I've been on the receiving end of various emails like that. They have details on specific systems and specific attacks. They're occasionally useful, but often not. Knowing that a particular app is vulnerable to XSS might be useful, if I have staff that can fix it and they have the spare cycles.
For example, a hospital IT department might get an email telling them that their MRI is exposing remote desktop to the internet with default credentials. They know that. They don't change it because if they do, their vendor will drop support. This is a real thing that real medical hardware has to deal with, and it's only slowly getting better.
A big industrial company might easily have it worse than a hospital. Fixing the specific CVE on a specific port on a specific machine might mean having to retire a whole series of obscure, niche bits of SCADA hardware that don't support anything modern. It's like all those IoT gadgets that don't support 5GHz, writ large.
https://en.wikipedia.org/wiki/SCADA#Security_issues
Somewhere between those two, you have your well-run Windows network. It's probably a month to several months of patching behind. IT has a whole process to test any new patches for stability and compatibility with line-of-business software to ensure that nothing breaks. Knowing that their systems are vulnerable to the CVE that's fixed by a patch they're testing - or tested and found broke something important - might not always help them very much.