Vendor severity ratings reflect theoretical risk, not real-world exploitation. The speaker notes that most actively targeted vulnerabilities are not the ones receiving priority response under traditional models, meaning organizations may be patching lower-risk items while leaving exploited vulnerabilities unaddressed.