> ## Documentation Index
> Fetch the complete documentation index at: https://docs.minimus.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Prioritizing Vulnerabilities

> Risk based vulnerability prioritization based on EPSS, CVSS severity, and CISA KEV for your Minimus container images

## Why vulnerability remediation prioritization still matters

In theory, vulnerability prioritization tools should no longer be required now that anyone can upgrade container images daily using Minimus secure container images. Just pull a fresh build for your image to get the cleanest and most secure image possible. So why should we still be talking about how to prioritize vulnerability remediation?

In practice, frequent upgrades are considered to increase instability and are often delayed or even blocked to allow for testing to complete. Teams need to balance security updates with app stability, which reintroduces the need to prioritize vulnerabilities, especially taking into consideration their exploitability. This is where Minimus threat intel comes into play, making it simple to evaluate vulnerability risk directly from the Minimus console.

## Minimus threat intel

Minimus enriches every vulnerability advisory with data from 3 risk assessment systems:

* [CISA KEV](/remediate/priorities/kev)
* [EPSS](/remediate/priorities/epss)
* [CVSS](/remediate/priorities/cvss)

Minimus threat intel can direct your team's vulnerability remediation prioritization and ensure that images affected by vulnerabilities flagged as active exploits (CISA KEV) or likely exploits (high EPSS) are moved to the top of the remediation queue. Minimus actions, provided as part of the Minimus Enterprise Edition, can be used to automate workflows and notifications for establishing a robust vulnerability risk management system. [Learn more about Minimus actions](/remediate/actions)

> *There’s no inherent correlation between the vulnerability and if threat actors are exploiting them in terms of those severity ratings.* [Gartner Analyst, Mitchell Schneider](https://securityintelligence.com/articles/cve-backlog-update-nvd-struggles-attackers-change-tactics/)
