I’ve never understood the attempt to draw a difference between threat and a vulnerability.
I’ve done offensive security work and worked on defensive security systems professionally. It seems to me like there’s a certain less technical side of computer security that cares a little too much about making definitions and checkboxes - when I get asked in an interview if I think threats or vulnerabilities are a bigger issue I know that job is not a good fit.