Empirical Security found that the CNA tag is about the tag, not whether a fix exists.

Public source

Publisher name

Public post

The most useful thing in a CVE record is the link to the fix, and almost no CNA labels it. The CVE format lets a CNA tag a reference as "patch". That is how a tool knows…

Log in to read the full post

Company

Empirical Security

Security Intelligence and Decision Support, Tailored to your Enterprise.

Industry
Computer and Network Security
Location
Chicago, US
Company size
11–50 employees

About Empirical Security

Empirical builds mathematical models for security data. We maintain the world’s most advanced global models for cybersecurity, and we build local models that respond to your enterprise’s specific context and threat landscape.

See more

Latest activity

14 signals

Discover more

Similar public activity from other companies.

Customize signals for your business.

Know everything happening across the B2B world, and act on the company movements that matter to you.

© 2026 SeedOpsCompany intelligence.

SeedOps.