Troubleshooting "Vulnerability issues daily limit reached" in Cortex Cloud
Symptom
Users receive a notification stating "Vulnerability issues daily limit reached" or "Vulnerability issues creation paused."
Environment
- Cortex Cloud / XSIAM / XDR
Cause
Cortex Cloud has a hard-coded daily quota of 50,000 vulnerability issue actions per domain.
-
Action Types: The limit is consumed by the creation of new issues, status changes (e.g., "New" to "In Progress"), and policy re-evaluations (When modifying or creating new vulnerability policies)
-
Volume: A single asset can trigger thousands of individual findings. When processed globally, these frequently exceed the 50,000 action threshold.
-
Scope: This is a platform-wide limit. It is not tenant-specific and cannot be adjusted on a per-customer basis at this time.
Resolution
While global limit increases are being considered for future releases, TSEs should advise customers to prioritize high-value data within the existing quota:
-
Enable "CVEs Confirmed Vulnerable Externally": Engineering recommends enabling this specific default policy. It ensures that the daily quota is used to promote the most critical, externally validated risks (AST findings) to "Issues."
-
Disable Broad/Noisy Policies: Advise the customer to disable or narrow the scope of broad policies (e.g., policies covering all "Medium" or "Low" severity CVEs) that generate high volumes of low-value issues.
-
Targeted Asset Scoping: Refine policies to target only the most important assets or asset groups to ensure generated issues are meaningful.
-
Findings-First Workflow: Suggest using the Vulnerability Findings view for raw data visibility. Discovery and prevention functions are not affected by the issue creation pause, the environment remains protected.
-
CS Engagement: If the customer requires hands-on assistance with policy refinement or scoping, refer them to their Customer Success (CS) team.