The Flashpoint Method For Threat-Informed Vulnerability Prioritization
A practical, repeatable framework for prioritizing vulnerabilities based on real-world risk, exploitability, and business impact.

Organizations are gaining new ways to identify vulnerabilities at scale, thanks to new generations of powerful AI models. However, security teams still face the same fundamental question: which vulnerabilities actually matter?
Security teams have increasingly struggled to keep pace with growing disclosure volumes. So far in 2026, Flashpoint has tracked 21,667 vulnerabilities, an 8% year-over-year increase, while nearly one-fifth included publicly available exploit code. At the same time, the gap between disclosure and exploitation continues to shrink, with some vulnerabilities weaponized in as little as 24 hours.
Recent developments such as Anthropic’s Mythos model have highlighted the growing potential for AI-assisted vulnerability discovery. As advances in code analysis enable researchers and organizations to identify software flaws at unprecedented speed and scale, the volume of discovered vulnerabilities is set to increase significantly across software ecosystems.
While increased visibility into vulnerabilities is ultimately positive for defenders, it amplifies a challenge security teams already face: separating the vulnerabilities that pose meaningful risk from those that do not. Finding more vulnerabilities with AI does not automatically make organizations more secure — the key is understanding which vulnerabilities represent meaningful risk to your environment and require immediate action.
That’s why we created this guide — to introduce the Flashpoint Method for Threat-Informed Vulnerability Prioritization, a practical, intelligence-driven framework designed to help vulnerability and exposure management teams cut through the AI-driven noise and focus on the vulnerabilities that matter most. By incorporating real-world exploitation activity, threat actor behavior, asset exposure, business context, and remediation considerations, organizations can make faster, more informed decisions and reduce risk more effectively.
This report is for:
- Vulnerability and Exposure Management teams
- Cyber Threat Intelligence teams
- Security Operations / IT Security teams
- CISOs and security leadership overseeing remediation strategy
What you’ll learn:
- A clear, threat-informed prioritization framework: How to assess which vulnerabilities demand immediate attention, and why — moving beyond static severity scores alone.
- Core and expanded prioritization checklists: Criteria spanning asset criticality, active exploitation, CVSS severity and ransomware risk, social risk and community chatter, business context, compensating controls, zero-day status, KEV inclusion, EPSS scoring, ease of remediation, and vulnerability age.
- How to operationalize prioritization at AI scale: Insight into how Flashpoint’s vulnerability intelligence platform and analyst expertise help teams keep pace as AI-assisted discovery accelerates disclosure volume.
Key findings:
- Volume: Flashpoint tracked 21,667 vulnerabilities in the first half of 2026, an 8% year-over-year increase.
- Exploit availability: Nearly one-fifth (20%), or 4,015, of all vulnerabilities disclosed had publicly available exploit code.
- Speed: Some vulnerabilities are weaponized in as little as 24 hours after disclosure. Flashpoint flags zero-days on average within 24 hours of disclosure.
- Known exploited vulnerabilities: Flashpoint’s Known Exploited Vulnerabilities (FP KEV) list recently surpassed 7,000 entries, around 800 of which lack a CVE ID.
- AI-driven discovery: Emerging models such as Anthropic’s Mythos are accelerating AI-assisted vulnerability discovery, threatening to expand backlogs of vulnerabilities that may never be exploited in the real world.
Key takeaways:
- More vulnerabilities does not mean more risk: AI-driven discovery tools will surface more vulnerabilities, but greater visibility alone does not reduce risk. Teams need a repeatable way to separate what’s exploitable and relevant to their environment from what isn’t.
- Prioritization must be threat-informed, not just severity-informed: Static scores like CVSS are necessary but insufficient. Real-world exploitation activity, threat actor behavior, and social risk signals reveal urgency that severity scores alone miss.
- Business context determines true risk: The same vulnerability can be critical in one environment and irrelevant in another, depending on asset exposure, criticality, and compensating controls already in place.
- Consistency, not visibility, separates mature programs: The difference between mature and immature vulnerability management programs is the ability to consistently evaluate vulnerabilities through the lens of exploitation, exposure, business impact, and threat activity — then translate those insights into action.
- Flashpoint intelligence operationalizes the framework: Weekly vulnerability insight reports, deep and dark web monitoring, exploit availability tracking, threat actor insights, social risk scoring, zero-day tracking, the FP KEV list, and EASM integration give teams the context needed to prioritize confidently and reduce remediation cycles.
About Flashpoint
Flashpoint is the leader and largest private provider of threat data and intelligence. We empower mission-critical businesses and governments worldwide to decisively confront complex security challenges, reduce risk, and improve operational resilience amid fast-evolving threats. Powered by Flashpoint Primary Source Collection, our proprietary approach to collecting intelligence directly from the digital spaces where threats originate, the Flashpoint Ignite intelligence platform delivers unmatched depth, speed, and relevance from open and hard-to-reach sources, enriched by human expertise and scaled by AI. Our solutions span cyber threat intelligence, vulnerability intelligence, geopolitical risk, physical security, fraud, and brand protection. The result: our customers safeguard critical assets, avoid financial loss, and protect lives. Schedule a demo to learn more.


