home/glossary/vulnerability

vulnerability

nounverified·updated May 9, 2026

Weakness in a component of a system, particularly information assets, system security procedures, internal controls, or implementation, that could be exploited or triggered by human action or natural events.

polysemousTSP Section 100

Senses

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexiconextended definition available

A characteristic or specific weakness that renders an organization or asset (such as information or an information system) open to exploitation by a given threat or susceptible to a given hazard.

ISACA Cybersecurity Glossary

A weakness in the design, implementation, operation or internal control of a process that could expose the system to adverse threats from threat events

NIST Cybersecurity Framework

A weakness in an information system, administrative controls, internal controls, system security practices and procedures, implementation, or physical layout that could be accidentally triggered or intentionally exploited by a threat in order to gain unauthorized access to information or disrupt processing.

CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures

A weakness, susceptibility or flaw in a system that an attacker can access and exploit to compromise system security. Vulnerability arises from the confluence of three elements: the presence of a susceptibility or flaw in a system; an attacker’s access to that flaw; and an attacker’s capability to exploit the flaw.

Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary

A hardware, firmware, or software flaw that leaves an information system open to potential exploitation; a weakness in automated system security procedures, administrative controls, physical layout, internal controls, etc., that could be exploited to gain unauthorized access to information or to disrupt critical processing.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2

Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2sense 2 pending review

A weakness in a system, application, or network that is subject to exploitation or misuse.

CNSSI-4009 (Glossary of Information Assurance Terms)

Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited by a threat source.

Wordset Dictionary

susceptibility to injury or attack

Wordset Dictionary

the state of being vulnerable or exposed

Classifications

Entity Type

Vulnerability95%rule-basedr:entity.vulnerability.cve.v1
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

synonym
exposure
alternatephrasing
Vulnerability
plural
vulnerabilities
possessive
vulnerability's
pluralpossessive
vulnerabilities'