A Design Science Study of Automated CVE Ingestion and Risk-Based Vulnerability Prioritization in Healthcare Cybersecurity
Abstract
1. Introduction
1.1. Purpose and Research Questions
1.2. Significance
1.3. Contributions
2. Materials and Methods
2.1. Background and Related Literature
2.1.1. The Industrialization and Volume of CVE Disclosure
2.1.2. Artificial Intelligence as an Offensive Accelerant
2.1.3. The Weaponization of Artificial Intelligence for Vulnerability Exploitation
2.1.4. The Limits of Severity Scoring and the Rise of Data-Driven Prediction
2.1.5. Security Orchestration, Automation, and Response
2.1.6. AI-Enabled Threat Assessment and Vulnerability Prediction in Healthcare
2.1.7. Regulatory and Human-Factors Context
2.1.8. Why Healthcare Changes the Prioritization Problem
2.2. Definitions and Key Terminology
2.3. Problem Statement
2.4. Research Design and Methodology
2.4.1. Research Paradigm
2.4.2. Artifact Development Approach
2.4.3. Study Setting and System Boundary
2.4.4. Artifact Requirements
2.4.5. Data Sources and Evaluation Method
2.4.6. Evaluation Measures
2.4.7. Ethics and Data Governance
2.5. The Designed Artifact

| Logic App | Trigger | Function |
|---|---|---|
| 1. CVE intake and enrichment | Office 365 new mail, 10 s polling | Parses each advisory email; extracts and normalizes CVE, KB, and CISA references; enriches against KEV, NVD, MSRC, Defender, and xDome; scores risk with Security Copilot; writes tracker records; 500 top-level actions. |
| 2. Tracker update and incident automation | Recurrence, 5 min, single instance | Re-validates unclaimed rows against NVD and KEV; builds consolidated digest emails per analyst group; opens ServiceNow incidents; claims rows to prevent reprocessing; 245 workflow actions. |
| 3. Monthly reporting | Scheduled, first day of month, 08:00 Central | Computes SLA aging buckets of 15, 30, 60, 90, and 120 or more days; pulls Microsoft Secure Score history and control-level detail; renders charts; emails a consolidated report; 151 workflow actions. |
2.5.1. CVE Extraction from Unstructured Advisories
2.5.2. Multi-Source Enrichment
2.5.3. Healthcare-Contextual Scoring: The Actual Mechanism
The Prompt Is Assembled from Three Fixed Components
The Model Output Is Not Trusted Blindly
2.5.4. Batched Ticketing and Audit-Ready Tracking
2.5.5. Monthly Reporting and Secure Score Integration
2.5.6. Performance Engineering for Weekly-Scale Volume
2.5.7. Mapping to Research Questions
3. Results
3.1. Observed Processing Volume and the Exposure-First Funnel
3.2. Analytical Workload Displaced, with Sensitivity Analysis
3.3. What the Artifact Demonstrably Changed
- Coverage that previously did not exist. Weekly bulletins ranging from 1515 to 3906 CVEs are now parsed, exposure-checked, prioritized, and documented in their entirety. Prior to automation, bulletins of this size could only be partially reviewed or not reviewed at all. The largest observed production processed 3906 CVEs while identifying 470 environment-relevant findings.
- Environmental relevance replaces advisory volume as the analyst workload. Across six production bulletins, analysts were required to evaluate 1640 environment-relevant findings rather than the full set of 12,855 published references. This represents an aggregate reduction of 87.2 percent of the population requiring human review.
- Every finding receives a documented and traceable prioritization. Findings that survive exposure validation proceed through enrichment, severity assignment, and tracker-record creation. Decisions to defer action are therefore recorded and auditable rather than existing as undocumented omissions.
- Analyst effort shifted from discovery to judgment. The artifact automates CVE extraction, vulnerability intelligence collection, exposure validation, grouping, scoring, and tracking activities. Analysts are therefore able to focus on evaluating confirmed exposures and remediation decisions rather than manually processing every advisory reference.
- The data demonstrates that environmental exposure is dynamic. Filtering rates ranged between 70.5 percent and 97.2 percent across observed bulletins. The degree of environmental relevance changes significantly from week to week, reinforcing the need for telemetry-driven prioritization rather than fixed assumptions about vulnerability risk.
