Skip to content
← Blog & Education · compliance 9 min read

Ship a PSIRT that customers trust — CVSS v3.1, CSAF 2.0, and a CISA-KEV check on every advisory

How Talarity turns your product vulnerabilities into customer-facing security advisories — scored with CVSS v3.1, exported as CSAF 2.0, checked against the CISA Known Exploited Vulnerabilities catalog, and pushed to affected customers on a draft → published → withdrawn lifecycle.

By The Talarity team · July 18, 2026

When a vulnerability lands in one of your products, the scanner findings and the SBOM tell you what’s wrong internally. The next job is the hard one: tell your customers, in a form they can act on, and prove you did it. That is the Product Security Incident Response Team (PSIRT) function — and most teams run it out of a spreadsheet and a mail-merge.

Talarity’s Product Advisories page is a real PSIRT surface. Author an advisory about your own product, score it with CVSS v3.1, export a machine-readable CSAF 2.0 document, see instantly whether any of its CVEs are in the CISA Known Exploited Vulnerabilities catalog, and notify affected customers — all on a coordinated-disclosure lifecycle (draft → published → withdrawn) with a per-org advisory number.

The advisory register

Open Application Security → Product Advisories. Every advisory is one row: its ADV-YYYY-NNNN number, title, severity with the CVSS score, status (draft / published / withdrawn), a KEV column that lights up “Exploited” when a CVE is in the CISA catalog, and its publication date.

The advisory register: ADV numbers, titles, CVSS-scored severity, draft/published/withdrawn status, a lit "Exploited" KEV badge, and publication dates.

The number is assigned only at publish time — drafts don’t burn one — so your public advisory IDs stay dense and sequential.

Draft it, and let CVSS do the scoring

Click + New advisory. Write the title and summary, then enter the CVSS v3.1 vector. Talarity computes the base score on the server — the exact FIRST specification formula, rounded up to one decimal — and the derived score and severity become authoritative: the Severity field greys out because the vector governs it.

The New advisory editor: title, a greyed Severity field, summary, a CVSS v3.1 vector that computes a live "Base score 5.4 — Medium", and affected products/versions.

Add the affected products and version ranges, the CVE identifiers, and the CWE weakness classes. Everything you record flows into the machine-readable export in the next step.

Publish — with a CISA-KEV check and a CSAF document

A published advisory carries the whole picture. The header states the ADV number, status, severity, and CVSS score; a KNOWN EXPLOITED badge appears when one or more of the advisory’s CVEs are in the CISA Known Exploited Vulnerabilities catalog — the single most important signal for a customer deciding how fast to patch. Every advisory can be downloaded as a CSAF 2.0 JSON document, the OASIS standard your customers’ own tooling can ingest automatically.

A published advisory's detail: ADV-2026-0001, Published, Critical, CVSS 10.0, a red "KNOWN EXPLOITED" badge citing the CISA KEV catalog, CVE/CWE identifiers, remediation, and Download CSAF / Notify customers / Withdraw actions.

The KEV catalog is kept current by a nightly sync of the live CISA feed, so the check reflects the real, present-day exploited-in-the-wild status — not a stale snapshot.

Notify the customers who are affected

Click Notify customers. Build the recipient list a row at a time: an app user (chosen by name from your org — not a raw id), an email address, or a contact from your address book. App users get an in-app notification; email and contact recipients get an email through the standard mail queue. Talarity records who was notified and when.

The Notify customers modal: a per-row recipient builder with an email recipient and an app-user recipient chosen by name ("Alex Morgan").

Withdraw and reissue — never quietly edit

A published advisory is a public record, so you don’t silently edit it. If it turns out to be inaccurate or is superseded, you withdraw it with a documented reason. The advisory goes terminal — its only remaining action is downloading the (now withdrawal-stamped) CSAF document — and you issue a fresh advisory in its place.

A withdrawn advisory: status Withdrawn, a documented withdrawal reason, and terminal actions (only Download CSAF and Close remain).

Find what you need

Filter the register by status or severity, or search by title — pull “every published advisory” or “every critical” in one click.

The register filtered to Published: the list narrows to the two published advisories, severity/CVSS and the KEV badge intact.

What you walk away with

A coordinated-disclosure PSIRT workflow that produces audit-ready, machine-readable advisories: CVSS-scored on the FIRST specification, exported as CSAF 2.0, checked live against the CISA KEV catalog, published under a per-org advisory number, and pushed to the customers who need them — with a withdraw-and-reissue discipline that keeps your public record honest.

The page maps to the standards your customers’ security teams already speak: CVSS v3.1 (FIRST.org, base-metric group), CSAF 2.0 (OASIS, the machine-readable successor to CVRF), the CISA Known Exploited Vulnerabilities catalog (BOD 22-01), and the coordinated-disclosure practice of ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling), operationalized the way the FIRST PSIRT Services Framework describes.

Loading…

Keep reading

See Talarity in action.

A 30-minute walkthrough or a 7-day trial — your call.