Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A CVE tells you which publicly disclosed vulnerability is being discussed; a VEX statement tells you whether a supplier says that vulnerability affects a particular product, and what status or remediation applies. Neither replaces the other: use the CVE to identify the issue, then match supplier guidance to the exact product, version, and deployment in your inventory.

What does a CVE tell you?

A CVE is a common identifier and catalog record for a publicly disclosed vulnerability. It lets security teams, suppliers, and tools refer to the same issue. A CVE identifier alone does not establish whether a particular downstream product—or your configuration of it—is affected.

That distinction matters when a vulnerable component appears in a product’s software inventory. Its presence may signal something to investigate, but does not by itself prove that the product uses the vulnerable functionality in an affected way.

What does a VEX statement add?

VEX is machine-readable, product-specific information about the relationship between a product and a known vulnerability. It answers whether the supplier considers a specified product affected and may explain the status or provide remediation guidance. OASIS describes the purpose of its VEX profile as stating whether and why a product is or is not affected in the CSAF 2.1 standard.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common status labels include affected, not affected, fixed, and under investigation. Read the supplier’s stated product and version scope, status, and justification together. A “not affected” finding for one product or configuration is not a blanket finding for other products.

How CVEs, supplier advisories, and VEX differ

Item What it tells you What it does not settle
CVE Which publicly disclosed vulnerability is being referenced. Whether a specific supplier product or deployment is affected.
Supplier security advisory Supplier guidance about products or versions, often including severity, mitigations, fixed versions, or response details. CISA characterizes these as vulnerability-centric: issued in response to a vulnerability and identifying affected products. Whether the products named in the advisory match your inventory and deployment.
VEX statement Machine-readable supplier status for a particular product’s relationship to a vulnerability, with an explanation or remediation information where applicable. Your local exposure decision unless you match the statement to the actual product, version, and configuration.

In short: CVE identifies the vulnerability; VEX communicates a supplier’s product-specific status. A supplier advisory may carry that context in a human-readable format, while VEX makes status information machine-readable. See CISA’s Software Acquisition Guide for guidance on supplier advisories and product assessment.

How VEX relates to an SBOM and CSAF

An SBOM describes a product’s software components. Finding a component associated with a CVE can flag a possible issue, but component presence alone does not prove that the containing product is affected: the product may not use the vulnerable functionality. CISA explains that VEX can clarify and help prioritize risk, and that VEX and SBOMs can be used together or independently in its SBOM consumption guidance.

CSAF is an open, machine-readable security advisory framework that includes a VEX profile. Under CSAF 2.1, the profile requires product and vulnerability information. A “known not affected” status requires an impact statement; a “known affected” status requires product-specific remediation information. This structure helps tools and teams interpret supplier statements, but it does not remove the need to confirm that the product scope matches the software you run.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to assess a CVE against your environment

  1. Match the supplier and product. Compare the advisory or VEX statement with the exact supplier and product recorded in your inventory.
  2. Confirm the version and scope. Check whether the version and any stated configuration conditions cover the deployment you operate.
  3. Read the VEX status and explanation. Do not make a decision from the CVE identifier or severity score alone. Check why the supplier says a product is or is not affected.
  4. Follow remediation for affected products. Find the fixed version or mitigation and follow the supplier’s instructions.
  5. Keep unresolved cases open. Treat “under investigation” as unresolved supplier status, not evidence that the product is safe.
  6. Recheck changed advisories and make a local decision. Supplier coverage and status can change. Base your exposure assessment on the actual deployment and configuration, and revisit the advisory when it is updated.

If sources appear to disagree, compare their product and version scope, publication dates, status explanations, and remediation instructions. If the conflict remains, consult the responsible supplier rather than treating one statement as universally applicable.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What supplier VEX coverage means in practice

On September 8, 2026, Microsoft announced that it was publishing VEX statements for all Microsoft-assigned CVEs. The company said the statements could automate portions of vulnerability analysis and reduce manual effort when interpreting advisories across complex environments. This is Microsoft’s stated publication scope as of that announcement—not evidence that every supplier publishes VEX or that every security tool consumes it. See the Microsoft Security Response Center announcement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.