www.darkreading.com 7/21/2026, 10:20:50 PM · external

LLMs falter in vulnerability prioritisation due to false positives

LLMs falter in vulnerability prioritisation due to false positives
CyberSIXT Evidence Panel Source marked as original reporting

LARGE language models (LLMs) are facing significant challenges in effectively prioritizing vulnerabilities in application security. The high false-positive rates of these models, along with an inability to consider the context of scans, complicate the work of AppSec professionals. Reports indicate that over 60% of flagged vulnerabilities may be false positives or pertain to low-severity issues, making it difficult for security teams to triage effectively.

As the number of valid vulnerabilities surges, driven by an increase in Common Vulnerabilities and Exposures (CVE), relying solely on LLMs is proving inadequate. Experts stress the need for models to have comprehensive context—organizational, technical, and code-specific—to make accurate assessments. Additionally, methods to measure reachability can significantly reduce the vulnerabilities that security teams need to manage. Overall, improving the effectiveness of vulnerability detection and classification in the context of application security is critical.

View full article

Article by CyberSIXT