DefinitionEPSS (Exploit Prediction Scoring System) is a model maintained by FIRST that estimates the probability, from 0 to 1, that a vulnerability with a CVE will be exploited in the next 30 days, based on signals observed in the real world.
How it works
EPSS uses a statistical model fed by public and partner data, such as the existence of exploit code, mentions in intelligence sources and observed attack activity. Scores are published for CVEs and recalculated daily, as two numbers:
- Probability: the estimated chance of exploitation in the next 30 days, between 0 and 1 (or 0% to 100%).
- Percentile: where that flaw ranks relative to all other scored flaws.
The data is open and can be queried or downloaded from the FIRST website, which makes it easy to integrate into scanners and prioritization tools.
EPSS vs CVSS vs KEV
The three answer different questions. CVSS measures the technical severity of the flaw. EPSS estimates the likelihood of attack. CISA's KEV records flaws with confirmed exploitation. Crossing CVSS and EPSS separates what is serious and under attack from what is serious but still theoretical, and reveals heavily exploited low-score flaws that a queue sorted by CVSS alone would push to the bottom.
In practice
EPSS is an estimate, not a guarantee: a low probability does not mean the flaw will never be exploited. It works best as one of several prioritization criteria, together with KEV, asset exposure and business importance. Since the score changes every day, prioritization should also be reviewed frequently.
Network Secure offers Vulnerability Management as a continuous service.
Frequently asked questions
Does EPSS replace CVSS?
No. CVSS describes how serious the flaw is; EPSS estimates the chance it will be exploited. Used together, they help decide what to fix first.
What EPSS value is considered high?
There is no official cutoff. Each organization sets its threshold based on its remediation capacity, often using the percentile to isolate the small group of flaws most likely to be exploited.