What 'Critical Severity' Actually Means When a Hospital or Utility Gets a Warning
Security bulletins sent to hospitals and utilities throw around words like critical, high, and CVE score constantly. Here's what they mean and how worried you should actually be.
Every time a serious software flaw is found in equipment used by hospitals or utilities, it comes with a number — “CVSS 9.8,” “critical severity,” “actively exploited.” Most coverage never explains what that actually means, or why the same vulnerability is a bigger deal in a hospital’s infusion pump network than on your laptop.
The scoring system, in plain terms
CVSS (Common Vulnerability Scoring System) rates a software flaw from 0 to 10 based on how easy it is to exploit and how much damage it can do:
- 0.1–3.9 — Low. Hard to exploit, limited damage even if it works.
- 4.0–6.9 — Medium. Worth patching promptly, not an emergency.
- 7.0–8.9 — High. Exploitable with real impact — attackers actively look for these.
- 9.0–10.0 — Critical. Easy to exploit remotely, often without a password, with major consequences. This is the “patch today, not this week” tier.
The word that matters more than the score
A 9.8 sitting unused in a lab is less urgent than a 7.5 that’s “actively exploited in the wild” — meaning real attackers are already using it, right now, against real systems. When you see that phrase next to a company or product you use, that’s the actual signal to act, regardless of the number attached.
What this means for you as a patient or resident, not an IT admin
You’ll never patch a hospital’s medical devices or a utility’s control systems yourself — their IT and biomedical engineering teams do. What the severity tells you is how seriously to take a “please update immediately” notice, a scheduled system-maintenance announcement, or a follow-up breach notification if the flaw was actually exploited before it got patched.
Worried this affects you?
Check whether your email address has shown up in this breach — or any other — in seconds.
Run a free breach check →Related coverage
Colonial Pipeline, Years Later: The Lesson That Actually Stuck
The 2021 ransomware attack that shut down fuel supply on the East Coast started with a single reused password. That detail still matters more than the headline did.
The Change Healthcare Breach: The Largest Healthcare Hack in US History
A ransomware attack on a single billing company froze prescriptions and payments across the entire US healthcare system for weeks. Here's what happened and who was affected.