The Question
Two enterprises, similar in size and sector, are running CTEM programs. Both use the same vulnerability management platform. Both have roughly the same number of open findings — call it 80,000 across the enterprise. Both have prioritization engines that rank findings by CVSS score and asset criticality. Both produce a top-500 remediation list each week.
The first enterprise's top-500 list reflects the highest-severity vulnerabilities on the highest-criticality assets. It is technically sound. The second enterprise's top-500 list reflects the same criteria — but filtered against an additional layer: which of these vulnerabilities are actively being exploited by threat actors who target organizations in this industry, in this geography, right now?
The second enterprise patches a VPN vulnerability rated CVSS 7.8 in week one that the first enterprise's list puts at position 340. Three weeks later, that vulnerability is added to the CISA KEV list following confirmed exploitation across the sector. The first enterprise is now in emergency remediation mode. The second enterprise already closed it.
This is the operational difference that threat intelligence integration makes in a CTEM program. It is not a theoretical improvement to a risk score — it is the difference between proactive and reactive remediation against the specific threat actors targeting your organization.
Threat intelligence integration in CTEM is what separates a technically-driven prioritization program from an attacker-driven one — and the difference is whether you're patching what could be exploited theoretically or what is being exploited actively against organizations like yours.
Why This Matters Now
The operational case for TI-driven CTEM prioritization crystallized during the Volt Typhoon campaign disclosures of 2024–2025. CISA, NSA, and the Five Eyes intelligence partners issued a series of advisories documenting that the Chinese state-sponsored threat actor had pre-positioned access in US critical infrastructure — energy, water, transportation, communications — by exploiting vulnerabilities in internet-facing networking equipment, primarily from Cisco, Fortinet, and Ivanti.
The specific vulnerabilities Volt Typhoon exploited were, in several cases, not the highest-CVSS findings in the affected organizations' environments. They were the vulnerabilities with working public exploits, present on internet-facing infrastructure, in environments where lateral movement to operational technology networks was possible. The attacker's prioritization logic was: reachable, exploitable, high-value lateral movement destination.
The organizations that detected Volt Typhoon intrusions before significant damage was done shared a common characteristic: they were using threat intelligence — specifically actor-attributed TI from Mandiant, CrowdStrike, or Recorded Future — that identified which vulnerabilities Volt Typhoon was actively exploiting. That TI fed into their CTEM prioritization and moved those specific findings to the top of the queue ahead of higher-CVSS items that Volt Typhoon was not using.
The organizations that did not detect early had CVSS-based prioritization programs that did not reflect attacker behavior. The lesson is not subtle: TI-driven CTEM prioritization is a detection and prevention capability, not just a risk management improvement.
What the CURVE™ Data Shows
The 2026 Stackcurve CTEM CURVE™ Report evaluated TI integration capabilities across 14 CTEM platforms, with specific assessments of CISA KEV integration, EPSS adoption, commercial TI feed support, and dark web intelligence integration.
CISA KEV integration was nearly universal — 12 of 14 platforms evaluated had native KEV integration. The differentiators emerged at the next layers. Mandiant Attack Surface Management (Google Cloud) rated Tier 1 in actor-attributed TI integration, reflecting its direct access to Mandiant's threat intelligence on active exploitation campaigns and attacker TTPs. Recorded Future rated Tier 1 as a standalone TI platform with the deepest CTEM integration pathway, particularly through its API integrations with Tenable, Qualys, and ServiceNow for automated prioritization updates. CrowdStrike Falcon Exposure Management rated Tier 1 in combining endpoint telemetry with adversary intelligence for prioritization context.
EPSS adoption was more variable. Only 6 of 14 platforms had native EPSS integration in their prioritization engines; the others referenced CVSS as the primary severity signal. Platforms with EPSS integration included Tenable (via Lumin), Qualys (via TruRisk), and Rapid7 InsightVM. Dark web intelligence integration — specifically credential monitoring and underground market data — was present in only 3 of 14 platforms evaluated, reflecting the early-stage maturity of this capability in the CTEM stack.
The full vendor rankings are in the 2026 Stackcurve CTEM CURVE™ Report — free to download.
The Gap Most Buyers Miss
The CTEM TI integration conversation usually starts and ends with CISA KEV. That is the wrong place to stop. CISA KEV tells you what has already been exploited at scale — it is a trailing indicator. The highest-value TI integration layers are the ones that give CTEM programs a leading indicator advantage.
CISA KEV: Table Stakes, Not Differentiation
Every enterprise CTEM program should have CISA KEV integrated as a hard filter in the prioritization engine. Findings on the KEV list should be automatically escalated regardless of their CVSS score, because KEV status means confirmed in-the-wild exploitation. This is not a strategic differentiator — it is basic hygiene. If your CTEM platform does not natively integrate CISA KEV, that is a platform deficiency, not a configuration gap.
EPSS: The Prioritization Upgrade Most Programs Haven't Made
EPSS — the Exploit Prediction Scoring System maintained by FIRST.org — predicts the probability that a CVE will be exploited in the next 30 days, on a 0–1 scale. An EPSS score of 0.9 means a 90% probability of exploitation in the next 30 days based on vulnerability characteristics and real-world exploitation telemetry. An EPSS score of 0.01 means a 1% probability — and roughly 50% of CVEs with CVSS scores of 9.0 or higher have EPSS scores below 0.05.
