CVSS measures severity, not your actual risk. Learn how exposure, exploitability, asset importance, active attacks, and controls should shape patch priorities.