For all the crying about the "AI vulnerability apocalypse" - it's just business as usual in the trenches amongst orgs doing the doing.
Almost every CVE was never actually exploited, and that pattern continues.
CVEs are bundled up in patches by vendors, so you just apply the patches each month as usual.
A lot of people have, and continue to, cry wolf.