A CVSS 9.8 on a dev laptop is not your worst problem.
Every control below is one of the twelve TRIS v2 layers: three foundational signals (CVSS, EPSS, CISA KEV), four contextual (threat actor targeting, asset criticality, public exposure, BASzy validation), and five novel v2 layers (attack path, supply chain, defense efficacy, trajectory, expected financial impact). Move any one and both scores recompute. The presets load four shapes that show up in real environments.
Active exploitation, APT targeting, crown jewel exposure, and accelerating trajectory make this an immediate fix. CVSS underestimates because it only sees severity.
This is a simplified demonstration. Real TRIS v2 uses proprietary weights and diminishing-returns functions documented in the white paper.
Cross 90 and the fix jumps the queue.
TRIS v2 outputs a queue position, not a color. The thresholds below are the ones the calculator above applies. Band, not raw score, decides what happens next: ACT items enter the current change window, INFO items get documented and left alone.
Active exploitation plus context that proves reach. Patch in the current change window, ahead of everything else.
Contextual signals push it above its CVSS rank. Schedule inside seven days.
Moderate risk under current conditions. Normal patch cycle; watch the trajectory layer.
Low risk in this environment. Often a CVSS critical that existing controls already block.
Effectively a non-issue here. Record the decision and move on.
Now run it on your scan data.
The calculator takes your word for the context. CVEasy reads it from your connectors and your asset inventory, then scores every finding through the same twelve layers, against 361,000+ indexed CVEs, on your hardware.