3.4. Descriptive Statistical Treatment and Confirmatory Validation Protocol
3.4.1. Descriptive Statistics on the Exposure-First Funnel
3.4.2. Reliability and Reproducibility
3.4.3. Prospective Confirmatory Validation Protocol
3.5. Operational Performance Metrics
4. Discussion
4.1. Design Principles and Transferable Design Knowledge
4.2. Validity, Limitations, and Future Work
4.2.1. Construct Validity
4.2.2. Internal Validity
4.2.3. External Validity
4.2.4. Reliability
4.2.5. Known Gaps and Future Work
5. Conclusions
Supplementary Materials
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| Abbreviation | Full term |
| AEG | Automated Exploit Generation |
| AI | Artificial Intelligence |
| BOD | Binding Operational Directive |
| CISA | Cybersecurity and Infrastructure Security Agency |
| CVE | Common Vulnerabilities and Exposures |
| CVRF | Common Vulnerability Reporting Framework |
| CVSS | Common Vulnerability Scoring System |
| DSR | Design Science Research |
| EPSS | Exploit Prediction Scoring System |
| HIPAA | Health Insurance Portability and Accountability Act |
| KEV | Known Exploited Vulnerabilities (catalog) |
| KB | Knowledge Base |
| MSRC | Microsoft Security Response Center |
| MTTE | Mean Time to Exploit |
| NVD | National Vulnerability Database |
| SLA | Service Level Agreement |
| SOAR | Security Orchestration, Automation, and Response |
Appendix A. Workflow Structure Summary
| Workflow | Trigger | Actions | External Endpoints Invoked |
|---|---|---|---|
| 1. CVE intake and enrichment | Office 365 new mail; 10 s polling | 500 | NVD services API; CISA KEV JSON feed; MSRC CVRF API; Microsoft Update Catalog; Microsoft Defender advanced hunting API; Claroty xDome API; SharePoint Online |
| 2. Tracker update and incident automation | Recurrence, 5 min; concurrency limited to one run | 245 | NVD services API; MSRC; SharePoint Online; ServiceNow incident table API; Office 365 mail |
| 3. Monthly reporting | Recurrence, day 1 at 08:00 Central | 151 | Microsoft Graph secure score endpoints; SharePoint Online; chart rendering service; Office 365 mail |
Appendix B. CVE Extraction Sequence
Appendix C. Scoring and Deterministic Fallback

- Note: The terminal default is deliberately set to a high rather than a low value, so that a scoring failure produces an over-escalation that a human will see, rather than an under-escalation that would pass unnoticed.
Appendix D. Signals Supplied to the Scoring Step
| Signal | Source | Role in Prioritization |
|---|---|---|
| CVSS base score and severity | NVD; Microsoft Defender | Intrinsic severity; explicitly not treated as sufficient |
| Exposed device count | Microsoft Defender advanced hunting | BOD 26-04 asset exposure, information technology estate |
| Affected and potentially relevant devices counts | Claroty xDome | BOD 26-04 asset exposure, operational technology and medical devices |
| Environment-adjusted severity level | Claroty xDome | Contextual severity reflecting device criticality |
| EPSS probability | Claroty xDome record | Empirical probability of exploitation; the data-driven signal recommended by [24] |
| Known-exploited boolean | Claroty xDome record | Corroborating exploitation evidence |
| KEV listing | CISA KEV feed | BOD 26-04 KEV status |
| Known ransomware campaign use | CISA KEV entry | Short-circuits to critical when combined with KEV listing |
Appendix E. Tracker Schema
| Column | Purpose |
|---|---|
| Title | CVE or advisory identifier serving as the row key |
| Group | Vendor or advisory grouping used for consolidated digests |
| CVEs Found | Count of identifiers extracted from the source advisory |
| New Defender | Count newly matched to information technology assets |
| New XDOME | Count newly matched to operational technology assets |
| Already Tracked | Count suppressed as duplicates of existing rows |
| Not Found | Count with no matching asset in either telemetry source |
| Severity and priority | Resolved tier from the fallback chain in Appendix C |
| ServiceNow Incident | Incident number and record URL written back on creation |
| Status | Workflow state used for claiming and closure |
| Created and modified | Timestamps used to compute SLA aging buckets |
Appendix F. Evaluation Calculation
- 40 CVEs: approximately 2 h, representing routine daily volume.
