Not particularly related to this one, but the new CVE scoring system basically lets vendors set Exploit Maturity for every vuln to Unreported, as there's almost always no exploits before patch - which means you never get a CVE score above 8 for unauth RCEs any more as a vendor.



