Vulnerability statuses and resolutions

Last updated: September 8, 2026

Use this article when you need to move a vulnerability through triage or understand its resolution.

Status groups

  • Active statuses: Open, Confirmed, Needs Review, In Progress, and In Review.
  • Final statuses: Resolved and Closed. A resolution is required when a vulnerability reaches a final status.

Resolutions

  • Fixed: Cysmiq confirmed remediation. This resolution is scanner-managed and cannot be selected manually or submitted through API or CLI triage.
  • Won't Fix: the team accepts the risk and will not remediate.
  • False Positive: the finding is not a real issue.
  • Duplicate: the same issue is tracked elsewhere.
  • Cannot Reproduce: the issue cannot be verified.
  • Done: the work is complete.

False positive workflow

  • Open the vulnerability detail view.
  • Set the status to Closed.
  • Choose False Positive as the resolution.
  • Add a comment with the reviewer, evidence, or linked discussion.
  • Save the status change.

Reopening behavior

A final vulnerability can be reopened manually only when Cysmiq still has an active location for it. If all locations are fixed, future redetection by a scan is the path that reopens the finding, and that reopening is tracked as a regression.

Canonical docs

For the maintained reference, see Vulnerability lifecycle.

Contact support if

  • An expected status transition or resolution is unavailable.
  • A final vulnerability reopens and you need help understanding why.
  • You need help deciding between Won't Fix, False Positive, Duplicate, or Cannot Reproduce.