- 500 CVEs: approximately 25 h, representing a typical CISA Weekly Summary.
- 1000 CVEs: approximately 50 h, representing a larger CISA Weekly Summary.
Appendix G. Operational Dataset Construction
- 8 June 2026: 1787 CVEs
- 22 June 2026: 1918 CVEs
- 29 June 2026: 1865 CVEs
- 6 July 2026: 1515 CVEs
- 3 August 2026: 1864 CVEs
- 10 August 2026: 3906 CVEs
- 8 June 2026: 396 findings
- 22 June 2026: 53 findings
- 29 June 2026: 551 findings
- 6 July 2026: 90 findings
- 3 August 2026: 80 findings
- 10 August 2026: 470 findings
Appendix H. Data Note for Figure 1
| Year | Published CVEs | Δ vs. Prior | YoY | Source |
|---|---|---|---|---|
| 2019 | 17,344 | — | — | CVE Program publication count |
| 2020 | 18,325 | +981 | +5.7% | CVE Program publication count |
| 2021 | 20,171 | +1846 | +10.1% | CVE Program publication count |
| 2022 | 25,084 | +4913 | +24.4% | CVE Program publication count |
| 2023 | 28,818 | +3734 | +14.9% | CVE Program publication count |
| 2024 | 39,962 | +11,144 | +38.7% | [4] |
| 2025 | 48,185 | +8223 | +20.6% | [4] |
| Total | 197,889 | +30,841 | +177.8% | 2019–2025 aggregate |
Appendix I. Data Note for Figure 2
| Reporting Window | MTTE (Days) | Δ vs. Prior | Basis |
|---|---|---|---|
| 2018–2019 | 63 | — | [5] |
| 2020 | 44 | −19 | [5] (directly reported) |
| 2021–2022 | 32 | −12 | [5] |
| 2023 | 5 | −27 | [5] |
| 2024 | −1 | −6 | Author-interpolated zero-crossing estimate (see note) |
| 2025 | −7 | −6 | [6] |
Appendix J. Run and Telemetry Evidence
| Workflow | Definition | Runs (Last 24 h) | Sampled Run Durations |
|---|---|---|---|
| Logic App 1—EmailCveNotification | 1 trigger, 500 actions | 12 succeeded, 0 failed | 20.24 s, 26.49 s, 33.94 min, 2.19/2.76/2.87 min, 45.63 min, 6 min, 42.6 min; platform Actions Succeeded ≈ 4.66 k, 0 Actions Failed |
| Logic App 2—CVE_Tracker_mod | 1 trigger, 245 actions | 287 succeeded, 0 failed | 11.7 s, 11.93 s, 13.44 s, 13.61 s, 14.63 s, 15.5 s, 19.44 s, 19.96 s |
| Logic App 3—CVE_Reports | 1 trigger, 151 actions | 0 succeeded, 0 failed (monthly) | 4.14, 4.27, 4.62, 5.08, 5.19, 5.20, 5.45, 5.64, 6.29 min (runs dated 2 Jul–1 Aug 2026) |
| Tracker Field | Value |
|---|---|
| Title | CISA Weekly Summary—CVE-2026-65400, Apple macOS Improper Authentication Vulnerability |
| ServiceNow Incident | INC0927352 |
| Date opened | 17 Aug 2026 |
| Threat-Intel Severity | Medium |
| Threat-Intel Source | Other |
| Status | OPEN |
| Assigned Group | Desktop Engineering |

- Note: Reproduced from the SharePoint tracker for one processed item, illustrating that each finding carries a resolved severity tier, a written-back ServiceNow incident number, and a routing assignment, so any prioritization or deferral decision can be reconstructed from the record. This is the auditable-prioritization property claimed in Section 3.3; it is not a claim of comparative predictive accuracy against ground-truth exploitation outcomes (Section 3.4.3). Field values other than the CVE identifier and incident number are shown as recorded; internal identifiers are withheld.
