5 Steps to VEX Success: Managing the End-to-End Workflow - Cortez Frazier Jr. @OWASPGLOBAL
5 Steps to VEX Success: Managing the End-to-End Workflow - Cortez Frazier Jr.  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 1 week ago
If you work in vulnerability management, you’re probably familiar with the painful condition known as CVE overload. Each year, tens of thousands of new vulnerabilities are reported, and these potential risks overwhelm security teams tasked with confirming risks and remediating them.


A proposed solution is VEX (Vulnerability Exploitability eXchange): a set of formats that communicates vulnerability impact status, whether a vulnerability is exploitable in its deployed context, and mitigation steps. In theory, VEX (when used alongside other prioritization inputs) makes it possible for downstream security teams to remediate more efficiently. But as with most security frameworks, efficacy depends on proper implementation.


This talk will cover five steps to leveraging VEX throughout the vulnerability remediation lifecycle, from the time a vulnerability is disclosed to the time you publish and distribute a VEX statement. We’ll cover the tools and workflows security practitioners need to know to effectively use VEX in their organizations.

-

Managed by the OWASP® Foundation
owasp.org
5 Steps to VEX Success: Managing the End-to-End Workflow - Cortez Frazier Jr.AppSec Israel HighlightSo You Want To Be An OWASP Speaker?Defending Against New Phishing Attacks that Abuse OAuth Authorization Flows - Jenko HwongSecurity Champions at Scale: Transforming Security Culture by Aligning Incentives and Gamification202010 October 2020 Global Board MeetingConnecting the dots: 5 lessons learned from an 8 year journey of an AppSec Program track 1Beyond the Checklist: Building an AppSec Culture That Engineers Don’t DreadOWASP Software Assurance Maturity Model (SAMM) - Aram Hovsepyan, Sebastien DeleersnyderHow to Defend Your PKI Estate: Lessons Learned from Eight Years of CAA and Certificate TransparencyExhibitor : Over a Decade of Software Security  What Have We Learned -  Adam BrownOWASP Cornucopia Abuse Case Modeling
OWASP Foundation |

5 Steps to VEX Success: Managing the End-to-End Workflow - Cortez Frazier Jr.

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER