Cyber Resilience

CVSS 4.0 AdoptionStanding

About one in three new CVEs now carries a CVSS 4.0 score (33% in 2026Q2)

Updated 12 August 2026 · Timeframe: By publication quarter (quarters with >=200 scored CVEs)

Q1-1999Q2-202632380
Share of new CVEs carrying a CVSS 4.0 score, by quarter · security-resilience.ai

In 2026Q2, 33% of scored CVEs carried a CVSS 4.0 score, roughly a third, up from about a quarter two years ago. That is the mechanism behind the EU-vs-US 'divergence': the EUVD surfaces the 4.0 number while most US tooling still reads 3.1, and the two versions score the same flaw differently. The more 4.0 spreads, the more version-mixing comparisons drift from reality.

Why it matters

CVSS 4.0 scores a flaw about half a point differently from 3.1. As adoption climbs, any comparison that mixes versions drifts further from reality unless you compare like-for-like.

What to do

Our take

Tracking the quiet CVSS version transition is the kind of infrastructure signal that explains 'divergences' the market misreads as disagreement.