Appendix K. Automated Notification Emails

| Metric | Value |
|---|---|
| Total CVEs/affecting us/not affecting us | 1864/80/1784 |
| Software groups/groups affecting us | 907/8 |
| Estimated manual review avoided (banner) | 3 min average manual review per CVE; banner “Est. time saved: 3 day(s) 21 h” |
| New tracker items created (with device-list evidence) | Microsoft Edge (Chromium) 14 CVEs → #2181; Microsoft Edge for Android 1 → #2182; Cisco IOS XE Software 12 → #2183; Eclipse Foundation Jetty ee8 1 → #2184 |

- Note: Groups with detected device exposure have tracker items created automatically; groups with no detected devices are counted in the summary only. Values transcribed from the notification; recipient details withheld.
| Metric | Value |
|---|---|
| Source | [Informational] TLP GREEN: Ransomware Data Leak Sites Report |
| CVEs found/new Defender/new xDome/already tracked/not found | 6/0/1/0/5 |
| Escalation rule applied | CISA KEV catalog loaded; CVEs with confirmed ransomware use marked CISA KEV + Ransomware and auto-escalated to Critical; all other findings floored at High regardless of CVSS |
| Flagship finding | CVE-2021-26855 (Microsoft Exchange Server RCE): CVSS 9.8, EPSS 100%, 1 OT/IoMT device, CISA KEV + Ransomware + xDome-Exploited → auto-escalated Critical; tracker #2261 |

- Note: XDOME-only CVEs receive their own tracker item with full Copilot analysis; CVEs present in both Defender and xDome share one tracker item. Transcribed from the notification.
| Item | Value |
|---|---|
| NVD companion “1 resolved” | CVE-2026-65400: CVSS 9.8 Critical, Not in KEV, no mapped vendor KB → workstation incident INC0927352 (tracker title updated so it is not reprocessed) |
| KEV listed, no exposure (manual review required) | CVE-2025-55182, CVE-2022-26134, CVE-2024-37085, CVE-2026-35273, CVE-2025-30406—“No exposure data found in Defender or XDOME; however, this CVE IS listed in the CISA KEV catalog. Manual review required.” |
| H-ISAC intelligence audit (sample) | Akira → CVE-2024-37085 (VMware ESXi), Confidence HIGH/Microsoft Threat Intelligence; 3 AM → No CVE (LOW); Anubis → No CVE (HIGH/Microsoft MSTIC) |
| CVE | Affected Product(s) and KB | Deploy |
|---|---|---|
| CVE-2026-55040 | Microsoft SharePoint Enterprise Server 2016 KB5002891; SharePoint Server 2019 KB5002883; Windows 11 23H2 (ARM64 and x64)… | Open |
| CVE-2026-33824 | Microsoft SharePoint Enterprise Server 2016 KB5002891; SharePoint Server 2019 KB5002883; Windows 11 23H2 (ARM64 and x64)… | Open |

- Note: The notification maps each affected CVE to its Microsoft KB and provides a deploy link; ellipses indicate additional affected builds truncated in the source view. Transcribed from the notification; hostnames withheld.
References
- Beddies, C.; Eylert, B.; Kubica, S. The necessity of secure IT infrastructures in healthcare through AI vulnerability analysis. In Mechanisms and Machine Science; Springer: Cham, Switzerland, 2024; Volume 162, pp. 298–310. [Google Scholar] [CrossRef] [Scilit]
- Heinl, P.; Patapovas, A.; Pilgermann, M. Towards AI-enabled cyber threat assessment in the health sector. arXiv 2024, arXiv:2409.12765. [Google Scholar] [CrossRef] [Scilit]
- Islam, S.; Abba, A.; Ismail, U.; Mouratidis, H.; Papastergiou, S. Vulnerability prediction for secure healthcare supply chain service delivery. Integr. Comput.-Aided Eng. 2022, 29, 389–409. [Google Scholar] [CrossRef] [Scilit]
- Gamblin, J. 2025 CVE Data Review. 2026. Available online: https://jerrygamblin.com/2026/01/01/2025-cve-data-review/ (accessed on 25 July 2026).
