Prioritize vulnerabilities with KEV, EPSS, exposure and business impact—not CVSS alone—to stop exploitable paths before patch windows close.