New vulnerabilities matching algorithm
27 July 2026
The ShadowTrackr internal CVE database has been updated and augmented with new information. This allows us to better track and help you prioritise your risks from vulnerabilities. Check out our new
Vulnerability management documentation to learn more.
A big part of the update is the
ShadowTrackr CVSS Score. It is a CVSS v4 score, but unlike like the MITRE and NVD score we keep the threat group value (Exploit maturity) included in the final score. If a PoC exists or active attacks are known, the score will be higher. If not, it will be lower. We track a lot of sources for exploit status to keep the score accurate.
If you want, you can query our internal cves index for specific fields in the CVSS v4 vectorstring, or you can check our logs of changes to a CVE (when was an exploit found, when did CISA include it in the KEV, etc.). These options are also avaible for your
cves_assets index.
The algorithm matching your software against vulnerabilities has also improved. It can find more complex matches and has less false positives. You might notice a different number of CVEs found in this weeks reports.