- Charrier, C.; Weiner, R. How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends; Mandiant, Google Cloud: Reston, VA, USA, 2024; Available online: https://cloud.google.com/blog/topics/threat-intelligence/time-to-exploit-trends-2023 (accessed on 25 July 2026).
- Mandiant. M-Trends 2026: Data, Insights, and Strategies from the Frontlines; Mandiant, Google Cloud: Reston, VA, USA, 2026; Available online: https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026 (accessed on 25 July 2026).
- Cybersecurity and Infrastructure Security Agency. Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk; U.S. Department of Homeland Security: Washington, DC, USA, 2026. Available online: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk (accessed on 25 July 2026).
- Hevner, A.R.; March, S.T.; Park, J.; Ram, S. Design science in information systems research. MIS Q. 2004, 28, 75–105. [Google Scholar] [CrossRef] [Scilit]
- Malkawi, M.; Alhajj, R. AI-powered vulnerability detection and patch management in cybersecurity: A systematic review of techniques, challenges, and emerging trends. Mach. Learn. Knowl. Extr. 2026, 8, 19. [Google Scholar] [CrossRef] [Scilit]
- Mohammed, M.Q.; Jaaz, Z.A. A comprehensive review of predictive vulnerability prioritization using AI. Int. J. Comput. Electron. Asp. Eng. 2026, 7, 27–44. [Google Scholar] [CrossRef] [Scilit]
- Nobles, C. Stress, burnout, and security fatigue in cybersecurity: A human factors problem. HOLISTICA J. Bus. Public Adm. 2022, 13, 49–72. [Google Scholar] [CrossRef] [Scilit]
- Tariq, S.; Baruwal Chhetri, M.; Nepal, S.; Paris, C. Alert fatigue in security operations centres: Research challenges and opportunities. ACM Comput. Surv. 2025, 57, 224. [Google Scholar] [CrossRef] [Scilit]
- Huber, R. CISA BOD 26-04: Frequently Asked Questions About the New Risk-Based Patching Directive; Tenable: Columbia, MD, USA, 2026; Available online: https://www.tenable.com/blog/cisa-bod-26-04-FAQ-vulnerability-remediation-impact (accessed on 25 July 2026).
- Kaniewski, S.; Schmidt, F.; Enzweiler, M.; Menth, M.; Heer, T. A systematic literature review on detecting software vulnerabilities with large language models. arXiv 2025, arXiv:2507.22659. [Google Scholar] [CrossRef] [Scilit]
- Verizon. 2026 Data Breach Investigations Report; Verizon Business: New York, NY, USA, 2026. [Google Scholar]
- Hilario, E.; Azam, S.; Sundaram, J.; Imran Mohammed, K.; Shanmugam, B. Generative AI for pentesting: The good, the bad, the ugly. Int. J. Inf. Secur. 2024, 23, 2075–2097. [Google Scholar] [CrossRef] [Scilit]
- Ferrag, M.A.; Alwahedi, F.; Battah, A.; Cherif, B.; Mechri, A.; Tihanyi, N.; Bisztray, T.; Debbah, M. Generative AI in cybersecurity: A comprehensive review of LLM applications and vulnerabilities. Internet Things Cyber-Phys. Syst. 2025, 5, 1–46. [Google Scholar] [CrossRef] [Scilit]
- Ginige, Y.; Niroshan, A.; Jain, S.; Seneviratne, S. AutoPenTester: An LLM agent-based framework for automated penetration testing. In Proceedings of the 24th IEEE International Conference on Trust, Security and Privacy in Computing and Communications; IEEE: New York, NY, USA, 2025; pp. 163–174. [Google Scholar]
- Benson, D.; Panchev, C. Leveraging large language models in post-exploitation: Navigating the cyber kill chain with AI-driven tactics. In Computer Security: ESORICS 2025 International Workshops; Laborde, R., Garcia-Alfaro, J., Yazdinejad, A., Epiphaniou, G., Abie, H., Ranise, S., Choraś, M., Woźniak, M., Hara, Y., Mühlberg, J.T., et al., Eds.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2026; Volume 16233. [Google Scholar] [CrossRef] [Scilit]
- Chen, J.; Hu, S.; Zheng, H.; Xing, C.; Zhang, G. GAIL-PT: An intelligent penetration testing framework with generative adversarial imitation learning. Comput. Secur. 2023, 126, 103055. [Google Scholar] [CrossRef] [Scilit]
- Jin, D.; Fu, Q.; Li, Y. Good news for script kiddies? Evaluating large language models for automated exploit generation. arXiv 2025, arXiv:2505.01065. [Google Scholar] [CrossRef] [Scilit]
- Peng, W.; Ye, L.; Du, X.; Zhang, H.; Zhan, D.; Zhang, Y.; Guo, Y.; Zhang, C. PwnGPT: Automatic exploit generation based on large language models. In Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics; ACL: Kerrville, TX, USA, 2025; pp. 11–29. Available online: https://aclanthology.org/2025.acl-long.562/ (accessed on 23 June 2026).
