How are folks managing CVEs at scale? #itsecurity #opensource #vulnerability #sbom

Sep 18, 2026

Dog-walk thoughts on vulnerabilities at scale 🐕

More CVEs are being found, disclosed and weaponised faster than ever. For a small team with one product, that's manageable: a CVE lands, you fix it.

But if you're running thousands of applications across tens of thousands of repos, "the teams will handle it" stops working. It becomes a governance problem:

Where are we actually exposed? Is it reachable? Is it public-facing or in a critical system? How long has it been sitting there? And are we reducing our threat, or just counting? 20,000 open last quarter, 2,000 fixed, 2,500 new ones since. What does that number even tell you?

At Kosli we think we can give your existing security tooling superpowers here, but first we want to understand how this problem really shows up at scale.

If you own this, or know who does, we'd love to talk. Comments or DMs open.

https://www.linkedin.com/in/tooky/