Security teams love certainty and clean labels: "critical," "high," "known exploited." These feel like definitive, clear directives we can build policy around. But here's the uncomfortable truth: ...