning, hardening configurations through security frameworks such as Security Technical Implementation Guides (STIGs), understanding what is running in production, determining reachability, and incorporating threat intelligence from sources like CISA's Known Exploited Vulnerabilities catalog (KEV) and the Exploit Prediction Scoring System (EPSS). The ultimate objective shouldn't be a perfectly empty vulnerability dashboard, the report argues—in a modern software environment, that's neither realistic nor necessarily the right measure of security. The goal should be a continuously improving understanding of actual risk, determining which vulnerabilities are open, which ones an attacker can reach, which ones lead somewhere important, and which ones represent the greatest risk right now. Organizations that continue relying on lengthy, sequential manual triage will struggle as the combination of more vulnerabilities and a collapsing time-to-exploit window creates a fundamentally different security environment. The shift from counting vulnerabilities to managing contextual risk isn't just a process improvement—it represents a necessary evolution in how security leaders allocate finite remediation resources in an environment where traditional prioritization frameworks no longer match the threat landscape.