ForumsVulnerability management

CVE counts are a terrible way to compare vendors and we should stop

Discussion 18 Jun 2026 348 views
Jonas Lindqvist Sample IT/OT convergence. Owns 30 plants worth of legacy. · member since Apr 2026

A colleague built a shortlist scored partly on the number of CVEs published against each vendor. I have been arguing against it all week and want a sanity check.

My position: a vendor who runs a bug bounty, works with researchers and files CVEs properly will always look worse on that metric than one who quietly fixes things in a point release. Counting disclosures rewards silence. It also tracks how much software a company ships and for how long, which is portfolio size, not security.

4 replies

Priya Raghunathan Sample Detection engineering lead. Writes the rules, tunes the noise. · 2 months ago

You are right and there is a sharper version of the argument. The metric you want is not how many CVEs exist but how the vendor behaves around them: time from report to fix, quality of the advisory, whether they publish IOCs, whether they tell you when something is being exploited rather than waiting for the news.

Those are all observable from public advisories and they actually differentiate.

Chen Wei Sample Detection content and purple teaming. · 2 months ago

Agreed. The one place raw counts are useful is the opposite direction from how they are usually used: if a product with a large installed base has almost no CVEs, that is sometimes a sign nobody is looking, not that nothing is there.

Rahul Deshpande Sample Infrastructure and security. Patches what the vendors break. · 2 months ago

For the shortlist, ask each vendor for their last three security advisories and read them. The difference between a vendor who writes a clear advisory with affected versions and mitigations, and one who publishes two sentences, tells you more than any count.

Jonas Lindqvist Sample IT/OT convergence. Owns 30 plants worth of legacy. · 2 months ago

That is the argument that won it. We replaced the count column with 'quality of last three advisories' and the ranking changed completely.

Sign in or join to reply.