- Fang, R.; Bindu, R.; Gupta, A.; Kang, D. LLM agents can autonomously exploit one-day vulnerabilities. arXiv 2024, arXiv:2404.08144. [Google Scholar] [CrossRef] [Scilit]
- Jacobs, J.; Romanosky, S.; Edwards, B.; Adjerid, I.; Roytman, M. Exploit Prediction Scoring System (EPSS). Digit. Threat. Res. Pract. 2021, 2, 20. [Google Scholar] [CrossRef] [Scilit]
- Le, T.H.M.; Chen, H.; Babar, M.A. A survey on data-driven software vulnerability assessment and prioritization. ACM Comput. Surv. 2023, 55, 100. [Google Scholar] [CrossRef] [Scilit]
- Aljahdali, A.O.; Alsulami, R. Streamlining threat response and automating critical use cases with security orchestration, automation and response (SOAR). J. Digit. Secur. Forensics 2025, 2, 36–57. [Google Scholar] [CrossRef] [Scilit]
- Ismail; Kurnia, R.; Brata, Z.A.; Nelistiani, G.A.; Heo, S.; Kim, H.; Kim, H. Toward robust security orchestration and automated response in security operations centers with a hyper-automation approach using agentic artificial intelligence. Information 2025, 16, 365. [Google Scholar] [CrossRef] [Scilit]
- Cybersecurity and Infrastructure Security Agency. BOD 26-04: Implementation Guidance for Prioritizing Security Updates Based on Risk; U.S. Department of Homeland Security: Washington, DC, USA, 2026. Available online: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk (accessed on 25 July 2026).
- Cybersecurity and Infrastructure Security Agency. CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities [Press Release]; U.S. Department of Homeland Security: Washington, DC, USA, 2026. [Google Scholar]
- Jalalvand, F.; Baruwal Chhetri, M.; Nepal, S.; Paris, C. Alert prioritisation in security operations centres: A systematic survey on criteria and methods. ACM Comput. Surv. 2025, 57, 156. [Google Scholar] [CrossRef] [Scilit]
- Bandura, A. Self-Efficacy: The Exercise of Control; W. H. Freeman: New York, NY, USA, 1997. [Google Scholar]
- Venable, J.; Pries-Heje, J.; Baskerville, R. FEDS: A framework for evaluation in design science research. Eur. J. Inf. Syst. 2016, 25, 77–89. [Google Scholar] [CrossRef] [Scilit]
- Landis, J.R.; Koch, G.G. The measurement of observer agreement for categorical data. Biometrics 1977, 33, 159–174. [Google Scholar] [CrossRef] [Scilit]
- Cohen, J. A coefficient of agreement for nominal scales. Educ. Psychol. Meas. 1960, 20, 37–46. [Google Scholar] [CrossRef] [Scilit]
- Gwet, K.L. Computing inter-rater reliability and its variance in the presence of high agreement. Br. J. Math. Stat. Psychol. 2008, 61, 29–48. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Wilcoxon, F. Individual comparisons by ranking methods. Biom. Bull. 1945, 1, 80–83. [Google Scholar] [CrossRef] [Scilit]


| Design Science Guideline | How This Study Addresses It |
|---|---|
| Design as an artifact | A three-application Azure Logic Apps pipeline for CVE ingestion, enrichment, prioritization, and tracking (Section 2.5). |
| Problem relevance | An AI-accelerated, volume-driven prioritization gap in healthcare vulnerability management (Section 2.3). |
| Design evaluation | Analytical evaluation against a documented baseline of three minutes per CVE lookup (Section 3). |
| Research contributions | A replicable artifact instantiation and its explicit alignment to the BOD 26-04 risk model (Section 2.5 through Section 4). |
| Research rigor | Grounding in peer-reviewed prioritization, orchestration, and healthcare security literature (Section 2.1). |
| Design as a search process | Iterative refactoring for scale, including the exposure-first optimization introduced on the weekly path (Section 2.5.6). |
| Communication of research | This white paper, structured for both technical and managerial audiences. |
