AI-Assisted Features in DevSecOps
5 ways to fix misleading vulnerability severities with policy

5 ways to fix misleading vulnerability severities with policy

5/13/2026 · Grant Hickman

What this post added

Introduced vulnerability management policies that allow for automated severity overrides based on defined rules (CVE ID, CWE ID, file path, directory). Supports 'Set Severity', 'Increase Severity', and 'Decrease Severity' operations. Provides use cases for downgrading low-risk CVEs in internal services, upgrading injection vulnerabilities in production code, normalizing severity across scanners, aligning severity with exploitation intelligence, and applying org-wide risk models at the group level. Details on policy creation, validation, and quick reference for parameters are included.

Read the original post ↗