Product Announcements

Forum Discussion

tsitcawich's avatar
tsitcawich
Product Team
3 months ago

Tenable product update: Standardizing Tenable risk scoring

At Tenable, we are committed to providing the most accurate, defensible, and actionable view of organizational risk. To achieve this, we must continually refine the intelligence that powers your prioritization. 

On July 1, 2026, we are implementing a series of foundational updates to our risk scoring engines. As part of this update, you may see changes to your risk scores, depending on the Tenable product(s) you own. These changes simplify your workflow by standardizing scoring on a single, high-fidelity model for vulnerability and asset risk. 

The new standard for VPR 

For the past several months, many of you have utilized VPR (Beta) to gain deeper insights into exploitability. We are excited to announce that on July 1, this model will be promoted to the primary Vulnerability Priority Rating (VPR) across the Tenable platform.

By standardizing on this advanced model, we are retiring legacy VPR scoring to ensure every customer benefits from our most sophisticated threat intelligence. The new version of VPR incorporates more threat intelligence and vulnerability metadata so that you can focus on the 1.6% of vulnerabilities that actually matter.  

Better context through enhanced asset classification 

Alongside the VPR update, we are enhancing our asset classification engine. This update improves how we identify the function and importance of assets across your entire attack surface, including Cloud, OT, and third-party devices. As a result, customers with access to Asset Criticality Ratings (ACR) for VM assets will see these scores more accurately reflect real-world business risk. 

What this means for you

These are backend enhancements designed to provide immediate value with zero manual configuration. On July 1, your dashboards, reports, and APIs will automatically reflect these updated metrics. 

Because both VPR and ACR serve as inputs to Cyber Exposure Score (CES) and Asset Exposure Score (AES), customers using these scores may see changes that reflect a more accurate understanding of exposure.

Customer FAQ

  1. What happens to the VPR (Beta) score in the Tenable UI? The Beta label will be removed. The high-fidelity model you’ve been previewing will become the standard VPR. The legacy version of VPR will be retired to ensure a single, unified source or truth. 
  2. Do I need to rewrite my custom API scripts using VPR? No. For customers using APIs, updated values will be mapped into legacy VPR fields on the back end to ensure compatibility and a smooth transition for your scripts and third-party tools.
  3. How does this affect my SLAs? Because many organizations use VPR as their operational prioritization layer, your SLA statistics and remediation tracking will now reflect the more precise scoring model. This helps ensure your team is meeting response goals for the vulnerabilities that pose the highest actual risk.
  4. How does Enhanced Asset Classification affect my scores? The system now automatically identifies the function and criticality of assets across Cloud, OT, and third-party sources. This improved context leads to more accurate Asset Criticality Rating (ACR) adjustments. For customers with access to ACR, this ensures your most critical business assets are effectively prioritized.
  5. What actions does my team need to take, and when will the changes be reflected in my container? These updates will occur automatically within your Tenable console. Depending on the size of your environment, it may take time for score recalculations to be fully reflected across your console.

For a detailed guide on our enhanced VPR, check out this FAQ

Want to see the why behind our scoring? View our scoring explained

12 Replies

      • tsitcawich's avatar
        tsitcawich
        Product Team

        Great, thank you for confirming, Adam, and apologies again for the inconvenience. 

  • Hi Adam, thank you for flagging! So sorry about that. The link has now been fixed. 

    • adam_walter's avatar
      adam_walter
      Connect Contributor V

      Hi, it's still broken for me. I get: 

      404 Error

      Looks like somebody cut the cord.

  • aamin's avatar
    aamin
    Connect Contributor II

    Thanks for the information.

    Is this update will be available for on-prem tenable solution also? or just cloud thing?

    • metehanefe's avatar
      metehanefe
      Connect Contributor III

      Hi,

      The new VPR model is already available in Tenable Security Center (on-prem) as VPR (Beta). With this update, the beta label is expected to be removed and the same model is expected to continue as the standard VPR. Therefore, on-prem Security Center customers are also expected to continue benefiting from the updated VPR scoring.

      • aamin's avatar
        aamin
        Connect Contributor II

        Thanks for your response.

        Could you please guide me where to find the VPR (Beta) cause I search for it but didn't find anything the least feature I have in my security center is the Asset Explorer my Security Center version is 6.8 which I believe it's the latest update.

        Thanks again.