That specific data point is the reason EPSS matters operationally. Half of the highest-CVSS findings in your environment are statistically unlikely to be exploited in the near term. Deprioritizing them in favor of lower-CVSS findings with high EPSS scores is not risk acceptance — it is evidence-based prioritization. Enterprises that have made this switch typically reduce their emergency patch burden by 30–50% while improving their actual protection against imminent exploitation.
Commercial TI: The Actor-Specific Layer
CISA KEV and EPSS are sector-agnostic. Commercial threat intelligence from Mandiant, CrowdStrike Falcon Intelligence, Recorded Future, and Flashpoint adds the actor-specific layer: which vulnerabilities are threat actors who target your industry and geography actively exploiting right now? This is the intelligence that the second enterprise in the opening scenario was using to catch the VPN vulnerability early.
The integration question to ask vendors: can I bring my own TI feeds, and how does actor-specific TI from commercial providers map to findings in the prioritization engine? The gap most platforms have is that they integrate CISA KEV (table stakes) and reference EPSS (increasingly common) but do not enable a clean integration pathway for actor-specific TI that would tell you whether the threat groups targeting your sector are actively using vulnerabilities in your environment.
Dark Web Intelligence: The Identity Exposure Layer
Credential monitoring services — SpyCloud, Flare, Constella Intelligence — and dark web monitoring platforms — Recorded Future, Flashpoint — provide a specific signal that pure vulnerability data cannot: which enterprise credentials are available for purchase on criminal marketplaces. This is an exploitability signal for identity exposures that is entirely absent from CVE-based CTEM programs. If an employee's credentials for a VPN or cloud console are available on an underground forum, that is an active exposure that should appear in the CTEM prioritization queue regardless of whether there is a CVE associated with it.
Questions Your Buying Team Should Be Asking
1. Does the platform natively integrate CISA KEV, and how are KEV findings surfaced in the prioritization workflow?
The answer should describe automatic escalation logic — not just a tag — that moves KEV findings above the standard CVSS threshold in the remediation queue. Ask whether KEV updates are pulled in real time or on a delayed sync cadence, and what the average latency is between a CISA KEV addition and its reflection in the platform's prioritization output.
2. Does the platform integrate EPSS, and can EPSS scores replace or supplement CVSS as the primary severity signal?
This question reveals the prioritization philosophy of the platform. Vendors that have integrated EPSS as a first-class prioritization signal are ahead of the market on attacker-centric prioritization. Ask for a demonstration showing how EPSS scores affect the ranking of findings relative to CVSS, and specifically what happens to high-CVSS, low-EPSS findings in the prioritization output.
3. Can the platform ingest commercial threat intelligence feeds, and does it support actor-attribution mapping to findings?
The most sophisticated CTEM prioritization connects specific threat actors to specific vulnerabilities in the enterprise environment. Ask whether the platform has native integrations with Mandiant, CrowdStrike, or Recorded Future, and whether those integrations support actor-level attribution — not just generic "in the wild exploitation" flags.
4. How does the platform handle identity-related exposures, and does it integrate with credential monitoring or dark web intelligence services?
This question surfaces whether the CTEM platform's threat intelligence scope extends beyond CVEs to identity exposures. A comprehensive CTEM program should be able to correlate credential compromise intelligence with the identities that have access to critical systems — and escalate those findings into the remediation queue alongside CVE-based ones.
5. How does the platform's TI integration update prioritization scores dynamically — specifically, what happens to a finding's rank when new exploitation intelligence becomes available?
Static prioritization is a snapshot. Dynamic prioritization responds to new TI. Ask specifically: if a CVE that was ranked 200 in our remediation queue is added to the CISA KEV list or appears in a new Mandiant threat actor report, how quickly does it escalate in the queue, and does that escalation trigger an automated notification to the responsible remediation team?
The Stackcurve Take
Threat intelligence integration is not a feature of CTEM — it is what makes CTEM attacker-centric rather than technically-centric. The difference is material: CVSS-based prioritization produces a defensible remediation program. TI-driven prioritization produces a program that reflects what adversaries are actually doing against organizations like yours.
The baseline for 2026 is CISA KEV integration as a hard prioritization filter and EPSS as a supplementary scoring signal. Those two data sources are free, widely integrated, and available to any enterprise regardless of TI budget. Enterprises operating without them are leaving a measurable prioritization advantage unclaimed.
The strategic advantage layer is actor-specific commercial TI — intelligence that tells you whether the threat groups targeting your industry are actively exploiting vulnerabilities in your environment. This is the capability that moved early warning from incident response to proactive remediation in the Volt Typhoon cases. Mandiant (Google Cloud), CrowdStrike Falcon Intelligence, and Recorded Future are the three most operationally mature sources for this intelligence tier.
The 2026 Stackcurve CTEM CURVE™ Report covers TI integration capabilities across all major CTEM platforms, including a detailed evaluation of CISA KEV and EPSS implementation quality, commercial TI feed support, and dark web intelligence integration. Download it free →
Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.