Definition
A technique that checks whether a known software flaw is actually usable in your specific system — for example, whether the vulnerable piece of code ever actually runs — rather than just flagging every flaw that theoretically exists. One deployment cut a list of 40 million potential vulnerabilities down to fewer than 2,000 that were genuinely exploitable.
Why it matters
Security teams are drowning in vulnerability alerts; reachability analysis (increasingly paired with AI agents) lets scarce staff focus on the tiny fraction of flaws that pose real risk.