2026 CVSS v4.0 Severity Scoring, Vector Metrics & Patch SLA Reference Table
2026 Verified ReferenceCVSS v4.0 (FIRST.org standard) replaces CVSS v3.1's ambiguous `Scope (S:U/C)` metric with explicit Vulnerable System (`VC/VI/VA`) and Subsequent System (`SC/SI/SA`) impact metrics, introduces `Attack Requirements (AT:N/P)` to replace `User Interaction` nuance, and encourages reporting combined Base + Threat (`CVSS-BT`) scores.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N → Score: 9.3 (Critical)| CVSS v4.0 Rating / Metric | Score Range / Vector Values | v4.0 Architectural Change vs v3.1 | Enterprise Remediation SLA |
|---|---|---|---|
| Critical Severity | 9.0 – 10.0 (e.g., AV:N/AC:L/AT:N/PR:N) | Unauthenticated network RCE or auth bypass | Emergency Patch: 24 – 72 Hours |
| High Severity | 7.0 – 8.9 (e.g., AV:N/AC:L/AT:P/PR:L) | Privilege escalation or high-impact data leak | Priority Patch: 7 – 14 Days |
| Medium Severity | 4.0 – 6.9 (e.g., AV:N/AC:L/AT:N/UI:A) | Reflected XSS, CSRF, or limited info disclosure | Scheduled Release: 30 – 60 Days |
| Attack Requirements (AT) | AT:N (None) vs AT:P (Present) | Separates race conditions/MITM prereqs from AC | AT:P lowers score when exploit depends on timing |
| Subsequent System CIA (SC/SI/SA) | SC:H / SI:H / SA:H (Downstream Impact) | Replaces binary Scope:Changed (S:C) from v3.1 | Models lateral movement to hypervisor or DB |
| Exploit Maturity (Threat E) | E:A (Attacked) | E:P (PoC) | E:U (Unreported) | Produces official CVSS-BT nomenclature score | Prioritize E:A (CISA KEV) over theoretical E:U |
