Risk AssessmentHigh riskComparison recommended

AI Playbook for Zero-Day Vulnerability Prioritization

CISA published a Known Exploited Vulnerabilities update adding 7 new CVEs. Your organization has 14,000 endpoints. Patch management data shows exposure across all 7 CVEs. You have a 72-hour patch window before the next maintenance blackout. You can patch approximately 40% of affected systems in that window.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: CISA published a Known Exploited Vulnerabilities update adding 7 new CVEs.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Zero-Day Vulnerability Prioritization".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • CISA KEV entries for the 7 new CVEs (full detail)
  • Asset inventory with OS, application versions, business function, and network segment
  • Exploit maturity data (Metasploit availability, public PoC status)
  • Business impact classification for all asset groups
  • Prior patch success rate by asset group and patch type

Attachments: Documents (Documents)

The Prompt

You are a vulnerability management lead prioritizing emergency patching for 14,000 endpoints. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Score each CVE by exploitability (CVSS, EPSS, public exploit availability) and asset exposure (number of affected systems, network location, business criticality).
2. Identify which CVE-asset combinations represent the highest immediate risk: internet-facing systems with publicly exploitable vulnerabilities should be first.
3. Build the patch prioritization sequence for the 72-hour window, accounting for dependencies and reboot requirements.
4. Identify compensating controls (network segmentation, WAF rules, disable features) for systems that cannot be patched in the window.
5. Tell me what to communicate to business owners for systems going offline and what the residual risk posture is after the 72-hour window.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • CVE risk scoring matrix
  • Asset-level patch priority ranked list
  • 72-hour patch sequence with dependencies
  • Compensating control recommendations for deferred patches
  • Business owner communication template

Review before you act

  • Validate this output against source files before relying on it: Score each CVE by exploitability (CVSS, EPSS, public exploit availability) and asset exposure (number of affected systems, network location, business criticality).
  • Validate this output against source files before relying on it: Identify which CVE-asset combinations represent the highest immediate risk: internet-facing systems with publicly exploitable vulnerabilities should be first.
  • Validate this output against source files before relying on it: Build the patch prioritization sequence for the 72-hour window, accounting for dependencies and reboot requirements.
  • Validate this output against source files before relying on it: Identify compensating controls (network segmentation, WAF rules, disable features) for systems that cannot be patched in the window.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Zero-Day Vulnerability Prioritization, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface cve risk scoring matrix; asset-level patch priority ranked list; 72-hour patch sequence with dependencies; compensating control recommendations for deferred patches. Those are comparison artifacts — they only exist if more than one model runs. Models disagree on blast radius, attribution confidence, and whether a vendor finding is theoretical or exploitable. Those disagreements mark where an analyst should slow down.

CybersecurityExposure ManagementRisk AssessmentHighDocuments

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.