15 June 2026
Rapid7 vs Tenable: Why Severity Scores Differ
By Greg Tereszczyn, Founder & Principal Consultant
The same CVE often shows a different severity in Rapid7 and Tenable because each platform adds its own risk score on top of the standard CVSS score, and the two scores weigh exploit activity, age and threat intelligence differently. Neither tool is wrong. It matters because the Essential Eight sets patching deadlines by the vendor's severity, so the label a tool chooses can move a fix from a two-week window to 48 hours.
Is CVSS the same in Rapid7 and Tenable?
Yes. Both platforms show the Common Vulnerability Scoring System (CVSS) score, and for a given CVE it is identical in either tool, because CVSS is a published standard. Its limit is that it has no context: it does not know whether attackers are exploiting the flaw today, how long it has been public, or how hard it is to use in practice. Both vendors add their own scoring on top to fill that gap, and they fill it differently.
How does Rapid7 score vulnerability risk?
Rapid7's own score, the Vulnerability Risk Score (Active Risk in newer versions of InsightVM), adds three things to CVSS:
- Age: a vulnerability left unpatched for longer accumulates risk.
- Exploit availability: whether a working exploit exists, for example in Metasploit, or is circulating in the wild.
- Threat intelligence: exploit kits and attacker activity observed across Rapid7's telemetry.
So a vulnerability with a moderate CVSS score can reach the top of a Rapid7 priority list if it is old, easy to exploit and actively used by attackers. That is intentional: the score reflects operational risk, not theoretical severity (Rapid7 Vulnerability Risk Score).
How does Tenable's VPR score risk?
Tenable uses the Vulnerability Priority Rating (VPR). It also blends threat intelligence and exploitability with CVSS, but draws on different data sources and weights them differently. Its score ranges and severity names differ as well, so what Rapid7 labels "High" can sit under a different label or range in Tenable (Tenable: what is VPR). Two tools looking at the same CVE can reach materially different severities, not because one is wrong, but because each vendor made different engineering choices about how to weigh risk.
What does the difference look like in practice?
The screenshot shows one CVE side by side as it appears in Rapid7 InsightVM and in Tenable. The severity rating, the score and the naming all differ, although the vulnerability is the same.

Expect these discrepancies whenever you move from one platform to another or run both during a migration. Telling stakeholders early stops the new tool being mistaken for a faulty one.
Why does severity matter for Essential Eight patching?
The Essential Eight's two patching strategies, patch applications and patch operating systems, set their deadlines by whether a vulnerability is "assessed as critical by vendors" or has a working exploit, not by CVSS (ASD, Essential Eight Maturity Model). The 48-hour deadline for critical vulnerabilities in online services and internet-facing systems applies at all three maturity levels; what grows with each level is the range of software it covers:
| Software or system | ML1 | ML2 | ML3 |
|---|---|---|---|
| Online services: critical or working exploit | 48 hours | 48 hours | 48 hours |
| Online services: non-critical, no exploit | 2 weeks | 2 weeks | 2 weeks |
| Internet-facing servers and network devices (operating system): critical or working exploit | 48 hours | 48 hours | 48 hours |
| Internet-facing servers and network devices (operating system): non-critical, no exploit | 2 weeks | 2 weeks | 2 weeks |
| Office suites, browsers, email clients, PDF software, security products | 2 weeks | 2 weeks | 48 hours (critical) or 2 weeks |
| Other applications | Not required | 1 month | 1 month |
| Workstations and non-internet-facing systems (operating system) | 1 month | 1 month | 48 hours (critical) or 1 month |
| Drivers and firmware | Not required | Not required | 48 hours (critical) or 1 month |
If your previous tool rated a vulnerability Medium and your new tool rates the same CVE Critical, the deadline changes, even though the vulnerability did not. For an internet-facing system that is the difference between two weeks and 48 hours at every maturity level. Meeting those windows is as much a remediation problem as a detection one: the detect, prioritise, remediate, verify loop we describe in our NinjaOne partnership post.
Which tool's severity should you follow?
The Essential Eight accepts the vendor's severity, so when two tools disagree you have to decide, and document, which one governs your patching deadlines. A conservative and defensible rule: if any tool in your environment rates a vulnerability Critical, treat it as Critical for Essential Eight purposes. That avoids compliance gaps during a migration and removes the argument when tools diverge.
Keep CVSS as the consistent cross-platform reference for reporting and benchmarking, but do not prioritise on raw CVSS: the Essential Eight does not ask for it, and you lose the context both platforms exist to add. Build this into stakeholder communication from the start of a migration. Severity differences between platforms are not an anomaly to investigate; they are how each tool approaches risk.
Need help with a vulnerability management migration?
If you are moving between Rapid7 and Tenable, maturing a programme on either, or building consistent vulnerability management across IT and OT, contact us. To see which Essential Eight patching controls your current licences already cover, run the free coverage check, or start with the $399 IT Security Review. Our Essential Eight assessment page explains the framework end to end.
Updated 4 October 2026: rewritten answer-first, and the Essential Eight table checked against ASD's current maturity model (it now includes the "other applications" row).
About the author
Greg Tereszczyn
Greg Tereszczyn is the founder and principal consultant of TERESEC, an Australian cyber security consultancy for small and medium business. He turns the Essential Eight, the ISM, ISO/IEC 27001, NIST CSF and IEC 62443 into plain-English advice a business can act on.