Skip to content
THREATWIRE

Research

How ThreatWire records a vulnerability

The status on a ThreatWire card is an editorial claim. Unknown stays unknown until a public source confirms a PoC, an exploit, or active use.

Published 4 Oct 2026 · Updated 5 Oct 2026

A ThreatWire card is a record, not a rumor with a color on it. The severity, the class, and the date describe the vulnerability. The status describes what we are willing to say about code and exploitation.

Five statuses exist, and they are not a ladder we climb by implication.

  • No PoC. We have looked, and there is no confirmed public proof of concept.
  • PoC Available. A public proof of concept is confirmed. That is not an exploit, and it is not evidence of intrusion.
  • Exploit Available. A public exploit is confirmed. For a supply-chain backdoor, the malicious release itself can be that exploit, and the write-up has to say so.
  • Active Exploitation. Use in the wild is confirmed. A CISA KEV entry is enough for this status. A blog post that says "attackers could" is not.
  • Unknown. We do not know. Unknown is a finished status, not a placeholder to be prettied up.

A URL does not change the status. The PoC field, the GitHub field, and the vendor advisory are links. Only the status line is allowed to say that something is available or active. If those disagree, the status wins, and a PoC link stays hidden until the status confirms it.

The opening record uses three public CVEs to show the difference. CVE-2024-3400 is Active Exploitation and a 0-day because the vendor reported exploitation before the fix and CISA lists known ransomware use. CVE-2021-44228 is Active Exploitation and not marked 0-day. CVE-2024-3094 is Exploit Available because the backdoor shipped in the tarballs, and it is not listed in KEV.

Nothing on this site is published by a feed. A later importer may create a draft. A person publishes it.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/research/how-threatwire-records-a-vulnerability