# Separate original and current device impact in the vulnerability event timeline

> Does a vulnerability event's original affected-device count describe the devices still affected now?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:38+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does a vulnerability event's original affected-device count describe the devices still affected now?

## Potentially affected

Microsoft Defender Vulnerability Management Event timeline investigations.

## DSE recommendation

Use the current impact column for present work and retain original impact as historical context.

## Article

## Source facts

Defender Vulnerability Management’s Event timeline distinguishes the devices affected when an event occurred from those affected now. The current-impact column can be added through Customize columns. The two headline totals count new and exploitable vulnerabilities, not timeline events: one event can involve several vulnerabilities, and one vulnerability can appear in several events. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline).

Selecting an event opens its details and current CVEs affecting devices, with a route to the associated security recommendation. The timeline includes vulnerability publications, exploit developments and configuration assessments. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline).

## Applicability

Use this distinction in Microsoft Defender Vulnerability Management Event timeline investigations. Keep the date being investigated and the time of the current observation visible; this brief does not treat the timeline as a list of confirmed local attacks.

## DSE recommendation

DSE recommends recording original and current impact in separate fields when an event becomes a remediation work item. Use the current population to identify remaining work, while preserving the original value to explain the event’s initial significance. Avoid adding event counts to vulnerability totals or interpreting a repeated vulnerability as several independent weaknesses. Follow the specific recommendation rather than acting from a headline number alone.

## Verification

Open a representative event, expose its current-impact column and compare the linked device and CVE details with the proposed work item. Confirm that the event date and observation time are not being conflated. After an approved remediation, review the current affected population again and retain unresolved devices explicitly without rewriting the historical impact.

## Official references

[Microsoft Learn: Event timeline](https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline).

## Primary reference

- Name: Event timeline - Microsoft Defender Vulnerability Management | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate original and current device impact in the vulnerability event timeline,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
