Here's a short article to explain very well the difference between risk, threat, and vulnerability.
Risk is the potential for loss, damage or destruction of assets or data caused by a cyber threat.
Threat is a process that magnifies the likelihood of a negative event, such as the exploit of a vulnerability.
Vulnerability is a weakness in your infrastructure, networks or applications that potentially exposes you to threats.
Links: