Cloud Security Compare

Lesson 2 · Basics · 3 min read

How CNAPPs rank risk: severity, exploitability and attack paths

Cloud Security Compare editors · Matchups reviewed September 2026 · Editorial assessment

The short version

A CNAPP ranks a finding by combining how bad it would be, how likely it is to be exploited, whether the affected code actually runs, and whether it sits on a path to something valuable. Vendors weigh these inputs differently, which is why the top of two products' lists rarely match. Our risk prioritization criterion, weighted 18%, scores how completely each vendor combines them.

Why is severity alone not enough?

A large cloud estate can produce thousands of vulnerability findings, and many carry a high or critical severity rating. Severity describes how bad a flaw would be if it were exploited in general. It does not say whether this flaw, on this workload, can be reached by an attacker, whether the vulnerable package ever loads, or what the attacker would get. Teams that fix by severity alone spend most of their time on findings that pose little real risk, while the few that matter wait in the same queue.

What inputs do CNAPPs add?

  • Exploit likelihood. EPSS, run by a special interest group at FIRST, estimates the probability that a published CVE will be exploited in the next 30 days. Aqua Security names EPSS scores and evidence of active exploitation among its ranking inputs.
  • Runtime context. A vulnerability in a package that never loads is less urgent than one in code that runs. Sysdig Secure uses runtime insight to filter out vulnerabilities in packages that are not in use, and the Orca Sensor shows which vulnerable packages are executed.
  • Exposure. Whether the workload can be reached from the internet, and through which path.
  • Identity and data. Which permissions the workload holds and which sensitive data those permissions can reach.

How do attack paths bring the inputs together?

An attack path chains these inputs: an internet-exposed workload, a vulnerable package on it, an over-permitted identity attached to it and a data store that identity can read. Breaking any one link breaks the path, so a tool that shows paths can point to the single cheapest fix. Wiz builds attack paths through its Security Graph, which links infrastructure, identities, data and AI resources. Orca Security runs attack path analysis on one data model built from agentless context. SentinelOne's Offensive Security Engine checks which exposures are exploitable and shows Verified Exploit Paths. CrowdStrike enriches posture findings with its adversary intelligence.

How do the vendors score on this criterion?

On our matrix Wiz leads risk prioritization at 4.9, with Orca Security at 4.8 and Upwind at 4.5. Microsoft Defender for Cloud and Aqua Security score lowest, at 3.9 each. The scores reflect how completely each vendor's public material describes combining the inputs above, not a measured result. Every score and its reason is on the comparison matrix.

How do you test risk ranking?

Give both products the same accounts and export each one's ten highest-priority findings. For each item, ask whether it is real, whether it is reachable and whether your team would fix it this week. Then read the explanation each product gives for its ranking: engineers act on a clear path faster than on a score. The proof of concept note sets out the full test, and our note on risk prioritization in CNAPPs compares what each vendor describes.

Related pages

Next lesson: Code security in a CNAPP: SCA, SAST, IaC, secrets and code-to-cloud