Vulnerability statuses and resolutions
Last updated: September 8, 2026
Use this article when you need to move a vulnerability through triage or understand its resolution.
Status groups
- Active statuses: Open, Confirmed, Needs Review, In Progress, and In Review.
- Final statuses: Resolved and Closed. A resolution is required when a vulnerability reaches a final status.
Resolutions
- Fixed: Cysmiq confirmed remediation. This resolution is scanner-managed and cannot be selected manually or submitted through API or CLI triage.
- Won't Fix: the team accepts the risk and will not remediate.
- False Positive: the finding is not a real issue.
- Duplicate: the same issue is tracked elsewhere.
- Cannot Reproduce: the issue cannot be verified.
- Done: the work is complete.
False positive workflow
- Open the vulnerability detail view.
- Set the status to Closed.
- Choose False Positive as the resolution.
- Add a comment with the reviewer, evidence, or linked discussion.
- Save the status change.
Reopening behavior
A final vulnerability can be reopened manually only when Cysmiq still has an active location for it. If all locations are fixed, future redetection by a scan is the path that reopens the finding, and that reopening is tracked as a regression.
Canonical docs
For the maintained reference, see Vulnerability lifecycle.
Contact support if
- An expected status transition or resolution is unavailable.
- A final vulnerability reopens and you need help understanding why.
- You need help deciding between Won't Fix, False Positive, Duplicate, or Cannot Reproduce.