
Back in July Cisco, instead of giving each vuln its own CVE number, it now lumps the same kind of vulns under one umbrella CVE. They all get the number of the worst CVSS score in the group, and the fixes go out in a reduced number of software updates instead of dozens of updates. This may be good for some, but not everyone. This impacts an entire system and everyone who uses CVE numbers as a shared name for one vuln. So scanners like Tenable and Qualys, KEV list, and EPSS will no longer work accurately in the same way. Those tools assume CVE-2026-12345 means one problem with one severity. If the number actually means “a bunch of vulns, and at least one is bad,” the score and the tracking doesn't work. If every vendor did this, CVE and CVSS would mostly describe a patch drop and not a single vuln. People are arguing that they could still ship a large update with the one bug one CVE method. What do you think?
Post summary
The text discusses the broader impact of Cisco grouping multiple vulnerabilities under umbrella CVEs and how this may affect scanners, KEV, EPSS, and CVSS tracking. It does not provide evidence of PoC code, exploit tools, active exploitation, specific patches, or concrete vulnerability details.






