A VEX document says whether a specific product or release is affected by a known vulnerability, and may explain why or describe the supplier’s response. Its status applies to the product and version named in the advisory—not automatically to every product that uses the same component. To decide what it means for your deployment, match the vulnerability, product and release, then read the status, rationale and update information together.
What is VEX?
VEX stands for Vulnerability Exploitability eXchange. It is machine-readable information about whether a named product is affected by a known vulnerability. The OASIS Common Security Advisory Framework (CSAF) Version 2.1 VEX profile puts its purpose this way: “The main purpose of the VEX format is to state that and why a certain product is, or is not, affected by a vulnerability.” Read the OASIS CSAF 2.1 VEX profile.
A VEX statement is a supplier’s product-specific assertion, not a general verdict about a software component in every context. CSAF VEX associates product status with product and vulnerability records. A document can cover multiple products or releases and report different states for each, so check the exact product identity and release rather than relying on a product family name or a component match alone.
What do the VEX statuses mean?
In the CSAF VEX profile, the principal status values are known_affected, known_not_affected, fixed and under_investigation. Cisco’s VEX FAQ describes these in practical terms:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
| Status | Practical meaning | How to read it |
|---|---|---|
known_affected |
The product is affected by the vulnerability. | Use the advisory’s remediation or response information to determine what action the supplier recommends. |
known_not_affected |
The product is not affected; no remediation is necessary for that product and vulnerability. | Read the stated justification, and confirm that the product and release match your deployment. |
fixed |
A fix has been applied to mitigate the impact. | Check which release or product the fixed status applies to; do not assume your installed version includes the fix. |
under_investigation |
It is not yet known whether the product is affected. | Treat the status as unresolved and look for later advisory information. |
These status definitions are for the CSAF VEX profile; other formats may use different fields or vocabularies. Cisco’s definitions and guidance appear in its Vulnerability Exploitability eXchange FAQs.
What does “not affected” mean?
known_not_affected is a claim about the product as identified in the advisory. The justification explains why the vulnerability does not apply to that product. It is not, by itself, a guarantee about every configuration or deployment choice a reader may have made. Cisco’s FAQ describes several common justification categories:
Rank #2
component_not_present: the vulnerable component is not included in the product.vulnerable_code_not_present: the component may be present, but the vulnerable code is not.vulnerable_code_not_in_execute_path: the vulnerable code is not reached along the relevant execution path.vulnerable_code_cannot_be_controlled_by_adversary: an attacker cannot control the code in the way required for exploitation.inline_mitigations_already_exist: a mitigation within the product prevents exploitation.
These are reasons for the supplier’s product-level assessment, not severity ratings. If the stated rationale depends on a particular product design or behavior, compare it with the product and release you actually run; do not substitute assumptions about your local configuration for the supplier’s stated scope.
How do status, justification and response differ?
They answer separate questions. Status is the disposition for a product and vulnerability; justification is why that disposition applies; response describes what the supplier has done or plans to do. CycloneDX’s vulnerability exploitability use case describes these as distinct information, alongside detail about unaffected versions. See the CycloneDX vulnerability exploitability use case.
Rank #3
For example, “not affected” is the status, “the vulnerable component is absent” is a possible justification, and “no remediation is needed” may describe the response. Keeping these concepts separate helps avoid mistaking an explanation for a fix or a remediation plan for proof that a particular installed release is already fixed.
How do I know whether a VEX statement applies to my product version?
- Identify the vulnerability. Match the vulnerability identifier in the advisory to the issue you are investigating.
- Match the product and release. Compare the product identity and version in the VEX record with the product actually deployed. If the advisory gives version-specific scope, use it rather than assuming that all releases share a status.
- Read the status and its context. Check the applicable status, any justification, and the supplier’s response or remediation information. For a fixed status, determine which release contains the fix.
- Check the advisory’s dates and source. Review its publication or update information and consult the supplier’s current advisory for the exact release before making a current security decision.
VEX complements, rather than replaces, product and component inventory. CISA’s Software Acquisition Guide explains that a software bill of materials (SBOM) helps identify components, while VEX helps determine whether known vulnerabilities affect a product and whether action is needed. Read CISA’s Software Acquisition Guide for Government Enterprise Consumers.
Rank #4
Why did the VEX status change?
A status can change as a supplier investigates a vulnerability, learns more about a product, or makes a fix available. Cisco describes VEX information as point-in-time: it can become obsolete as vulnerabilities are disclosed, fixed and investigated. A previous “under investigation” status may be clarified later, and a fix may change the status for a particular release. Check the supplier’s updated advisory rather than treating an older VEX file as a permanent verdict. The CISA VEX Use Cases Document also illustrates that one document can give different statuses for different products and versions.
There is no universal update schedule established by these sources. Suppliers’ publication and revision practices differ, so the advisory’s own update details and the supplier’s current security information are the relevant guides.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Are all VEX files in the same format?
No. CISA identifies CSAF, CycloneDX and SPDX as formats in which VEX can be implemented, and also mentions OpenVEX implementations. The common purpose is to communicate vulnerability applicability, but the available sources do not establish that the formats have identical fields, product-identity methods, status vocabularies or requirements. When reading a file, identify its format and interpret its fields according to that format’s specification rather than assuming one schema applies to all.
If you are evaluating VEX support in a security workflow, useful questions include how the format identifies products and versions, what status and justification vocabulary it supports, how files are distributed and updated, and how vulnerability statements relate to an SBOM. A format name alone does not tell you whether a particular supplier publishes updates in a way your process can consume.
What does Microsoft’s 2026 VEX announcement cover?
In an announcement dated September 8, 2026, Microsoft said it was publishing VEX statements for all Microsoft-assigned CVEs. This is Microsoft’s stated coverage, not an industry-wide commitment or a guarantee about another supplier’s products or publishing practice. Read Microsoft Security Response Center’s announcement.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