| Requirement | Source | Design Feature | Supports |
|---|---|---|---|
| Identify CVE references in unstructured advisories | Advisory workload | Logic App 1 decomposes the message into hyperlinks, raw and plain-text URLs, fetches linked pages, normalizes Unicode separators, then tokenizes and de-duplicates | RQ2 |
| Determine whether a CVE affects the environment | BOD 26-04 asset exposure | Defender Advanced Hunting and Claroty xDome device queries establish exposure from internal telemetry rather than from the advisory | RQ2 |
| Avoid spending enrichment cycles on non-affecting CVEs | Weekly-scale runtime limits | Exposure-first ordering; scope and KB lookups execute only for CVEs with confirmed affected assets | RQ2 |
| Weight real-world exploitability over intrinsic severity | Exploit prediction literature; BOD 26-04 exploit automation | KEV status, EPSS probability, and NVD exploitability are supplied to Security Copilot with an explicit instruction not to rely on CVSS alone | RQ1, RQ2 |
| Resolve every CVE as a priority even when AI is unavailable | Reliability concerns in AI security tooling | Deterministic fallback chain with a terminal default; downstream actions execute after success, failure, timeout, or skip | RQ2 |
| Preserve an audit trail for prioritization and deferral | BOD 26-04 documentation obligation | SharePoint tracker as system of record, incident URL write-back, row claiming, deduplication, and SLA aging in the monthly report | RQ2 |
| BOD 26-04 Risk Factor | Operationalization in the Artifact |
|---|---|
| Asset exposure | Established through Microsoft Defender Advanced Hunting and the Claroty xDome device list, reflecting whether the organization holds exposed, affected assets. |
| KEV status | Live check against the CISA KEV feed at ingestion. KEV listing combined with known ransomware association drives automatic critical classification. |
| Exploit automation | Assessed from three empirical exploitability signals, the MSRC exploitability index carried in the CVRF advisory, the EPSS probability supplied with the Claroty xDome record, and the NVD CVSS exploitability sub-metrics—which are passed to Security Copilot with an explicit instruction not to rely on CVSS severity alone. KEV listing and the known-ransomware flag act as deterministic escalators over these signals. |
| Post-exploitation technical impact | Derived from the NVD impact sub-metrics and from a Security Copilot assessment of blast radius and patient-safety and uptime consequence, using the Defender and Claroty xDome device counts and the healthcare-contextual rubric (for example, any 1 to 5 clinical OT devices establishes a high minimum). Documented application-criticality tiers from the ServiceNow APM inventory (Tier 0 mission-critical through Tier 2 business-use) are being incorporated as an additional impact input under the routing enhancement described in Section 4.1. |
| Resulting priority and timeline | Combined signals drive the tracker severity and priority fields, and the SLA aging buckets are reported monthly. In the current pre-production configuration, ServiceNow urgency and impact default to Low; a mapping from tracker severity to ServiceNow priority (Critical to P1, High to P2, and so on) is being promoted to production (see Section 4.1). |
| Question | Evidence Used | Artifact Element | Finding |
|---|---|---|---|
| RQ1 | Published CVE volume; mean time to exploit; peer-reviewed work on AI exploit generation; alert fatigue literature | Problem framing and the decision to treat exploit automatability as a changing rather than fixed property | AI and industrialized disclosure together produce a workload and prioritization failure mode, not merely a larger queue |
