CVSS 4.0 AdoptionStanding
About one in three new CVEs now carries a CVSS 4.0 score (33% in 2026Q2)
Updated 12 August 2026 · Timeframe: By publication quarter (quarters with >=200 scored CVEs)
In 2026Q2, 33% of scored CVEs carried a CVSS 4.0 score, roughly a third, up from about a quarter two years ago. That is the mechanism behind the EU-vs-US 'divergence': the EUVD surfaces the 4.0 number while most US tooling still reads 3.1, and the two versions score the same flaw differently. The more 4.0 spreads, the more version-mixing comparisons drift from reality.
Why it matters
CVSS 4.0 scores a flaw about half a point differently from 3.1. As adoption climbs, any comparison that mixes versions drifts further from reality unless you compare like-for-like.
What to do
- Security leaders. Check whether your scanners and dashboards read 3.1 or 4.0; a mixed view manufactures phantom severity swings.
- Lean IT orgs. Pick one CVSS version and apply it consistently; do not compare a 4.0 score to a 3.1 one.
- MSPs. As 4.0 adoption rises, standardize the CVSS version you report to clients.
Our take
Tracking the quiet CVSS version transition is the kind of infrastructure signal that explains 'divergences' the market misreads as disagreement.