Parameter

Exploit Prediction Scoring System (EPSS)

Exploit Prediction Scoring System (EPSS) is a data-driven model from FIRST that estimates the probability a given CVE will be exploited in the wild within the next 30 days. It outputs a probability from 0 to 1 and a percentile, updated daily for every published CVE.

Last reviewed

What is EPSS?

EPSS estimates one thing: the probability that a vulnerability will be exploited in the wild in the next 30 days. It is a machine-learning model maintained by the EPSS Special Interest Group at FIRST, with scores generated by Empirical Security and published free through a daily CSV and an API. Every published CVE gets a score, recomputed every day. The current model is v2026.06.15 (EPSS v5), which began publishing on June 15, 2026; earlier versions were EPSS v3 (March 2023) and v4 (March 2025), and each version shift produces a step change in scores that a time series should account for.

EPSS exists because severity does not predict exploitation. Most vulnerabilities are never attacked: in any 30-day window, exploitation activity is observed for roughly 2.5 to 3 percent of published CVEs. A model that says "probably not" for the large majority, and concentrates its high scores on the small fraction that matters, is more useful for ordering a patch queue than a severity rating that calls thousands of flaws Critical.

What do the probability and the percentile mean?

Each CVE gets two numbers, and they answer different questions.

  • Probability is the direct model output, from 0 to 1. A score of 0.05 means an estimated 5 percent chance that exploitation activity will be observed in the next 30 days. Among many CVEs scoring around 0.05, you would expect about 5 in 100 to see activity.
  • Percentile is a relative ranking against all currently scored CVEs. A CVE at the 90th percentile has a higher probability than 90 percent of scored vulnerabilities.

The percentile matters because the distribution is heavily skewed toward zero. A probability of 0.10 sounds small but currently sits near the 95th percentile, so an absolute number that looks low can still be an extreme outlier. The probability tells you the absolute likelihood; the percentile tells you where it stands in the population.

EPSS scores change overnight by design. A jump means new signals arrived, such as public exploit code, published detection signatures, or a spike in scanning chatter. Nothing about the vulnerability itself changed; the model's information did.

What EPSS is not

EPSS is the threat-likelihood component of a risk calculation, not the whole thing. FIRST is explicit: it does not measure impact, does not know what assets you run, and does not account for compensating controls. Two consequences follow:

  • Do not treat EPSS as a complete risk score. Combine it with the consequence of exploitation and with whether the flaw is present and reachable in your environment.
  • Do not multiply EPSS by a CVSS score. FIRST calls this out directly: it is not "probability times severity". A calibrated probability multiplied by an ordinal severity ranking produces a number with no interpretable meaning.

EPSS and CVSS are empirically close to uncorrelated. A Critical CVSS score with a low EPSS score is not a contradiction: one says a flaw is severe if exploited, the other says exploitation is currently unlikely.

A worked triage example

Three real vulnerabilities, with their NVD CVSS v3.1 base scores, their EPSS scores (as published on September 26, 2026), and their CISA KEV status:

CVEWhat it isCVSS baseEPSS probabilityEPSS percentileIn KEV
CVE-2023-4966Citrix Bleed, NetScaler info disclosure9.40.94+99th+Yes
CVE-2024-1351MongoDB TLS cert validation skip9.80.00540thNo
CVE-2024-0235EventON WordPress plugin email disclosure5.30.3898thNo

Read by CVSS alone, you would patch the two 9-something flaws first and leave the 5.3 for later. EPSS and KEV reorder that:

  1. CVE-2023-4966 is confirmed exploited (KEV) and near-certain on EPSS. It goes first, whatever else is in the queue. When a vulnerability is on KEV, KEV takes precedence: known exploitation beats a forecast.
  2. CVE-2024-0235, despite a middling 5.3, carries a 38 percent 30-day exploitation probability at the 98th percentile. That is a strong signal it is worth attention ahead of a higher-CVSS flaw with no exploitation signal.
  3. CVE-2024-1351, a 9.8, has a 0.5 percent probability at the 40th percentile and is not on KEV. It is genuinely severe if exploited, so it should be fixed, but it does not warrant emergency handling today over the other two.

A workable policy: treat any KEV entry as top priority regardless of score, then use an EPSS threshold on the rest. There is no universal threshold; FIRST notes 0.10 is commonly cited but carries no special authority. Pick one you can sustain given your remediation capacity, and revisit it. A program that currently treats CVSS Critical as its action line reaches a comparable effort level at roughly the 90th EPSS percentile.

Combining EPSS, CVSS and KEV

The three tools cover different axes, and a triage decision uses all of them:

  • CVSS describes severity: how bad it would be if exploited. See the CVSS entry.
  • EPSS estimates threat likelihood: how probable exploitation is in the next 30 days.
  • CISA KEV records confirmed exploitation: a fact, not a forecast, and it overrides the forecast when present.

None of the three knows whether the vulnerable code is reachable in your deployment or what the data behind it is worth. That last axis, exposure, comes from testing your own environment, not from any public score.

Written by Parameter · Last reviewed