| RQ2 | Documented manual lookup baseline; workflow action counts and ordering; task reallocation; BOD 26-04 factor mapping | Logic Apps 1 through 3, the tracker, exposure-first ordering, Copilot scoring with deterministic fallback | The artifact displaces lookup effort and retains a documented prioritization rationale, with the ticketing gap noted in Section 4.1 |
| Bulletin | Total CVEs | Affecting Us | % Filtered | Groups Affecting |
|---|---|---|---|---|
| Week of 8 June 2026 | 1787 | 396 | 77.8% | 34 |
| Week of 22 June 2026 | 1918 | 53 | 97.2% | 9 |
| Week of 29 June 2026 | 1865 | 551 | 70.5% | 14 |
| Week of 6 July 2026 | 1515 | 90 | 94.1% | 11 |
| Week of 3 August 2026 | 1864 | 80 | 95.7% | 8 |
| Week of 10 August 2026 | 3906 | 470 | 88.0% | 32 |
| Aggregate | 12,855 | 1640 | 87.2% | 108 |
| Bulletin (Total CVEs) | At 2 min | At 3 min | At 5 min |
|---|---|---|---|
| 8 June (1787) | 59.6 h | 89.3 h | 148.9 h |
| 22 June (1918) | 63.9 h | 95.9 h | 159.8 h |
| 29 June (1865) | 62.2 h | 93.2 h | 155.4 h |
| 6 July (1515) | 50.5 h | 75.8 h | 126.2 h |
| 3 August (1864) | 62.1 h | 93.2 h | 155.3 h |
| 10 August (3906) | 130.2 h | 195.3 h | 325.5 h |
| Aggregate (12,855) | 428.5 h | 642.8 h | 1071.2 h |
| Repeated Item | Runs | Field Drift Observed | Severity Stable? | Priority Stable? |
|---|---|---|---|---|
| CVE-2024-2511 | 2 | OT/IoMT device count drifted 317 to 320 with updated logic | Yes | Yes |
| Adobe Acrobat Reader group | 3 | Free-text rationale prose varied | Yes | Yes |
| Test or Statistic | What It Establishes | Addresses |
|---|---|---|
| Cohen’s kappa/Gwet’s AC1 | Model–analyst severity agreement | Construct validity (RQ2) |
| McNemar | Override never de-escalates a true Critical | Safety/internal validity |
| Wilcoxon signed rank | Measured per-CVE time reduction | RQ2 effect size |
| Bulletin-level variance | Non-stationary relevance rate | External validity/planning |
| Workflow | Trigger Cadence | Observed Run Duration (Sampled Window) | Observed Success |
|---|---|---|---|
| 1. CVE intake and enrichment | New mail; 10 s polling | Payload-dependent; approximately 20 s for a small individual advisory to about 25–45 min for a full weekly bulletin | 12 of 12 runs succeeded and 0 failed, in a representative 24 h window; platform Actions Succeeded metric 4.66 k with 0 Actions Failed |
| 2. Tracker update and incident automation | 5 min recurrence; single instance | Approximately 10–17 s up to 5 min for weekly bulletins | 287 of 287 runs succeeded and 0 failed, in a representative 24 h window |
| 3. Monthly reporting | Day 1 of month, 08:00 Central | Approximately 4–6.3 min | All sampled monthly runs succeeded; 0 failed |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Anderson, C.L. A Design Science Study of Automated CVE Ingestion and Risk-Based Vulnerability Prioritization in Healthcare Cybersecurity. Information 2026, 17, 846. https://doi.org/10.3390/info17090846
Anderson CL. A Design Science Study of Automated CVE Ingestion and Risk-Based Vulnerability Prioritization in Healthcare Cybersecurity. Information. 2026; 17(9):846. https://doi.org/10.3390/info17090846
Chicago/Turabian StyleAnderson, Carl L. 2026. "A Design Science Study of Automated CVE Ingestion and Risk-Based Vulnerability Prioritization in Healthcare Cybersecurity" Information 17, no. 9: 846. https://doi.org/10.3390/info17090846
APA StyleAnderson, C. L. (2026). A Design Science Study of Automated CVE Ingestion and Risk-Based Vulnerability Prioritization in Healthcare Cybersecurity. Information, 17(9), 846. https://doi.org/10.3390/info17090846
