Definition · Known Vulnerabilities (CVEs)
What is EPSS?
EPSS (Exploit Prediction Scoring System) is maintained by FIRST, the Forum of Incident Response and Security Teams — the same body that maintains CVSS. Each scored CVE receives a probability between 0 and 1 that exploitation activity will be observed within the following 30 days, plus a percentile showing where that probability sits relative to all other scored vulnerabilities.
What EPSS is not
EPSS does not describe severity, impact, or how bad exploitation would be for you. A vulnerability can have a high EPSS score and a low CVSS score, or the reverse. It also says nothing about your environment: exposure, compensating controls, and business criticality are yours to add.
How to read the scores
Scores are updated daily and most vulnerabilities score low, because most are never exploited at scale. Teams typically pick a threshold — for example, treating anything above 0.1 as elevated — and then combine it with exposure. A modest EPSS score on an internet-facing service can outrank a higher one on a host nobody can reach.
Using EPSS for prioritisation
A workable order of operations is: fix what is in the KEV catalogue and internet-facing, then high-EPSS items on exposed assets, then the remainder by CVSS and business context. This uses each signal for what it measures — observed exploitation, predicted exploitation, and potential impact — rather than asking one score to do everything.
Related concepts
EPSS scores are keyed to CVE identifiers published through the NVD, and reflect the likelihood that an exploit — sometimes starting from a proof-of-concept — will be used in anger. They feed directly into vulnerability management and patch management sequencing.